Privacy Policy
Effective June 10, 2026
Empathix ("Empathix", "we", "us") provides a research platform that helps product teams gather qualitative and quantitative insight. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It also explains, in a dedicated section below, exactly how we handle data we access through Google APIs.
1. Information we collect
- Account information. Your name, email address, company, and authentication details when you create an account or sign in.
- Content you connect. When you connect a third party service (for example Google Docs, Google Sheets, Google Analytics, Figma, Notion, or an analytics product) and point Empathix at a specific resource, we read content from that resource so we can generate the research output you requested.
- Usage information. Basic logs and diagnostic data needed to operate, secure, and improve the service.
2. How we access and use Google user data
This section describes specifically how Empathix interacts with data obtained through Google APIs, in line with the Google API Services User Data Policy.
Data accessed
Empathix requests read only access and only to the specific resources you choose to connect. We never request write access. The scopes we use are:
- Google Docs (
documents.readonly): the text content of a document whose link you provide. - Google Sheets (
spreadsheets.readonly): the cell values of a spreadsheet whose link you provide. - Google Analytics, GA4 (
analytics.readonly): aggregated analytics report data for a property you connect.
Data usage
We use the data solely to provide the features you request. Content read from a connected Google resource is supplied as context to AI models that generate UX research insights and that answer your analytics questions in plain language. We do not use Google user data for advertising, and we do not use it for any purpose unrelated to the feature you invoked.
Data sharing
We do not sell Google user data and we do not share it with third parties except the service providers that operate Empathix on our behalf, and only to the extent needed to deliver the feature you requested:
- Anthropic(AI processing): connected content is sent to Anthropic's Claude API to generate your results. It is processed to produce your output and is not used to train models.
- Vercel (application hosting) and Turso (database): host the application and store your account and project data.
- Fly.io: runs the research worker that performs a requested run.
Empathix's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data storage and protection
- OAuth access and refresh tokens are encrypted at rest using AES-256-GCM.
- All data is transmitted over encrypted connections (HTTPS / TLS).
- Each company's data is logically isolated so one customer cannot access another customer's data.
- Access to production systems is restricted to authorized personnel for operation and support.
Data retention and deletion
- We retain your Google OAuth tokens only until you disconnect the integration. Disconnecting it in Empathix (Admin, Integrations, then Disconnect) immediately deletes the stored credential.
- Content read from a Google resource is used to produce the research output you requested and is retained as part of that project for as long as your account is active.
- You can delete a project at any time, and you can request deletion of all of your data by emailing support@empathix.app. We will delete it within 30 days.
- You can also revoke Empathix's access to your Google Account at any time at myaccount.google.com/permissions.
3. How we use information generally
Beyond the Google specific uses above, we use the information we collect to operate and secure the service, authenticate you, provide customer support, communicate with you about your account, and improve the product. We do not sell your personal information.
4. Your rights and choices
You may access, correct, export, or delete your information. You can disconnect any connected integration from the Integrations page, and you can close your account at any time. To exercise these rights, contact us at the address below.
5. Children
Empathix is a business product and is not directed to children under 16. We do not knowingly collect personal information from children.
6. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you.
7. Contact us
For any privacy question or request, contact support@empathix.app.