Legal

Storm OS Privacy Policy

What we hold, why, and what you can ask us to do about it. The short version is at the top.

Effective date: August 12, 2026
Last updated: August 12, 2026

Version: 1.0

The short version

  • Your Workspace data is yours. We hold it only to run the product for you.
  • We do not sell or share your data, we do not serve ads, and we do not use your data to train AI models.
  • We ask for the minimum from Google: sign-in identity only. We do not read your mailbox, calendar, files, or contacts.
  • We do not browse your Workspace. Storm OS personnel access Workspace content only when you ask us to for support, or when we must to fix a security or availability incident. Every such session is logged, time-limited, and visible to your Workspace Admins.
  • You can export everything and delete everything, at any time.

The rest of this policy is the detail behind those statements.


1. Who we are and what this covers

On-Call CMO, doing business as Storm OS ("Storm OS," "we," "us"), 239 4th Ave, Ste 1401, Pittsburgh, PA 15222, USA, operates the Storm OS marketing site (storm-os.com) and the Storm OS application (storm-os.app), an installable Progressive Web App for managing customer, investor, and partner relationships.

This policy explains what personal data we handle, why, and what rights you have. It applies to visitors to our site, people who create or join a Workspace, and individuals whose information appears inside a customer's Workspace.

Two different roles. This distinction determines who you should contact about your data:

DataOur roleWho decides how it's used
Account Data: your name, email, sign-in identity, sessions, devices, support tickets, billingController (business)Us. This policy governs.
Customer Data: the records, notes, tasks, files, and configuration inside a Workspace, including information about the people and companies our customers trackProcessor (service provider)Our customer, who is the controller. We act only on their instructions under our Data Processing Addendum.

If your details appear in someone's Storm OS Workspace and you want them corrected or removed, contact that organization directly. If you contact us instead, we will forward your request to the relevant customer and, where the law requires, assist them in responding. See §12.

2. What we collect

2.1 Data you give us

CategoryExamplesWhy
AccountName, email address, password hash (Argon2id; we never store your password), or your Google identity provider subject IDCreate and secure your account
ProfileDisplay name, avatar, role, timezone, locale, notification preferencesPersonalize the app
Workspace configurationWorkspace name, logo, branding, pipelines, custom fields, permissions, sharing rulesRun your Workspace
Customer DataRecords for people and organizations (names, emails, phone numbers, titles, domains), opportunities, notes, tasks, attachments, custom fields, imported filesProvide the Service; you decide what goes in
SupportMessages, screenshots, and diagnostic detail you send usAnswer your questions
BillingCompany name, billing contact, address, tax ID; card details are handled by our payment processor and never touch our serversCharge you, if you are on a paid plan

2.2 Data we collect automatically

CategoryExamplesWhy
Authentication and sessionSession and refresh token identifiers, sign-in timestamps, device and browser summary, IP address at sign-inKeep you signed in; show you your active devices; detect account compromise
Security telemetryFailed sign-in attempts, rate-limit hits, audit log entries (who did what, when, from what device)Protect your Workspace; give your admins an audit trail
DiagnosticsError reports and stack traces, function performance metricsFix bugs and keep the app fast
Push subscriptionsWeb Push endpoint and keys, if you opt in to notificationsDeliver notifications you asked for
Marketing site analyticsWe do not currently run analytics on storm-os.com. We intend to add Google Analytics 4, together with a consent banner, and will update this policy before it goes liveUnderstand what's useful on our site

We do not use advertising cookies, third-party trackers, or cross-site tracking pixels in the application. The application sets only strictly necessary cookies: httpOnly, Secure, SameSite=Lax authentication cookies that keep you signed in. Because they are strictly necessary, no consent banner is required for them; if we ever add non-essential cookies to the marketing site, we will ask for consent first where the law requires it.

2.3 Data from third parties

  • Identity provider (Google): see §3.
  • Payment processor: subscription status and payment outcomes. Card numbers never reach our servers.
  • Data you import: CSV/XLSX files you upload, and information from Integrations you connect. We do not buy contact lists or enrichment data, and we do not append third-party data to your records without you asking for it.

3. Signing in with Google

Storm OS offers "Sign in with Google" so you don't need another password. This section is the full disclosure of what that involves. Google is currently our only third-party sign-in provider. If we add another, we will update this policy before that option becomes available to you.

3.1 What we request

We request identity scopes only:

ProviderScopes requestedWhat we receive
Googleopenid, email, profileYour Google account's unique identifier (sub), email address and whether it is verified, display name, and profile picture URL

We neither request nor can access your Gmail mailbox, your Google Calendar, your Drive files, or your Google Contacts. No message content, no attachments, no meeting data.

3.2 What we do with it

We use this information solely to: authenticate you; create or match your Storm OS account; populate your display name and avatar; and send you transactional email at the address on file. We store the provider's unique identifier, your email address, your display name, and your avatar URL. We do not store tokens beyond what is needed to complete sign-in, and we do not use provider data for advertising, profiling, or model training.

3.3 Google API Services User Data Policy and Limited Use

Storm OS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:

  • Use Google user data only to provide or improve user-facing features that are prominent in the Storm OS interface;
  • Do not transfer Google user data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with the user's explicit prior consent;
  • Do not use Google user data for serving advertisements of any kind, including retargeting, personalized, or interest-based advertising;
  • Do not sell Google user data; and
  • Do not allow humans to read Google user data unless we have the user's affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and de-identified.

3.4 If we ever need more

Automatic email capture is on our roadmap. If we build it, mailbox access will be a separate, optional, clearly explained authorization that you can decline while continuing to use sign-in normally. Adding those permissions would require a new consent prompt from Google, so access cannot expand silently. We will update this policy and notify Workspace Admins before any such feature launches.

3.5 Revoking access

You can disconnect Storm OS at any time:

Revoking stops us from authenticating you through Google. It does not delete your Workspace; to delete data, see §11.

PurposeData usedLegal basis (GDPR / UK GDPR)
Provide the Service; create Workspaces; sync your devicesAccount, Workspace configuration, Customer DataPerformance of a contract (Art. 6(1)(b)); for Customer Data, our customer's basis, on their instructions (Art. 28)
Authenticate you and secure accountsAccount, authentication and session dataContract; legitimate interests in security (Art. 6(1)(f))
Detect and prevent abuse, fraud, and attacksSecurity telemetry, audit logs, IPLegitimate interests (Art. 6(1)(f)); legal obligation where applicable
Fix bugs, monitor performance, improve reliabilityDiagnostics, aggregated usageLegitimate interests (Art. 6(1)(f))
Send transactional messages (verification, invitations, notifications you enabled)Account, notification preferencesContract
Send product or marketing emailAccount, marketing site contactsConsent (Art. 6(1)(a)) where required; otherwise legitimate interests, with opt-out in every message
Bill you and keep financial recordsBillingContract; legal obligation (Art. 6(1)(c))
Comply with law and respond to lawful requestsAs requiredLegal obligation (Art. 6(1)(c))

5. What we never do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act. We have not done so in the preceding 12 months.
  • We do not serve advertising in Storm OS, and we do not let anyone pay to influence what you see.
  • We do not use Customer Data to train, fine-tune, or evaluate machine-learning or generative AI models, ours or anyone else's.
  • We do not disclose Customer Data to third parties except as described in §7.

6. Who can access Workspace data

This is the part most people actually want answered, so here it is plainly.

Access is limited to:

  1. Authorized Users of your Workspace. What each one sees is governed by your Workspace's org-wide defaults, ownership, admin sharing rules, and individual record shares. Every record has an access explainer showing who can see it and why. Workspace Admins have full access to Workspace content by design, and their actions are audited.
  2. Integrations you connect. Only the data required for that integration, only after a Workspace Admin authorizes it, and only for as long as it stays connected.
  3. Our subprocessors (§8). They process data on our documented instructions, under contract, with no right to use it for their own purposes.
  4. Storm OS personnel, narrowly and on the record. We do not browse Workspaces and we have no general-purpose window into your data. Our staff may access Workspace content only in these situations:
  • You ask us to. Support may start a time-limited session acting as your user to reproduce a problem. Every session requires a stated reason, is capped at 60 minutes, displays a persistent banner in the app, is recorded in our platform audit log, and appears in your own Workspace audit log so your admins can see exactly who accessed what, when, and why.
  • Security or availability incidents. Where we must investigate abuse, a breach, data corruption, or a serious outage, access is limited to what the investigation requires, is role-restricted, and is audited the same way.
  • Legal compulsion. See §7.

Support sessions cannot change your password or email address, and cannot export your data, unless the operator holds an explicitly elevated support permission. Routine engineering does not use production Workspace data; development and testing run against synthetic seed data.

These limits are enforced technically as well as contractually: every row in our database carries a workspace identifier, Postgres row-level security is applied as defense in depth, access is resolved server-side by a single authorization module on every read and write, and audit writes are append-only.

7. When we disclose data

We disclose personal data only:

  • To subprocessors who help us run the Service (§8).
  • At your direction: to Integrations you connect, or to recipients you share with.
  • For legal reasons: to comply with a valid legal process, or to protect the rights, safety, or property of Storm OS, our customers, or the public. Where we are legally permitted, we will notify the affected customer before disclosing Customer Data so they can seek protective relief. We will push back on requests that are overbroad or defective.
  • In a business transfer: if we are involved in a merger, acquisition, financing, or sale of assets, data may transfer to the successor, which will remain bound by this policy or give notice before any material change. Google user data would transfer only with the affected user's explicit prior consent (§3.3).

8. Subprocessors

We use a small number of vendors to operate the Service. Current subprocessors:

SubprocessorRoleDataLocation
Netlify, Inc.Application hosting, serverless functions, CDN, blob storage for attachments and exports, and error and performance monitoringAll Service data in transit; attachments and files at rest; diagnostic dataUSA
Neon, Inc.Serverless Postgres databaseAll Workspace data at restUnited States and Germany
Resend, Inc.Transactional email (verification, invitations, notifications)Recipient email address, message contentUSA
Google LLCIdentity provider, if you sign in with GoogleSign-in identity onlyUSA
Stripe, Inc.Subscription billing and payment processingBilling contact name, email, address, tax ID, payment statusUSA

We maintain the current list at [https://storm-os.app/subprocessors] and will give Workspace Admins at least 30 days' notice before adding a new subprocessor that processes Customer Data, with an opportunity to object.

9. International transfers

Storm OS is operated from the United States. Customer Data is hosted in the United States and Germany. Wherever your Workspace is hosted, our personnel, support, and administrative systems are located in the United States, so operating the Service involves processing your data in the US and in other countries whose data protection laws may differ from your own.

Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on:

  • the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, or the Swiss equivalent), executed in our Data Processing Addendum, as our primary transfer mechanism;
  • supplementary technical and organizational measures, including encryption in transit and at rest, tenant isolation, least-privilege access, and a policy of challenging overbroad government requests; and
  • where a subprocessor holds a valid certification, the EU-US Data Privacy Framework and its UK Extension and Swiss-US Framework, as an additional basis.

A copy of the relevant transfer mechanism is available on request at privacy@storm-os.com.

Storm OS is not currently self-certified under the EU-US Data Privacy Framework. Standard Contractual Clauses are our own transfer mechanism; the Framework is relevant only where a subprocessor is separately certified.

10. Security

We design for hard tenant isolation and least privilege. Our current measures include:

  • In transit: TLS 1.2+ everywhere; HSTS.
  • At rest: encryption at the storage layer for the database and blob storage.
  • Credentials: passwords hashed with Argon2id with a strength requirement; passwords are never stored or logged in readable form.
  • Sessions: short-lived access tokens plus rotating refresh tokens in httpOnly, Secure, SameSite=Lax cookies that are never readable by JavaScript; token-reuse detection invalidates the whole session family; per-device sign-out and "sign out everywhere."
  • Multi-factor authentication: optional TOTP per user; Workspace Admins can require it for everyone.
  • Tenant isolation: every row is workspace-scoped, Postgres row-level security applied as defense in depth, cross-tenant access tested in CI as a failing-closed test.
  • Authorization: a single server-side module resolves access on every read and write, including search, reports, and offline sync, so clients never receive rows they aren't entitled to.
  • Files: attachments and exports are stored privately and served only through short-lived signed URLs; nothing is publicly addressable.
  • On your device: offline data is scoped to user and Workspace and wiped on sign-out; an optional app lock re-authenticates after inactivity; revoking a session remotely takes effect on the device's next connection.
  • Operations: brute-force and rate limiting, append-only audit logging, error and performance monitoring, automated dependency vulnerability scanning, an automated test suite that gates every deployment and includes denied-path authorization tests on every endpoint, and least-privilege access for personnel bound by written confidentiality obligations. We have not yet commissioned an independent third-party penetration test. When we do, we will say so here and make the summary available to customers on request.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected Workspace Admins without undue delay and in any event within 48 hours of becoming aware, matching our contractual commitment in DPA §9, and will notify regulators and individuals where required by law. Report suspected vulnerabilities to security@storm-os.com.

11. How long we keep data

DataRetention
Customer Data in an active WorkspaceUntil you delete it or close the Workspace
Deleted recordsSoft-deleted with restore from the Recycle Bin for 30 days, then purged
Workspace after terminationExportable for 30 days, deleted from active systems within 30 days after that
BackupsRolling 35-day expiry; deleted data ages out of backups on that cycle
Workspace audit log400 days
Relationship score history400 days
Offline sync mutation records30 days
Account DataFor the life of the account, then 90 days
Security and authentication logs12 months
Billing and tax records7 years, as required by law
Support correspondence24 months

12. Your rights

If you are an Authorized User or account holder, you can view and update most of your data directly in the app: profile and preferences, active sessions and devices, notification settings, and Workspace export. For anything else, contact privacy@storm-os.com.

Depending on where you live, you may have the right to: access your personal data; correct it; delete it; obtain a portable copy; restrict or object to processing (including profiling); withdraw consent; opt out of the sale or sharing of personal information and of targeted advertising (we do neither); limit the use of sensitive personal information (we do not collect it for the purposes the law targets); and appeal a refused request. We will not discriminate against you for exercising these rights.

To exercise a right, email privacy@storm-os.com. We will verify your identity by confirming control of the email address on the account, or by other proportionate means. We respond within 30 days (extendable by a further 60 where the law allows, with notice). You may use an authorized agent where the law provides for one.

If your information is in a customer's Workspace, that customer is the controller. Send your request to them. If you send it to us, we will route it to them within 10 business days and support them in responding; we will not unilaterally alter or delete their records.

Complaints. You may lodge a complaint with your local supervisory authority: in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office; in California, the California Privacy Protection Agency or the Attorney General. We would appreciate the chance to resolve it first.

EU/UK representative. Storm OS markets and sells the Service in the United States. Prices are quoted only in US dollars and the Service is offered only in English, so we do not consider ourselves to be offering goods or services to individuals in the EU or UK within the meaning of GDPR Article 3(2), and we have not appointed an Article 27 representative. If we begin actively marketing to the EU or UK, we will appoint one and update this policy before doing so.

13. Children

Storm OS is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@storm-os.com and we will delete it.

14. Automated decision-making

Storm OS computes two relationship scores: a Fit Score from criteria your Workspace Admin configures, and an Activity Score based on recency and type of interactions. Both are decision support. Each is shown with a full breakdown of how it was calculated, and can be manually overridden by your users. They are not used by us to make automated decisions producing legal or similarly significant effects about any individual.

15. Changes to this policy

We will update this policy as the product changes. For material changes we will notify Workspace Admins by email and post an in-app notice at least 30 days before the change takes effect, and update the "Last updated" date above. Where the change requires consent, we will ask for it. We keep prior versions available at [https://storm-os.app/privacy/archive].

16. Contact us

On-Call CMO d/b/a Storm OS
239 4th Ave, Ste 1401, Pittsburgh, PA 15222, USA

Privacy: privacy@storm-os.com · Security: security@storm-os.com · Storm OS has not appointed a Data Protection Officer, as it is not required to do so under GDPR Article 37. Privacy enquiries are handled at the address above.

Questions about any of this go to legal@storm-os.com. Privacy requests go to privacy@storm-os.com, and anything security related to security@storm-os.com.