Privacy Policy
How Refix Inc. collects, uses, shares, and deletes personal data, including the Google Sign-In and Google API scopes we request and the data those scopes access.
Last updated September 12, 2026
This Privacy Policy applies to Refix and Refix Analytics, our websites (including refix.ai), dashboards, plugins, and related support and marketing activities (together, the “Services”). References in older interfaces or documentation to “Prism” mean the current Refix product.
1. Who we are
Refix Inc. (“Refix”, “we”, “us”, or “our”) provides two products:
- Refix, an AI product manager that works through Slack and the web. It answers questions, analyzes connected business data, searches connected knowledge sources, and runs scheduled monitoring.
- Refix Analytics, our earlier website and product analytics service, including its tracking script and Framer plugin.
Our registered address is 8 The Green, Ste A, Dover, DE 19901, United States. We operate from San Francisco, California. Contact us at hey@refix.ai.
2. Our role
We act as a data controller for personal data we decide how and why to process, such as account, billing, support, and Refix website data.
We generally act as a data processor when a customer uses Refix to process data from its Slack workspace, connected services, databases, or knowledge sources, or uses Refix Analytics to collect data about visitors to the customer’s website. The customer is the controller of that data and is responsible for providing required notices, establishing a lawful basis, and honoring requests from its users and visitors. We process that data on the customer’s instructions, the applicable agreement, and this policy.
3. Personal data we collect
Account, billing, and support data
We may collect:
- name, work email address, organization, role, and account identifiers
- authentication and workspace information
- subscription, billing, transaction, and invoice information (payment-card details are handled by our payment provider)
- communications with us, including support requests and feedback
- service usage, device, browser, IP address, diagnostic, security, and audit logs
Sign-in and authentication
You can create or sign in to a Refix account with Google, email and password, or Slack.
Google sign-in. When you choose Google, Google shares your Google account name, work email address, profile photo if you have one, and a unique Google user identifier. We do not receive your Google password. We use this information only to create, authenticate, and manage your Refix account and to associate you with a workspace. We request the openid, email, and profile scopes for sign-in. We do not use Google sign-in data for advertising, selling data, or training generalized AI models.
Email and password. We collect your work email address and a hashed password. We send verification and password-reset messages to that address.
Work email. Google and email sign-up require a work email. Consumer email providers such as Gmail are not accepted on those paths. This does not change existing Slack users who already signed in with a consumer email.
Slack. We receive Slack user and workspace identifiers and profile details as described below.
Refix
Depending on the features a customer enables, Refix may process:
- Slack workspace, channel, thread, and user identifiers, profile details such as name, email, locale, and time zone, and messages or files sent to or made available to Refix
- prompts, conversations, query history, generated answers, charts, files, feedback, and scheduled watcher configurations and results
- integration settings, account or project selections, OAuth tokens, API credentials, and other connection information
- data retrieved from customer-authorized services and databases to answer questions or perform monitoring, such as analytics, advertising, billing, commerce, CRM, support, project-management, and data-warehouse information
- documents, messages, file metadata, and extracted text or chunks from knowledge sources a customer chooses to connect
- organizational context, saved memories, metadata, and generated insights used to provide more relevant answers and continuity between sessions
The data Refix can access depends on the integrations and permissions the customer or user chooses. We request or use permissions for the features being provided and do not use connected-service data to advertise to individuals.
Refix Analytics
When a customer installs Refix Analytics on a website, the service may collect:
- a randomly generated browser identifier stored locally and associated with that customer’s domain
- session and page-view information, including page path or URL, page title, referrer, and UTM campaign parameters
- interactions with links, buttons, and other clickable elements, including automatically generated event labels, and scroll depth
- browser, country, device type, operating system, language, and screen resolution
Refix Analytics’ core customer-site tracking does not use traditional browser cookies. It is designed not to capture passwords or other sensitive form inputs and does not retain visitors’ IP addresses as analytics data fields. A customer may separately send additional data to Refix Analytics through features it configures. The customer is responsible for that data and its lawful collection.
Cookie-less tracking does not by itself remove a customer’s obligations under privacy or electronic-communications laws. Customers should assess whether notice or consent is required for their use of Refix Analytics.
Our websites and marketing pages
When you visit or sign in to a Refix website, we and our vendors may use cookies, pixels, scripts, local storage, and similar technologies. These may collect device and browser data, IP address, pages viewed, interactions, referral and campaign information, and identifiers. Some vendors may help associate a business visit with a company or business contact record.
We use this information to operate our sites, understand traffic, measure marketing, detect fraud and abuse, identify company-level interest, and communicate with relevant business contacts. This website activity is separate from Refix Analytics’ cookie-less customer-site tracking.
You can use your browser controls to limit cookies. For supported visitor-identification services, you can also use Retention.com’s opt-out and RB2B’s GDPR opt-out.
Data from other sources
We may receive information from your employer or workspace administrator, authentication and integration providers, payment providers, support and marketing vendors, and publicly available business sources.
4. How we use personal data
We use personal data to:
- provide, personalize, maintain, and secure the Services
- authenticate users and administer accounts, workspaces, integrations, and subscriptions
- retrieve customer-authorized data and generate answers, analyses, summaries, charts, alerts, and other requested output
- operate Refix Analytics and produce website and product analytics for the relevant customer
- troubleshoot issues, monitor performance, prevent fraud or abuse, and improve reliability
- provide support and communicate about the Services
- understand use of our websites and market our business-to-business Services
- comply with law, enforce our agreements, and protect rights, safety, and property
- create aggregated or de-identified information that cannot reasonably identify an individual
Where the GDPR or similar law applies, our legal bases may include performance of a contract, our legitimate interests in operating, securing, improving, and marketing the Services, consent where required, and compliance with legal obligations. When we process customer data as a processor, the customer determines the applicable legal basis.
5. Google user data we access
This section is the Google OAuth disclosure. It lists the Google user data Refix Inc. accesses, why we access it, and how we use it. We request Google scopes only after you sign in or connect an integration. We do not access Google user data in the background without that grant.
Google Sign-In
Used only to create and authenticate a Refix account. We request:
| Scope | Data accessed | How we use it |
|---|---|---|
openid |
A stable Google account identifier | Match the Google account to a Refix user on later sign-ins |
email (userinfo.email) |
Your primary Google Account email address | Create the account, send verification and product mail, and associate you with a workspace. We require a work email |
profile (userinfo.profile) |
Name and profile photo you have made available on your Google Account | Show your name and avatar in Refix |
We do not receive your Google password. We do not request Drive, Analytics, or BigQuery scopes during sign-in.
Google product integrations
Used only after you or a workspace administrator connects the integration in Refix. We request:
| Scope | Data accessed | How we use it |
|---|---|---|
drive.file |
Google Drive files and folders you create or open with Refix, including names, metadata, and file content | Index those files as a knowledge source so Refix can search and answer questions from them |
analytics.readonly |
Google Analytics accounts, properties, and report data you connect, including metrics, dimensions, configuration, and downloadable report data | Answer questions, investigate trends, and monitor goals you set in Refix. Read-only. We do not change your Analytics settings |
bigquery.readonly |
Google BigQuery projects, datasets, tables, and query results you connect | Run read-only queries you or Refix request so we can answer questions from that warehouse. We do not write or delete BigQuery data |
Sign-in identity scopes (openid, email, profile) may also appear on a connected Google integration so we can show which Google account granted access.
How we use, share, and retain Google user data
- Use. We use Google user data only to provide and improve the Refix features you asked for: sign-in, connected knowledge, analytics questions, and warehouse questions. Access is user-initiated through OAuth.
- Human access. Refix staff do not read your Google user data unless you ask for support, we must investigate abuse or security, or law requires it.
- Sharing. We may send the minimum needed prompts, retrieved rows, file chunks, and conversation context to our infrastructure and AI model providers (including Google, Anthropic, OpenAI, and Amazon Bedrock) so they can generate the requested output. Those providers process that data for us. We do not sell Google user data. We do not share it with independent third parties for their advertising. We do not use Google user data for ads.
- AI training. Data obtained from Google APIs is not used to develop, improve, or train generalized or third-party AI models.
- Storage. We may store OAuth refresh tokens, the Google account identifier and email, selected Drive file content or chunks, Analytics query results, BigQuery query results, and generated answers as described in Sections 3 and 11.
- Revoke and delete. Disconnect the integration in Refix, or revoke Refix in Google Account permissions. Revoking stops future access. It does not by itself delete data we already stored. To delete stored Google data, follow our Data Deletion Instructions.
Refix’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
6. Other connected services
Refix accesses a connected service only after a customer or authorized user configures the connection or grants permission. Depending on the integration, Refix may query services such as Slack, Google Analytics, Google Ads, Google BigQuery, Google Drive, databases, data warehouses, analytics tools, CRM systems, support platforms, billing platforms, commerce platforms, and project-management tools.
We use connected data to provide the requested Refix feature. We may store connection credentials, selected account and project metadata, query and conversation history, retrieved results, generated outputs, and selected document content or chunks needed for knowledge retrieval and continuity. Refix is not intended to create a permanent copy of an entire connected database or file system, although saved knowledge sources, outputs, memories, and query results may contain portions of connected data.
You can disconnect integrations in Refix or through the relevant provider. Disconnecting stops future access but does not automatically delete data already retained in Refix. You or your administrator may request deletion as described in our Data Deletion Instructions.
7. AI processing
Refix uses third-party AI and cloud model providers to understand requests and generate outputs. Depending on configuration and availability, these may include Amazon Web Services (Amazon Bedrock), Anthropic, OpenAI, and Google.
We send these providers only the prompts, connected data, conversation context, and instructions needed to provide the relevant feature. We do not permit customer data to be used to train providers’ generalized models where provider controls or contractual terms allow us to prevent that use. AI providers may retain data for limited periods for security, abuse prevention, or legal compliance under their applicable terms.
AI-generated output may be inaccurate. Customers and users should review output before relying on it, especially for important decisions.
8. How we share personal data
We may share personal data:
- with infrastructure, hosting, database, authentication, payment, email, customer-support, analytics, monitoring, integration, and AI providers that process data for us
- with connected services at a customer’s direction, including when Refix reads from or takes an authorized action in those services
- with a customer’s workspace administrators and other authorized workspace members
- with professional advisers, auditors, insurers, and authorities where reasonably necessary
- to comply with law or protect the rights, safety, and security of Refix, our users, or others
- in connection with a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards
Providers used for some or all Services include Google Cloud for managed infrastructure, Stripe for payments and subscriptions, Resend for verification and password-reset email, and the AI providers described above. Some integrations use an integration-platform provider such as Composio. The particular providers involved depend on the product, deployment, integrations, and features used.
We do not sell customer data or connected-service data. We do not share that data with independent third parties for their own advertising. Our own marketing websites may use the business visitor-identification practices described in Section 3.
9. International transfers and hosting
Our managed core application and analytics infrastructure is hosted in the European Union. We are a United States company, and some service providers may process data in the United States or other countries. Those countries may have different data-protection laws.
Where required, we use appropriate safeguards for international transfers, such as contractual protections. For customer-hosted deployments of Refix, the customer determines the hosting location and may directly configure certain infrastructure and model providers.
10. Security and tenant separation
We use reasonable technical and organizational measures designed to protect personal data, including encryption in transit and at rest where supported, access controls, credential protection, backups, monitoring, and logical separation of customer environments and data. No system is completely secure, and we cannot guarantee absolute security.
Customers are responsible for managing their users, integration permissions, credentials, and the data they choose to make available to the Services.
11. Retention and deletion
We retain personal data for as long as reasonably necessary to provide the Services, maintain security and business records, comply with law, resolve disputes, and enforce agreements. Retention varies by the type of data, customer configuration, deployment, and legal requirements.
When a customer disconnects a source, closes an account, or requests deletion, we delete or de-identify applicable data within a reasonable period unless we must retain it by law or it remains in backups for a limited period. A customer may have its own retention settings or obligations. If you submitted data through a customer’s website or workspace, contact that customer first. We will assist the customer with a valid request as required by our agreement and applicable law.
For request steps and the information to include, see our Data Deletion Instructions.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- access and receive a copy of your personal data
- correct inaccurate or incomplete data
- request deletion
- restrict or object to processing
- receive certain data in a portable format
- withdraw consent where processing is based on consent
- lodge a complaint with your local data-protection authority
To exercise a right regarding data Refix controls, email hey@refix.ai. We may need to verify your identity. For data controlled by a Refix customer, submit the request to that customer. We will support the customer where required.
13. Children’s privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data to us, contact us so we can review and delete it where appropriate.
14. Changes to this policy
We may update this policy to reflect changes to our Services, providers, or legal obligations. We will post the updated version on this page and change the date above. Where required, we will provide additional notice of material changes.
15. Contact us
Refix Inc.
8 The Green, Ste A
Dover, DE 19901
United States
This policy is also governed by our Terms of Service.