Free discovery sessionSee which agents would take the admin off your sales team

Privacy Policy

Last updated: August 7, 2026

This policy explains how Go Fig, LLC ("Go Fig", "we", "us") handles personal data. It covers both our website at gofig.ai and the Go Fig application, and it is written for two different audiences: people who visit our site or hold a Go Fig account, and the businesses whose data we process on their instruction.

The two roles we play

Go Fig handles personal data in two distinct capacities, and your rights differ depending on which one applies.

  • As a controller. For website visitors, prospects, and account holders, we decide what personal data we collect and why. Part 1 below covers this data.
  • As a processor. For the business data our customers connect or upload to the platform, the customer is the controller and Go Fig acts on their documented instructions. Part 2 below covers this data. Where a customer has signed a Data Processing Agreement with us, that agreement governs and controls over this policy in the event of a conflict.

Part 1: Data we control

Account and profile data

When you register for an account we collect your name, email address, company name, and optionally your phone number and job title. If you authenticate through Google or Microsoft, we receive your name, email address, and profile image from that provider. We store password hashes, never plaintext passwords.

Billing data

Subscription billing is handled by Stripe. We receive and store your billing email, plan, and subscription status. We do not receive or store full payment card numbers; those go directly to Stripe.

Website and product usage data

We collect standard server log data (IP address, browser type, referring page, timestamps) and product analytics events (features used, pages viewed, actions taken) through PostHog. We use this to understand how the product is used and where it is failing people. We also use cookies for authentication, session management, and analytics. You can disable cookies in your browser, though authentication cookies are required for the application to function.

Marketing and communications

We use Loops for product and marketing email and SendGrid for transactional email such as password resets and alerts. You can unsubscribe from marketing email at any time using the link in any message. Transactional email related to your account cannot be unsubscribed from while the account is active.

Support correspondence

If you contact us, we retain the correspondence and any attachments you send, so we can resolve the issue and improve our support.

How we use controller data

  • To provide, operate, secure, and maintain the website and the application
  • To authenticate you and enforce access controls
  • To bill you and manage your subscription
  • To respond to support requests
  • To understand product usage in aggregate and prioritize improvements
  • To send you service notices, and marketing email you have not opted out of
  • To detect and prevent fraud and abuse
  • To comply with legal obligations

We do not sell personal data, and we do not share it with advertising networks or data brokers.

Part 2: Customer Data we process

What Customer Data is

"Customer Data" means the business data a customer connects, uploads, or generates in the platform, along with the models, metrics, flows, dashboards, and analyses built on top of it. As between Go Fig and the customer, the customer owns their Customer Data. We process it only to provide the service, and on the customer's instructions.

How Customer Data reaches us

  • Direct upload. CSV and Excel files uploaded through the application, stored in Google Cloud Storage.
  • Connectors. Around sixty integrations across accounting, CRM, marketing, sales, ERP, database, and messaging systems. Data movement for these is performed by Airbyte, our sync subprocessor, which reads from the source system and writes into the customer's isolated storage.
  • DataStack live connections. For customers who bring their own warehouse (Snowflake, BigQuery, Azure SQL, PostgreSQL, Databricks and similar), Go Fig queries the warehouse directly and compiles the query to run on the customer's own infrastructure. Results are returned for display. Bulk copies of the warehouse are not made, except where a query joins across two different backends, which requires materializing an intermediate result.

Personal data inside Customer Data

Several connectors read systems that contain personal data about people who are not Go Fig users: customers, employees, contacts, and correspondents of our customer. Mail and calendar connectors (Gmail, Outlook, Google Calendar) and messaging connectors (Slack) can carry message content. CRM and accounting connectors carry contact and transaction records.

The customer decides which connectors to enable and what scope to grant. The customer is the controller for that personal data and is responsible for having a lawful basis to send it to us and for informing the people concerned. Go Fig processes it only to provide the service.

Credentials

OAuth tokens and warehouse credentials supplied by the customer are encrypted at rest using Fernet symmetric encryption, with platform secrets held in Google Cloud Secret Manager. Credentials are used only to perform the syncs and queries the customer has configured.

AI processing

Celeste, Go Fig's AI analyst, uses third-party AI providers to interpret questions and generate queries. Google (Gemini via Vertex AI) is the primary provider on every plan, and OpenAI (GPT) is used on every plan for failover and specific tasks. Anthropic (Claude) is in the routing pool on Pro, Growth and Enterprise; on Starter no data is sent to Anthropic. All are accessed through their business API tiers, whose standard terms provide that data submitted through the API is not used to train the provider's models. We do not use consumer-tier endpoints, and we do not fine-tune any model on Customer Data. Where a provider offers a negotiated zero-retention amendment, we pursue it.

What leaves our infrastructure is your question and session history, structural metadata such as table names, field names and types, and a capped sample of rows, at most 100 per request. Samples are filtered by your role-based permissions before they are sent, then passed through automated redaction covering Social Security numbers, credit card numbers, email addresses and phone numbers. That detection is pattern-based: it catches common formats reliably, but it is not a substitute for data governance and it will not catch personal data in an unusual format. Full table exports, bulk extracts and credentials are never sent. A separate search index, hosted on Google Cloud Vertex AI Vector Search in the United States, holds broader structural metadata and a small number of sample rows so that Celeste can find the right table.

Celeste is read-only by default and generates SELECT queries only. An administrator can opt in to write-back on a per-connector basis, in which case Celeste can create records in and send messages through connected systems, and every write is recorded in an audit log the customer can review. Separately, if you connect your Go Fig organization to an external AI assistant through our MCP server, data flows to that assistant's provider under your agreement with them rather than ours. The same applies to any data you export from the platform.

We review conversation content from real usage to evaluate and improve Celeste's own accuracy. This is internal quality work and it trains no third-party model. Conversations pass an automated screen that excludes any conversation showing signs of personal data, and anything the screen flags is reviewed by a member of our team before it can be used. Customers who want their organization excluded from this entirely can request it at [email protected].

The complete data-flow detail, with worked examples of every category and the full contents of the search index, is set out at gofig.ai/security. The binding version of these commitments is Annex I, Section 6 of our Data Processing Agreement.

Subprocessors

We use third parties to provide the service, including for cloud infrastructure, data sync, AI processing, billing, email, analytics, and error tracking. Each is bound by confidentiality and data protection terms no less protective than our own commitments.

The current list, with the purpose and data category for each, is maintained at trust.gofig.ai/subprocessors. You can subscribe there to be notified when it changes.

Where data is stored

Go Fig runs on Google Cloud Platform in the United States. Application compute runs in the us-east1 region. Customer Data we store is held in Google Cloud Storage's US multi-region location, which replicates it across at least two United States regions and holds it only within the United States. Customers on DataStack keep their data in their own warehouse, wherever that is hosted, and we query it in place.

If you are in the European Economic Area, the United Kingdom, or Switzerland, transferring your data to us means transferring it to the United States. Where required, we rely on the European Commission's Standard Contractual Clauses, which are incorporated into our Data Processing Agreement.

Retention and deletion

We retain account data for as long as your account is active, and afterward as needed to meet legal, tax, and accounting obligations.

On request, or on termination of your subscription, we will make your Customer Data available for export in standard formats for 30 days. After that period we delete Customer Data from our production systems. Encrypted database backups are retained on a rolling schedule of 21 automated daily backups, with a seven-day point-in-time recovery window; backups are never restored to production, and data within them is overwritten as they age out. The outside limit from termination to full expunction is therefore roughly 51 days. We provide written confirmation of production deletion on request.

AI interaction audit logs, which capture the content and context of a request, are retained for 90 days. Server and security logs are retained for up to 12 months.

Usage metering records are retained for seven years, the period our tax and accounting obligations require for financial records. These record what was consumed, not what was said: the model used, token counts, cost and credits for each request, associated with your organization. They contain no query text, no results and no content from your data. The link to the individual user is removed after 90 days, so only organization-level metering persists for the remainder.

Security

Go Fig is SOC 2 Type II certified against the Security trust services category. Data is encrypted in transit using TLS 1.2 or higher, with TLS 1.3 negotiated by default, and at rest using Google Cloud managed AES-256 encryption. Access is governed by role-based controls: organization roles apply on every plan, and table-level and field-level restrictions are enabled on Growth and Enterprise. Multi-factor authentication is available to all users. Tenant isolation is enforced independently at the middleware, database query, storage, and permission layers, so separation does not depend on any single control holding. Our controls are continuously monitored through Vanta, and we commission external penetration testing periodically.

Our SOC 2 examination covered the Security category only. Availability, Processing Integrity, Confidentiality, and Privacy were not in scope, and the auditor expressly excluded the behavior of our AI components from the assurance provided. We describe our AI handling on this page, and in full at gofig.ai/security, because the audit does not speak to it.

No system is perfectly secure and we do not claim otherwise. Full detail is available at trust.gofig.ai. Our SOC 2 Type II report is available under NDA to Enterprise customers. On any other plan you can request a security summary and written answers to specific questions at [email protected].

Incidents

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and no later than 72 hours after becoming aware, with what we know about the nature and scope of the incident and the steps we are taking. Suspected vulnerabilities can be reported to [email protected].

Your rights

If you are in the EEA, UK, or Switzerland

You have the right to access your personal data, correct it, erase it, restrict or object to its processing, and receive it in a portable format. Where we process data on a customer's behalf, direct your request to that customer; we will assist them in responding. We will respond to requests we are responsible for within one month. You also have the right to complain to your supervisory authority.

If you are in California

Under the CCPA and CPRA you have the right to know what personal information we have collected about you and why, to request its deletion, to request correction, and to opt out of sale or sharing. Go Fig does not sell or share personal information as those terms are defined, and has not done so in the preceding 12 months. We will not discriminate against you for exercising these rights.

Making a request

Email [email protected]. We may need to verify your identity before acting, and we will tell you if an exemption prevents us from fulfilling a request.

Children

Go Fig is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

Changes to this policy

We will post any material change here and update the date at the top. Where the change materially reduces your rights, we will give account holders notice by email before it takes effect.

Contact

Privacy questions: [email protected]. Security reports: [email protected]. Legal notices: [email protected].

Go Fig, LLC
25 Goldsmith St, PMB 38
Greenville, SC 29609
United States