Privacy Policy
This Privacy Policy explains how Giga collects, uses, discloses, and safeguards your information when you visit our website or use our service (the "Service"), and describes your privacy rights and how the law protects you. By using the Service, you agree to the collection and use of information in accordance with this Policy.
1. Who We Are & Key Definitions
Giga is operated by Tonic Labs Limited, a company registered in Ireland ("Giga", "we", "us", or "our"). For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Tonic Labs Limited is the Data Controller of personal data processed through the Service. You can contact us about privacy at support@getgiga.com.
- Personal Data — any information relating to an identified or identifiable individual.
- Usage Data — data collected automatically from your use of the Service (e.g. IP address, browser type, pages visited, timestamps).
- Connected-Service Data — data we access from a third-party service you connect (e.g. Google Workspace, Slack) on your instruction, solely to carry out your requests.
- Service Provider / Processor — a third party that processes data on our behalf under contract.
2. Information We Collect
Information you provide. When you create an account, connect integrations, or communicate with us, we collect information such as your name, email address, workspace configuration, and any content you submit through the Service.
Information collected automatically. When you use the Service we automatically collect Usage Data, including your IP address, device and browser type, the pages you visit, and the time and duration of your visit.
Connected-Service Data. When you connect a third-party integration (including Google Workspace, Gmail, Google Drive, Google Docs, Google Calendar, and Slack), we access and process data from those services only to fulfil the specific requests you make and to provide the Service's functionality. See Section 5 for exactly what Google data we access and why.
3. Cookies, Analytics & Tracking
Our website uses cookies and similar technologies to operate the site and understand how it is used. These website analytics are entirely separate from — and never draw on — the Google user data described in Section 5. We use:
- Google Analytics — to measure website traffic and usage patterns.
- PostHog — for product analytics, to understand how features are used and improve them.
- Reditus — to attribute referrals from our affiliate programme.
Cookies may be "session" cookies (deleted when you close your browser) or "persistent" cookies (which remain until they expire or you delete them). You can instruct your browser to refuse cookies or alert you when one is set; some parts of the Service may not function properly without them. Where required by law, we ask for your consent before setting non-essential cookies. We honour recognised browser-based opt-out signals (including Global Privacy Control) where applicable.
4. How We Use Your Information & Legal Bases
We use your information to provide, maintain, secure, and improve the Service; to carry out the actions you request; to manage your account; to communicate with you about the Service; and to comply with our legal obligations. Under the GDPR, we rely on the following legal bases:
- Performance of a contract — to provide the Service and carry out the tasks you ask Giga to perform.
- Legitimate interests — to secure, maintain, and improve the Service and understand how it is used, balanced against your rights.
- Consent — for non-essential cookies and optional communications, which you may withdraw at any time.
- Legal obligation — where we must process data to comply with the law.
5. Google User Data & Limited Use
Giga's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We request the narrowest scopes needed to provide the features you ask for. Specifically:
- Gmail (
gmail.modify) — read the content and labels of messages you point Giga to, and, on your instruction, compose, send, draft, label, archive, and organise mail. We do not request permanent-deletion or full-account scopes. - Google Drive (
drive) — find, read, create, edit, move, and share files you ask Giga to act on, including files you did not create, so Giga can act on your existing content by description. - Google Docs (
documents) — read and edit the body content of documents you ask Giga to work on (insert, rewrite, restructure, or summarise sections in place). - Google Calendar (
calendar.events) — read your schedule and create, update, or cancel individual events on your instruction. We do not request broader calendar-settings scopes.
Google user data is accessed only when you ask Giga to act on it, used solely to compose the response or perform the action you requested, and not retained afterwards. We do not use Google user data for advertising or targeting, and we do not use it to develop, improve, or train generalised AI/ML models. Any transfer to a third party is limited to what is necessary to provide the Service at your direction (see Section 6) or as required by law.
6. How We Share Your Information & Subprocessors
We do not sell your personal data. We share it only with service providers who process it on our behalf under contract, and only as needed to run the Service:
- AI model provider — Anthropic, PBC. To carry out your requests, relevant content may be sent as ephemeral context to Anthropic's Claude models. Under Anthropic's commercial API terms, this data is not used to train their modelsand is not retained beyond what is needed to return the response.
- Cloud hosting & infrastructure — Hetzner (EU). Hosts the application and database within the EU.
- Backup storage — Cloudflare R2 (EU). Encrypted database backups are stored in EU-based object storage.
- Analytics providers — Google Analytics, PostHog, and Reditus, for website and product analytics only (never Google user data).
We may also disclose data in connection with a merger, acquisition, or asset sale (with notice), or as described in Section 10.
7. Data Security & AI Processing
We implement appropriate technical and organisational security measures designed to protect your information, including encryption at rest and in transit. No method of transmission or storage is 100% secure, but we work to protect your data using commercially acceptable means.
Giga uses a vault-proxy architecture for all third-party integrations. When you connect a service (e.g. Gmail, Google Drive, Slack), your credentials — API keys, OAuth tokens, and other secrets — are stored encrypted in a dedicated vault and are never exposed to our AI models or placed into model context. All authenticated requests are proxied through the vault, which injects the credential server-side so the raw secret never reaches the application layer.
When you ask Giga to act on connected data (e.g. summarise an email, find a file), the relevant content may be passed as ephemeral context to an LLM solely to fulfil your request. This processing is transient: context is not stored after the response is generated, and we do not train foundational AI models on your private data, chat history, or connected-service content. Your data remains yours.
8. Data Retention & Deletion
We retain your data for as long as your account is active or as needed to provide the Service. When you disconnect an integration, we stop accessing that data. When you delete your account, we delete or anonymise your data within 30 days, unless we are required by law to retain it. To request deletion at any time, contact support@getgiga.com.
9. International Data Transfers
We are based in Ireland (EU). Some of our service providers (including Anthropic) are located outside the European Economic Area, so your data may be transferred to and processed in countries whose data-protection laws differ from your own. Where we transfer personal data outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
10. Your Privacy Rights (GDPR & UK GDPR)
If you are in the EEA or UK, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data; the right to data portability; and the right to withdraw consent at any time. To exercise any of these rights, contact support@getgiga.com.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Irish Data Protection Commission, though you may also contact the authority in your own country.
11. Your Privacy Rights (California / CCPA)
If you are a California resident, you have the right to know what personal information we collect and how it is used; to request deletion or correction of your personal information; and to non-discrimination for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. To make a request, contact support@getgiga.com.
12. Legal Disclosures
We may disclose your personal data if we believe in good faith that it is necessary to comply with a legal obligation, respond to valid requests by public authorities (such as a court or government agency), protect the rights, property, or safety of Giga, our users, or the public, or investigate possible wrongdoing in connection with the Service.
13. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the Service.
15. Contact Us
If you have questions or comments about this Privacy Policy, or wish to exercise your rights, contact us at support@getgiga.com or by post to Tonic Labs Limited, Ireland.
Last updated: July 2026
© 2026 Tonic Labs Limited. All rights reserved.

