Privacy Policy

Last updated 28 July 2026

Beforehand is an assistant platform for real estate agents. It reads your email and calendar so it can draft replies in your voice, plan your day, and track your deadlines. Nothing is ever sent on your behalf without your approval.

This policy explains exactly what we access, what we store, how we protect it, who we share it with, and how you cut us off. We have tried to write it in plain language rather than hide behind legal padding.

1. Who we are

Beforehand is operated from Edmonton, Alberta, Canada. You can reach us at hello@getbeforehand.com. We are the data controller for the information described here.

2. Information you give us directly

If you create an account, we collect your name, your email address, and a password (stored only as a secure hash, never in readable form).

If you subscribe, Stripe collects your payment details directly. We store only your Stripe customer reference and your subscription status.

3. Google user data: what we access and why

Beforehand connects to your Google Account only after you authorize it yourself, through Google's own sign-in screen, on your own device. We never see, receive, or store your Google password. Google gives us a revocable access token, not a credential.

We request the following access, and nothing else:

  • View your email messages and settings (gmail.readonly). We read a sample of your recent sent messages to learn how you write, so drafts sound like you. We read incoming client email so we can prepare a reply for you to approve. We read attachments such as purchase agreements so we can flag the dates that matter.
  • Send email on your behalf (gmail.send). We send a message only at the moment you press approve and send. Nothing is ever sent automatically.
  • See the list of calendars you are subscribed to (calendar.calendarlist.readonly). We read your calendar list and its time zone so your daily brief arrives at the correct local hour.
  • View and edit events on your calendars (calendar.events). We read your events so your daily brief and schedule are accurate. We create, move, or cancel an individual event only when you ask us to and confirm it.
  • Basic profile and email address (openid, userinfo.profile, userinfo.email). To identify your account.

We deliberately do not request broader permissions that are available to us:

  • We do not request permission to permanently delete your email. We cannot delete a message or a thread.
  • We do not request permission to modify, label, archive, or organise your mailbox. We read, and on your approval we send. We change nothing else.
  • We do not request permission to share your calendars or change their sharing and access settings, and we cannot delete a calendar.

4. What we store

We are specific about this, because "we store nothing" would be untrue and you deserve better than that. Beforehand stores:

  • a sample of your recent sent messages, used to build your writing-voice profile
  • the incoming client emails that drafts are written in response to, so you have context before you approve
  • contacts you add or import yourself: names, email addresses, and phone numbers. Beforehand never creates contacts from your correspondence
  • calendar events: titles, times, and locations
  • the drafts Beforehand writes for you, and your edits to them

5. How we protect your data

Beforehand handles email and calendar content, so security is designed in rather than added on. This section describes the specific mechanisms in place.

Encryption. All data is encrypted in transit using TLS 1.2 or higher, including every connection between your browser and Beforehand, and every call we make to Google's APIs. All data at rest is encrypted using AES-256.

Where your data lives. Application data is stored in a managed PostgreSQL database hosted on Amazon Web Services in the us-east-1 region. The application runs on Vercel's infrastructure. We do not operate our own servers, and we do not store customer data on personal computers or removable media.

Isolation between agents. Every record is tagged to a single agent and protected by row-level security enforced in the database itself, not only in application code. A query can only ever return rows belonging to the authenticated agent. One agent cannot read another agent's email, calendar, contacts, or drafts under any circumstances.

Google credentials. Beforehand never sees, stores, or handles your Google password. Authorization happens through Google's OAuth flow. The resulting access and refresh tokens are held by our authorization provider, Composio, in encrypted storage. They are never written to our database and never exposed in our application logs. You can revoke Beforehand's access at any time, and access stops immediately.

Who can access your data. Access to production systems is limited to Beforehand's operator on a need-to-know basis, and is used only to operate the service, resolve a support request you have raised, or investigate a fault. Every account with production access is protected by two-factor authentication. We do not grant production access to contractors, advertisers, or any third party. We do not read your email for any purpose other than delivering the features described in this policy.

Least privilege. We request the narrowest Google permissions our features require, and no more. Section 3 lists both what we request and what we deliberately do not.

Model processing. Email and calendar content is sent to Anthropic for the sole purpose of generating your drafts and briefs. It is transmitted over encrypted connections, is not used to train any model, and is not retained for training purposes. See section 7.

Retention and deletion. You can disconnect Google at any time, which immediately revokes our access. On account deletion, your stored email content, calendar data, contacts, and drafts are permanently removed from our systems within 30 days. Encrypted backups are purged on their normal rotation, no later than 30 days after deletion.

Incident response. If we become aware of a breach affecting your Google data, we will notify affected users by email without undue delay, and in any event within 72 hours of confirming the incident, describing what happened, what data was involved, and what we are doing about it. Security concerns can be reported to hello@getbeforehand.com.

6. Who we share it with

We do not sell your data. We do not share it with advertisers. We do not use it for advertising of any kind. We share it only with the service providers we need to run the product:

  • Anthropic (anthropic.com), which powers the drafting engine. Email content and calendar context are sent to Anthropic to generate drafts and answers. Anthropic does not use this content to train its models.
  • Composio (composio.dev), which brokers the authorized connection to Google and holds the access token.
  • Supabase (supabase.com), which hosts our database.
  • Vercel (vercel.com), which hosts the application.
  • Stripe (stripe.com), which processes subscription payments. Your card details go directly to Stripe and never touch our servers; we store only your Stripe customer reference and your subscription status.
  • Resend (resend.com), which delivers our transactional email (welcome, billing, and account notices).

We may also disclose information if we are legally required to. We will tell you if that happens, unless we are prohibited from doing so.

7. Limited Use disclosure

Beforehand's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without qualification:

  • We do not use raw or derived Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
  • We do not transfer raw or derived Google user data to any third-party service that uses it to develop, improve, or train such models. Our drafting provider, Anthropic, does not train on the content we send it.
  • We do not use Google user data for advertising, targeted advertising, credit, or lending purposes.
  • No human at Beforehand reads your email content except where you have explicitly asked us to for support, where it is necessary for security purposes, or where we are required to by law.

Your email is used to serve you, inside your own account, and for nothing else.

8. Cutting us off

Open Settings, choose Connections, and press Disconnect. Access is revoked at Google immediately and syncing stops. It is a real revocation, not a switch in our database.

You can also revoke us at any time from your Google Account's own permissions page at myaccount.google.com/permissions. You are never locked in.

9. Retention and deletion

We keep your data for as long as your account is open. Ask us to delete your account and we delete your data, including your voice profile, stored email content, contacts, calendar events, and drafts, within 30 days. Email hello@getbeforehand.com and it is done.

10. Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Canadian privacy law, including PIPEDA, gives you these rights and we honour them regardless of where you live. Write to hello@getbeforehand.com.

11. Children

Beforehand is a professional tool and is not intended for anyone under 18. We do not knowingly collect data from children.

12. Changes

If we change this policy in a way that materially affects how we handle your data, we will email you before it takes effect. The date at the top always tells you when it last changed.

← Back to the site