Privacy Policy

Effective Date: March 8, 2026

1. Introduction

Sandri.ai ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, including our website, dashboard, and MCP server (collectively, the "Service").

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

3. How We Use Your Information

We use collected information to:

We do not use your data to:

4. Data Security

4.1 Encryption at Rest

4.2 Encryption in Transit

4.3 Access Controls

5. Third-Party Services

We integrate with the following third-party providers to enable features:

Provider Purpose Data Shared
Google (OAuth) Gmail, Calendar, Drive access OAuth tokens (access + refresh)
Slack (OAuth) Slack messaging OAuth tokens
Notion (OAuth) Note-taking and page management OAuth tokens
GitHub (OAuth) Repository and issue management OAuth tokens
Spotify (OAuth) Music playback and playlist management OAuth tokens
Supabase Authentication, database, Edge Functions User profile, connections, usage logs
Vercel Dashboard hosting No sensitive data
Firebase Landing page hosting No sensitive data
Google Places API Restaurant search Search queries only
Skyscanner (RapidAPI) Flight search Search parameters only
OpenTable (RapidAPI) Restaurant reservations Search parameters only
Brave Search API Web search Search queries only
LiteLLM Proxy LLM routing Tool call parameters

We do not share your personal information with third parties except as necessary to provide the Service or as required by law.

6. Data Retention

7. User Rights

You have the right to:

To exercise these rights, contact us at privacy@sandri.ai.

8. Data Breaches

In the event of a confirmed data breach involving unencrypted personal information, we will notify affected users within 30 days as required by law.

9. Compliance

10. Children's Privacy

Our Service is not intended for users under 13 (or the digital age of majority in your jurisdiction). We do not knowingly collect information from children. If we learn we have collected information from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy periodically. The effective date will be updated, and we will notify you of material changes via email or a banner on the Service.

12. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us at: