Privacy Policy

Last updated: July 14, 2026

This Privacy Policy describes how Accessfyr (“Accessfyr,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our websites, applications, Slack bot, and related services (the “Service”). Accessfyr is a multi-tenant access management platform that helps organizations manage employee lifecycle and third-party tool access through a web dashboard and natural-language commands in Slack.

By using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

1. Who this policy covers

Accessfyr is primarily a business-to-business (B2B) product. We process information on behalf of customer organizations (“Customers”) and their authorized administrators (“Admins”), as well as limited information about end users who interact with the Service (for example via Slack).

  • Account users — people who sign up, sign in, or administer a Customer workspace.
  • Directory / employee records — workforce data synced from a Customer’s connected identity directory (e.g. Google Workspace) and related access records.
  • Website visitors — people who visit our marketing or legal pages.

Where we process employee or directory data for a Customer, the Customer is typically the data controller (or equivalent) and Accessfyr acts as a processor (or service provider), except for our own account, billing, and product analytics data where we act as controller.

2. Information we collect

2.1 Information you provide

  • Account information — name, email address, password (stored hashed), and profile image URL if provided by a sign-in provider.
  • Organization information — organization name, tenant subdomain/slug, and related workspace settings created during setup.
  • Integration configuration — non-secret metadata such as a Google Workspace admin email used for domain-wide delegation, or Slack workspace identifiers and display names.
  • Communications — messages you send to us (support or other contact).

2.2 Information from connected services

When a Customer connects third-party services, we receive data necessary to provide the Service:

  • Google sign-in (user authentication) — basic profile identifiers (such as name, email, and profile image) used to create or authenticate an Accessfyr user account. This is separate from Google Workspace directory management.
  • Google Workspace (directory & lifecycle management) — via a Customer-provided service account with domain-wide delegation. Depending on configuration and Admin actions, this may include user profile fields (email, name, job title, department, photo URL, organizational unit, suspension status), group membership information, and related Admin SDK responses. We may store a copy of provider API payloads needed for sync and operations.
  • Slack — workspace identifiers, bot and optional user tokens, member identifiers/emails needed to map Slack users to Customer admins, and message content directed at the Accessfyr bot (for example @mentions and thread context) so we can interpret natural-language requests and reply.

2.3 Information collected automatically

  • Session and security data — session tokens, IP address, user agent, and related authentication metadata used to keep you signed in and protect accounts.
  • Usage and operational logs — technical logs related to requests, errors, integration events (for example Slack event IDs for idempotency), and product operation.

2.4 Credentials and secrets

Customers may store integration credentials in Accessfyr, including Google Workspace service account JSON keys and Slack API tokens. Those secrets are encrypted at rest using AES-256-GCM before being stored in our database. Non-secret metadata needed for operation (for example admin email or Slack team name) may be stored in plaintext form.

3. How we use information

We use information to:

  • Provide, operate, and secure the Service and Customer workspaces.
  • Authenticate users and maintain sessions across authorized tenant subdomains.
  • Sync and display directory/employee data and application access status.
  • Execute Admin-initiated access management actions (for example onboard, offboard, grant/revoke access, or manage Google Workspace users and groups) via the web app or Slack natural-language agent.
  • Process Slack messages and related tool results with AI model providers so the agent can understand requests and take permitted actions.
  • Improve reliability, debug issues, prevent abuse, and communicate service-related notices.
  • Comply with law and enforce our Terms of Service.

4. AI processing

When Admins use the Slack agent, message content and necessary context (such as employee search results or tool outputs) may be sent to our AI provider (currently OpenAI) to generate responses and decide which tools to call. Do not submit information to the agent that you are not authorized to process. Temporary credentials generated during provisioning may appear in Slack replies to the requesting Admin; treat those channels as sensitive.

5. How we share information

We share information only as needed to run the Service:

  • Service providers / subprocessors — infrastructure and platform vendors that process data on our behalf, which may include database/hosting (e.g. Supabase/Postgres), authentication and identity providers (e.g. Google OAuth for sign-in), productivity platforms you connect (Google Workspace, Slack), and AI providers (e.g. OpenAI).
  • Within a Customer tenant — authorized users of that Customer may access directory and access data according to product permissions.
  • Legal and safety — if required by law, regulation, legal process, or to protect rights, security, and integrity.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards.

We do not sell personal information. We do not use Customer directory data to advertise to employees.

6. Multi-tenant isolation

Customer data is associated with a tenant identifier. Access to a Customer workspace is limited to authenticated users who belong to that tenant (and to platform operators performing support or operations under strict access controls).

7. Data retention

We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Customer Admins may disconnect integrations or request deletion of a workspace; residual backups may persist for a limited period. Directory sync is additive operational data and may retain historical records until deleted or purged according to Customer requests and our retention practices.

8. Security

We implement technical and organizational measures designed to protect data, including encrypted storage of integration credentials (AES-256-GCM), access controls, and use of managed infrastructure. No method of transmission or storage is 100% secure. Customers are responsible for safeguarding their own credentials, Slack workspaces, Google admin configurations, and admin account access.

9. Cookies and similar technologies

We use cookies and similar technologies that are necessary for authentication and session management (for example session tokens that may be shared across authorized subdomains of our application domain). We do not currently use third-party advertising cookies on the Service.

10. International transfers

We may process and store information in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer mechanisms.

11. Children’s privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children.

12. Your rights and choices

Depending on your location and role, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. If you are an employee of a Customer, please contact your organization first; they control most directory and access data. Account users may update certain profile details in-product or by contacting us.

13. Customer responsibilities

Customers are responsible for:

  • Providing appropriate notices and obtaining any required consents from their workforce and users.
  • Configuring Google Workspace domain-wide delegation, Slack app permissions, and least-privilege admin access carefully.
  • Ensuring they have the legal right to process employee and identity data through Accessfyr.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated through the Service or by email where appropriate.

15. Contact

For privacy questions or requests, contact us at privacy@accessfyr.com.