About Connie
Conigma, Inc., operating as Connie ("Connie," "we," "us," or "our") provides the Service. This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices and rights you have.
By using the Service, including by installing or connecting the Connie app for Slack or Zoom, or by connecting the Connie MCP server to an AI assistant, you agree to the practices described in this policy.
Conigma, Inc.
1111B S Governors Ave # 43331
Dover, DE 19904, USA
1. Who this policy covers
This policy applies to:
- Users who create a Connie account and use the web application.
- Workspaces and their members who install or connect the Connie app for Slack or Zoom.
- Users who connect the Connie MCP server to an AI assistant or agent, such as Claude, whether by adding it as a custom connector or by installing it from a connector directory.
- Visitors to our website.
If you use Connie through an organization, your organization's administrator may control certain settings and data, and your use may also be subject to your organization's own policies.
2. Information we collect
Account and profile information. When you create an account, we collect information such as your name, email address, and authentication details.
Connie MCP server and AI assistant connectors. The Connie MCP server lets an AI assistant you choose — for example Claude — read from and act on your Connie workspace on your behalf. Connecting it is always something you initiate, and it operates only within the workspace and permissions attached to your own Connie account.
- Authorization data. Connecting the MCP server runs an OAuth 2.0 authorization flow against Connie. Connie issues the access and refresh tokens that represent your authorization. We do not store the plaintext tokens themselves — we store a hash of each token together with its metadata: the associated workspace and user identifiers, the granted scopes, expiry, and the identity of the client that requested access. This metadata is retained on the schedule in the retention table in Section 6.
- Tool call requests. When the AI assistant invokes a tool, we receive the arguments needed to perform that operation — for example the identifier of a record to read, the fields to write, or the file being imported. We record request metadata, including the tool invoked, timestamps, the workspace and client involved, and the outcome, so that the operation can be executed, audited, debugged, and rate-limited. We do not log the arguments themselves or the data a tool returns. Where a tool call consumes credits, the corresponding credit usage record (the tool, the time, the user who authorized the connector, and the credits used) is kept as part of your workspace's billing history for the life of the workspace.
- Workspace data returned to the assistant. Tools return data from your own Connie workspace, such as records, list contents, message threads, or flow results. This data leaves Connie and enters your conversation with the AI assistant, and is then handled by that assistant's provider under their own privacy policy and terms. Connie does not control the retention or use of data once it has been returned into a conversation on a third-party AI platform. Only the data a tool is asked for is returned; the connector does not push your workspace contents to any assistant on its own initiative.
- Data you send in through the connector. Where a tool accepts data — importing a CSV of contacts, creating or updating records, drafting or sending a message — the content you supply through that tool is stored in your workspace in the same way as data entered through the web application, and is covered by the same retention rules.
What the connector does not do. The connector does not receive, request, or store the contents of your conversation with the AI assistant beyond the arguments explicitly passed to a tool. It does not access the assistant's memory, chat history, conversation summaries, or files you have uploaded to that assistant. It does not read data belonging to Connie workspaces other than those your account is authorized for.
Slack data (when you connect Slack). The Connie app for Slack exists to let you build and run automations that act on Slack. With your authorization through Slack's OAuth flow, and only within the permissions you grant at install time, we process Slack data as follows:
- Automation event records, including channel messages. Connie subscribes to Slack message events for channels the app is a member of (including new messages in public and private channels) in order to power message-based automation triggers such as "new message in a channel." When a subscribed event occurs, Connie receives it at its webhook endpoint and records it in a single events table. Each record contains the event type, timestamps, the relevant Slack team, channel, and user identifiers, and the event payload (which can include message text). These records are the operational input that lets the automation engine evaluate and fire your configured triggers, and let you test triggers in the workflow builder.
- On-demand reads at execution time. When an automation runs, Connie may also read the specific Slack data the automation needs (such as a message, file, or channel detail) directly from Slack's API at that moment, to perform the automation.
- Profile and directory data. We read workspace member profile information, such as names and email addresses, to resolve mentions and identify users referenced by your automations.
Connie does not provide an inbox, search, or message-browsing interface over your Slack content. Stored events are used to operate your automations; they are not rendered back to you as a browsable message archive, and Connie does not offer an export or download of your Slack messages. Stored event records are deleted on the schedule in the retention table below and immediately when you disconnect the integration.
Zoom data (when you connect Zoom). With your authorization through Zoom's OAuth flow, and only within the permissions you grant, we process Zoom data to provide meeting-management features in your workflows: creating, updating, deleting, and viewing Zoom meetings, and reading your Zoom user profile to associate meetings with your account. OAuth tokens for your Zoom connection are held by our integration provider (Nango) and are not stored in our own database; we store only the references needed to operate the integration, such as meeting identifiers and your Zoom user ID.
Meeting recording and call intelligence. If you enable call recording, Connie uses a third-party meeting bot (Recall.ai) to join your scheduled or live meetings on supported platforms (including Zoom, Google Meet, and Microsoft Teams), record audio/video, and generate a transcript. The recording and transcript are processed to produce summaries, action items, and CRM updates. Meeting recordings are retained per the schedule in the retention table below (configurable per workspace) and are deleted when you delete them or close your workspace.
Other connected integrations. If you connect other third-party accounts, we process the data from those services that is necessary to provide the connected features. Where a feature enriches your records using an external data provider, we send that provider only the fields required to perform the lookup and store the result against your record.
Billing information. Payments are processed by our payment provider (Stripe). We receive billing-related event records but do not store full payment card numbers ourselves.
Usage and technical data. We collect log and usage data such as actions taken in the Service, device and browser information, and similar technical information.
3. How we use information
We use the information we collect to:
- Provide, operate, and maintain the Service and its features.
- Evaluate and run the automations and flows you configure.
- Operate the Connie MCP server, authenticate connector sessions, and execute the tool calls an AI assistant makes on your behalf.
- Enforce the scope of a connector authorization, so that an AI assistant can only reach the workspaces and data your account is entitled to.
- Maintain an audit record of connector activity for security, debugging, abuse prevention, and rate limiting.
- Create and manage Zoom meetings on your behalf as part of your workflows.
- Record, transcribe, and analyze meetings you choose to record, and generate summaries, action items, and CRM updates from them.
- Power AI-assisted features such as drafting, summarization, and research.
- Process payments and manage subscriptions.
- Communicate with you about the Service, including support and important notices.
- Monitor, secure, debug, and improve the Service.
- Comply with legal obligations.
We do not use your data, including your Slack content and data accessed through the MCP server, to train AI models. Our own AI features are powered by third-party providers accessed through OpenRouter, which we configure to route only to providers that do not train on the content we send them. Where you connect the MCP server to a third-party AI assistant, that assistant's provider determines how the data returned into your conversation is handled, under their own policies.
4. How we share information
We do not sell your personal information. We share information only as follows:
- Service providers who process data on our behalf to operate the Service, including our database and hosting provider (Supabase), our integration connection provider (Nango), our meeting-recording provider (Recall.ai), our payment provider (Stripe), and our AI model routing provider (OpenRouter) and the AI model providers it routes to. We engage these providers as vendors under our own contractual, security, and data-protection controls.
- AI assistants and agents you connect. When you connect the Connie MCP server to an AI assistant, the workspace data returned by a tool is disclosed to the provider of that assistant as part of your conversation with it. This happens only in response to a tool call, and only for the data that tool returns. These providers are not our vendors and do not process that data on our behalf; their handling of it is governed by their own privacy policy and terms, which you should review before connecting.
- At your direction, with third-party services you choose to connect.
- For legal reasons, where required by law or to protect rights, safety, and the integrity of the Service.
- In a business transfer, such as a merger, acquisition, or sale of assets, subject to this policy.
5. How we store and secure information
Customer data is stored in our database hosted on Supabase, in the AWS eu-central-1 region (Frankfurt, Germany, EU). Tokens issued by Connie for MCP connector sessions are stored as hashes rather than in plaintext. Credentials for third-party integrations are held by our integration connection provider (Nango) or stored encrypted where we hold them ourselves. We apply administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, or misuse. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data retention
We retain information for as long as needed to provide the Service and for the periods described below, after which it is deleted or purged automatically:
| Data type | Retention |
|---|---|
| Deleted records (flows, rows, fields, inbox/Slack conversations) | Permanently purged 7 days after soft-deletion |
| Notifications | Archived after 30 days unread/untouched; archived notifications purged after 180 days |
| OAuth access tokens (including MCP connector sessions) | Deleted 30 days after expiry |
| OAuth authorization codes (including MCP connector sessions) | Deleted 1 day after expiry |
| OAuth refresh tokens (including MCP connector sessions) | Deleted 90 days after revocation or expiry |
| OAuth audit logs | Retained 90 days |
| MCP tool call request logs (tool invoked, timestamps, workspace, client and outcome — never tool arguments or returned data) | Retained for up to 30 days |
| Billing / payment event records | Retained 90 days |
| Meeting recordings | Default 730 days (configurable per workspace) |
| All workspace data | Deleted immediately upon workspace deletion |
| Connected integration data (including stored automation event records) | Deleted immediately when the integration account is disconnected or removed |
| MCP connector authorization | Revoked when you disconnect the connector or revoke access; enforced on the next request, and the stored tokens are then purged per the rows above |
7. Your choices and rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We will respond consistent with applicable law.
Disconnecting the Connie connector. You can disconnect the MCP server from your AI assistant at any time, and you can revoke the authorization from Connie's Connectors page. Revocation is enforced on every request the connector makes, so the assistant's next call is refused and it can no longer read from or act on your workspace; a call already in progress at the moment of revocation completes. The stored tokens are then purged as described in the retention table above. Disconnecting the connector does not delete data already returned into a past conversation on the assistant's platform — to remove that, use the controls your AI assistant provider offers.
Disconnecting Slack. You can remove the Connie app from your Slack workspace at any time from your Slack workspace's app management settings. When the integration is disconnected, the associated stored data is deleted as described in the retention table above.
Disconnecting integrations. You can disconnect Zoom or other connected accounts at any time from Connie's settings, and the Zoom app from Zoom's App Marketplace under Manage > Installed Apps. When an integration is disconnected, the associated stored data is deleted as described in the retention table above.
Closing your account. When a workspace is deleted, associated workspace data is deleted immediately as described above.
8. International data transfers
We may process and store information in countries other than the one in which you reside. Where required, we use appropriate safeguards for such transfers. Where you connect the MCP server to an AI assistant, data returned into your conversation may be processed in the regions that assistant's provider operates in.
9. Children's privacy
The Service is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice.
11. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: support@connie.ai
Conigma, Inc., 1111B S Governors Ave # 43331, Dover, DE 19904, USA