Privacy Policy
Last updated: September 1, 2026
This Privacy Policy explains how Boring Plugins LLC and its parent company Boring Plugins LTD (together, “everything,” “we,” “us”) collect, use, share, and protect information when you use the everything platform, our website (thetool.company), our Chrome browser extension, and our mobile applications (the “Service”).
Who we are
everything is operated by Boring Plugins LLC, a Delaware limited liability company that handles billing and US operations, and Boring Plugins LTD, our Israeli parent company that develops and operates the platform. For privacy questions, you can reach us at privacy@thetool.company.
Information we collect
Account information
When you sign up, we collect your name, email address, profile picture (if you sign in with Google), workspace name, role, and authentication identifiers. If you subscribe to a paid plan, our payment processor (Stripe) collects payment details on our behalf; we do not store full card numbers.
Customer content
We store the data you create or import into the Service - contacts, deals, notes, tasks, calendar events, email threads, call recordings and transcripts, documents and contracts you send for signature, and skill configurations. This data belongs to your workspace and is processed to provide the Service to you.
Google user data
When you connect a Google account, we request specific OAuth scopes to power features you opt into. We only request the scopes needed for the features you use:
- Gmail (gmail.modify) - read your email threads to display them in the unified inbox alongside your saved contacts; compose and send replies and new emails from inside everything; mark messages read/unread, archive, and apply labels when you take those actions in our UI; subscribe to Gmail push notifications so the inbox stays in sync. We do not permanently delete your email.
- Other contacts (contacts.other.readonly) - read the contacts Gmail auto-saves when you exchange email with someone, so we can suggest them as people to add to your workspace and attribute incoming emails to the right contact record.
- Calendar - read and write calendar events to show your schedule alongside your contacts, create meetings from everything, and attach booking notes to deals.
- Profile and email (userinfo.profile, userinfo.email) - to identify your account and display your name and avatar in the app.
Data from other integrations
If you connect LinkedIn, X (Twitter), Reddit, WhatsApp, Slack, Twilio, Stripe, or other integrations, we process the data those services return to power the corresponding features. LinkedIn, X, Reddit, and WhatsApp traffic is always routed through your own browser via our Chrome extension; we never call those services from our servers.
Usage data
We collect logs about how you use the Service - pages viewed, features used, errors encountered, IP address, browser and device type - to operate, secure, and improve the Service.
The everything Chrome extension
The everything browser extension (Chrome Web Store item ID pgpojghbdfgplkplkmacafjmieiahhkk) is a companion to the everything app. Its LinkedIn connector for AI assistants can be used without an everything account (see below); every other feature requires a signed-in account. Everything the extension captures is sent only to the signed-in user’s own everything workspace. The extension does not send data to any third party, does not sell or transfer user data, does not use or transfer user data for any purpose unrelated to its single purpose, and does not use or transfer user data to determine creditworthiness or for lending purposes. It contains no advertising or third-party analytics code, and it executes no remote code - every script it runs ships inside the extension package.
What the extension collects
- Meeting and screen recordings. When you start a recording, the extension captures the audio and video of the tab you explicitly chose to record - a Google Meet, Zoom, or Microsoft Teams call, or a screen recording you initiate - plus your camera and microphone if you enable them. Recordings are uploaded to your workspace for playback, transcription, and summaries. Nothing is captured unless you start a recording or turn on auto-record for your own meetings.
- Authentication information. The extension reads your everything session cookie for thetool.company so it can call your own workspace API on your behalf and refresh your access token. It also uses the session cookies your browser already holds for LinkedIn, X (Twitter), Reddit, and WhatsApp Web, solely so that actions you initiate run from your own browser as your own signed-in account on those sites. The extension never collects, stores, or transmits passwords, PINs, or security questions, and it never sends third-party session cookies to our servers.
- Your own LinkedIn identity. After installation the extension reads the public identity of the LinkedIn member signed in to your browser (name, headline, profile URL, and photo) and records it against your everything session, so that the LinkedIn connector for AI assistants (Claude, ChatGPT, Codex, and other MCP clients) can act as you. If you have not created an everything account, the extension creates a guest session for this purpose; the guest session holds only this identity and the LinkedIn actions you ask an assistant to run. Creating an account later keeps the same session. Actions run from your own browser on your own LinkedIn account; nothing runs on our servers. While the extension is installed and LinkedIn is open, your session also serves read-only public lookups for other users under the shared enrichment pool described in our Terms (section 7a).
- Website content.When you activate a feature on a supported site, the extension’s content scripts read the part of the page you acted on: LinkedIn profiles, companies, search results, and job posts; X profiles and posts; Reddit posts, comments, and subreddits; Gmail and Outlook messages you read, draft, or send through everything; WhatsApp Web conversations; and meeting metadata such as the meeting title and participant list. On every other website, the only script that runs is a lightweight screen-recording shortcut that reads no page content. The extension does not collect your browsing history or a record of the sites you visit.
- Personal communications.Messages you send or receive on the channels you connect - email, LinkedIn messages, X direct messages, WhatsApp messages, and Reddit posts, comments, and messages - are saved to your workspace’s unified inbox and attached to the matching person record.
- Personally identifiable information. Names, job titles, employers, email addresses, phone numbers, and profile URLs of people whose profiles you choose to save into your workspace.
When you use the Reddit features, the extension uses the Reddit session already present in your browser to read the subreddits, posts, and comments you ask for, and to publish the posts, comments, votes, and subreddit joins that you or your sequences schedule. Reddit blocks requests originating from datacenter IP addresses, so these requests are made from your own browser rather than from our servers. We do not receive your Reddit password, and the extension does not read Reddit content you have not asked for.
How extension data is handled and stored
- Captured data is transmitted over TLS directly to your own everything workspace and is then stored, retained, and deleted on the same terms as the rest of your workspace data - see Data retention and Security below.
- Recordings are uploaded from your browser straight to presigned cloud-storage URLs; they do not pass through an intermediary server.
- Locally in your browser, using
chrome.storage, the extension keeps only: your everything session and access token, your workspace ID and app URL, your preferences (such as whether meeting auto-record is on), cached API identifiers, and a durable queue of pending recording uploads so a recording is not lost if the tab closes or the network drops before the upload finishes. All of it is removed when you sign out or uninstall the extension.
How extension data is shared
Data collected by the extension is shared only with the subprocessors listed under Sharing and subprocessors below, which host and process it on our behalf in order to operate your workspace. It is not shared with advertisers, data brokers, or any other third party, and it is not used to train generalized AI or machine learning models.
How we use information
- To provide, maintain, and improve the Service.
- To personalize the Service to your role, workspace, and workflow.
- To send transactional messages (sign-in links, billing receipts, workspace invitations, security alerts).
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To verify business contact information and keep it current, including contributing verification results to the shared dataset described below.
- To comply with legal obligations.
We do not use the content of your Gmail messages, Calendar events, or other Google user data to train generalized AI or machine learning models. AI features that operate on your data (such as email drafting, meeting summaries, and the AI-powered inbox) process your data on a per-request basis to generate output for you, and that output is shown only to you and your workspace.
Google API Services - Limited Use disclosure
everything’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, with respect to data obtained through Google Workspace APIs (including Gmail):
- We only use Google user data to provide or improve user-facing features that are prominent in the everything user experience.
- We do not transfer Google user data to third parties except (a) as necessary to provide or improve user-facing features that are prominent in our user experience, (b) for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for our internal operations and even then only when the data have been aggregated and anonymized.
Verified business contact data
The Service maintains a shared dataset of business contact information so that it can tell you whether an email address or phone number is current rather than merely plausible. That dataset improves as the Service is used.
When activity in your workspace demonstrates that a business datapoint is accurate, for example a call that connects, a reply that arrives, or a message that is delivered, we record it as verified. When activity demonstrates the opposite, for example a carrier rejecting a number as unassigned or a message hard bouncing, we record it as invalid. Those verification results are added to the shared dataset and are available to other customers, and you receive the benefit of results contributed by others.
What the shared dataset contains:
- Business email addresses and business phone numbers, and the professional profile each belongs to.
- Whether each was found to be valid or invalid, and when.
What it never contains:
- The contents of your communications, your notes, your records, your pipeline, or any other Customer Content.
- Your identity or your organization’s identity as the contributor of a result, or the identity of anyone you do business with.
- Personal email addresses at consumer mailbox providers, which are excluded from the dataset.
Only information the Service itself observed is contributed. Contact data you import from a file or another system is treated as unverified and is not contributed, and contact data we license from third-party providers is used only within your workspace under those providers’ terms.
To ask that a datapoint be removed from the shared dataset, or to ask us not to contribute results from your workspace, contact us using the details at the end of this policy.
Sharing and subprocessors
We share information only with service providers who help us operate the Service, under contracts that require them to protect your data. Our primary subprocessors are:
- Google Cloud Platform - application hosting (Cloud Run), storage, and authentication.
- Supabase - primary database and authentication.
- Anthropic, OpenAI - AI model inference for features that you trigger.
- Stripe - billing and payment processing.
- Backblaze B2 - file storage for documents and attachments.
- Twilio - voice and SMS for the dialer.
- Resend / Postmark - outbound transactional email.
We do not sell your personal information, and we do not share Google user data with third parties for their own marketing or advertising.
Data retention
We retain customer content for as long as your workspace is active. If you delete data inside the Service, we remove it from production within 30 days and from backups within 90 days. If you cancel your account, we delete or anonymize your data within 90 days unless we are required to retain it for legal, tax, or security reasons.
You can disconnect your Google account at any time from your integration settings or by visiting your Google account permissions page. Disconnecting revokes our access to your Google data going forward; data already in your workspace remains until you delete it.
Security
We protect your data with encryption in transit (TLS) and at rest, scoped database access, audit logging, principle-of-least-privilege employee access, and SSO with hardware-key-protected accounts for engineering staff. We are pursuing SOC 2 Type II and follow the Cloud Application Security Assessment (CASA) framework for our handling of restricted Google scopes.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. To exercise these rights, email privacy@thetool.company. We will respond within the time frames required by applicable law (typically 30 days under GDPR; 45 days under CCPA).
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to lodge a complaint with your local data protection authority. If you are a California resident, you have the right not to be discriminated against for exercising your privacy rights.
International transfers
We are based in the United States and Israel, and we use service providers in those and other jurisdictions. When we transfer data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses or other approved transfer mechanisms.
Children
The Service is not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Cookies and tracking
We use first-party cookies and similar technologies for authentication, security, and product analytics. We do not use third-party advertising cookies. You can manage cookies in your browser settings.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the Service at least 30 days before they take effect. Your continued use of the Service after the effective date means you accept the updated policy.
Contact
Questions or requests? Email privacy@thetool.company. You can also write to us at:
Boring Plugins LLC
Attn: Privacy
8 The Green, Suite #14483
Dover, DE 19901
United States