BreadCRMbs connects your people, projects, and conversations. This policy explains what information we handle, when it is shared with your workspace or connected services, and how to make a privacy request.
Wynkoop Consulting LLC ("we," "us," or "our") operates BreadCRMbs and its related website, CRM, APIs, and companion features (the "Service"). This Privacy Policy applies to information we process through the Service. Our Terms of Service explain the rules for using it.
When an organization uses BreadCRMbs to manage information about its clients, contacts, or members, that organization determines what it uploads and who can access it. We process that workspace content to provide the Service. The organization's own privacy practices may also apply; questions about its use of your information should be directed to it.
1. Information we collect
- Account and membership information. Your name, email address, password in hashed form, invitations, workspace and project memberships, roles, and account recovery information.
- Workspace content. Projects, companies, contacts, opportunities, tasks, notes, instructions, activity, uploaded files, document text and search indexes, and information submitted through imports or webhooks. This can include personal information about other people that you or your collaborators provide.
- Conversations and actions. Prompts, assistant replies, relevant context, attachments, tool requests and results, and records of changes, including the acting user or connected client. Conversation and audit records may contain copies of workspace content.
- Connection information. Connected account details, authorized permissions, access and refresh credentials, synchronization status, external tool configuration, and paired companion device and session information.
- Technical and support information. IP addresses, browser and device details, request timestamps, error and security logs, and information you provide when contacting us.
2. How we use information
We use information to operate the CRM; authenticate users and enforce permissions; store, search, and connect workspace records; import and organize context; provide requested AI responses and actions; synchronize authorized integrations; send invitations, password resets, and service messages; troubleshoot problems; prevent abuse; and comply with legal obligations. We also use operational information to maintain and improve reliability and usability.
Where applicable law requires a legal basis, we rely on performance of our agreement with you, legitimate interests in operating and securing the Service, compliance with legal obligations, or your consent, depending on the activity. Where we process workspace content on an organization's behalf, that organization is responsible for its lawful basis and any required notices or permissions.
3. Google and Gmail
Gmail access is optional and requires Google authorization by a workspace owner or administrator. We request permissions to read email and manage drafts. Google bundles draft creation and sending in the compose permission; BreadCRMbs uses that permission to save drafts for you to review and send in Gmail.
We access the connected email address, message headers (including senders and recipients), subjects, bodies, timestamps, labels, message and thread identifiers, and message payload data returned by Gmail, which may include attachment metadata or inline content. Connecting establishes a starting point without importing existing mail. Hourly syncs retrieve subsequent Inbox and Sent messages and relevant label changes. Reconnecting or recovering from expired Gmail history establishes a new starting point without a historical import. We store imported messages as workspace context for CRM filing, search, follow-up tasks, and authorized assistant use. Draft requests also contain recipients, subjects, and message text.
Imported mail is shared with workspace members who have permission to access it. Relevant email content may be sent to the AI provider or assistant used to work with that context, as described below. Only connect a mailbox you are authorized to use for these shared features.
BreadCRMbs' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace user data policy. We use Google data for the connected, user-facing features. We do not sell it, use it for advertising, or use it to train generalized AI models. Transfers and human access are limited by those policies, including consent-based feature delivery and support, security needs, and legal requirements.
You can disconnect Gmail in Integrations or remove BreadCRMbs access through your Google Account connections. Disconnecting stops future access through that connection; it does not automatically erase mail already imported into BreadCRMbs or drafts already saved in Gmail. See retention and deletion below.
4. AI and other connected services
The built-in assistant uses DeepSeek. When you use it, we send your prompt, relevant conversation history, workspace context retrieved by tools, and tool results to the configured provider to produce responses and perform requested work. Relevant context can include document text, contact details, or imported email. We store conversation and execution records to provide history, track actions, and troubleshoot failures. DeepSeek provides this processing under its Open Platform Terms of Service.
If you connect another assistant, external tool server, or a companion on your computer, that connection can receive the content and action results needed for the features you use, within its authorized access. A companion running on your computer can still send information to its AI provider. Tools may transmit information to an external service when invoked. Those providers' own terms and privacy practices also apply to information they receive.
Choose integrations appropriate for your data and review access before connecting them. You can revoke assistant access in Manage access, disconnect external integrations, and unpair companions using the available controls. Revocation prevents future access through the revoked connection; it does not delete copies a third party has already received. Contact that provider about its retention or deletion practices.
7. Retention and deletion
We retain information while it is needed to provide your account and workspace, preserve requested history, maintain security, meet legal obligations, resolve disputes, or enforce agreements. Retention depends on the record and purpose; there is no single automatic deletion period for all CRM content.
Some in-app deletions hide records rather than immediately erase them, and audit history can retain earlier values. Deleting a document queues removal of its uploaded file, but related audit records or copies in conversations may remain. Removing raw context or disconnecting an integration does not automatically delete derived contacts, notes, tasks, or activity. Backups and operational records may also retain copies until removed through their applicable retention processes.
To request account deletion or erasure of personal information, contact us below and identify the account, workspace, and information involved. We may need to verify your identity and coordinate with the workspace administrator. We will explain any information that must be retained and respond within the time required by applicable law. Deleting a BreadCRMbs copy does not delete the source in Gmail or another connected service.
8. Security and international processing
We use measures designed to protect information, including authenticated access, workspace and project permissions, encrypted integration credentials, and secure transport for the hosted Service. No system or transmission method is completely secure.
We and our providers may process information in the United States and other countries where we or they operate. The location depends on the feature and provider, including the AI service you use; we do not promise that all data stays in one country. Where required, we apply the safeguards required by applicable law for international transfers.
9. Your choices and rights
Depending on your location and applicable law, you may have rights to access or receive a copy of personal information, correct it, request deletion, restrict or object to processing, withdraw consent, or complain to a data protection authority. Withdrawing consent does not affect processing already lawfully carried out. We will not discriminate against you for exercising applicable privacy rights.
Use the available record and integration controls for routine changes, or contact us to make a request, including a request through an authorized agent where permitted. We may request enough information to verify the request. If your information was added by another organization, contact its workspace administrator as well; we can help direct requests concerning content we process for that organization.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information to us, contact us so we can investigate and address it.
11. Changes to this policy
We may update this policy as the Service or our practices change. We will post the revised version here and update the date above. For material changes, we will provide additional notice and obtain consent where required by law.
12. Contact
For privacy questions or requests, contact Wynkoop Consulting LLC at support@wynkoopconsulting.com. Please mention BreadCRMbs and the account or workspace involved.