Privacy Policy
Effective August 8, 2026
AI Den is an internal operating system built and operated by Corsac Vantage LLC. This policy explains what data the application accesses, why it accesses it, where that data goes, and how it is deleted.
1.Who operates this application
AI Den is owned and operated by Corsac Vantage LLC, a limited liability company. The application is used to draft documents, summarize information, and prepare correspondence for human review.
Questions about this policy, or requests relating to your data, go to info@corsacvantage.com.
2.Who uses it today
AI Den is not open to the general public. Access is currently limited to the operator of Corsac Vantage LLC and any individual expressly authorized by the company. The only personal data the application handles today belongs to those authorized users and to the correspondents who appear in their own email, calendar, and document content.
3.Google user data the application requests
Signing in with Google is optional and is used to connect a Google Workspace or Gmail account. When a user connects an account, AI Den requests the following scopes. Access is granted by the user and can be withdrawn at any time.
| Google OAuth scope | Why AI Den requests it |
|---|---|
gmail.readonly | Read message content the user asks the application to work with, so an agent can summarize a thread or draft a reply that responds to what was actually said. |
gmail.compose | Create draft messages in the user's own mailbox for the user to review before anything is sent. |
gmail.send | Send a message the user has reviewed and approved. The application does not send external correspondence without an explicit human approval step. |
drive.readonly | Read documents the user selects, so an agent can use them as source material. The application does not create, modify, or delete Drive files. |
calendar.readonly | Read availability and existing events to answer scheduling questions and prepare meeting material. |
calendar.events | Create or update calendar events at the user's direction, for example when scheduling a meeting the user has asked for. |
4.Limited Use of Google user data
Specifically, and without qualification:
- Google user data is not used to develop, improve, or train generalized artificial intelligence or machine learning models.
- Google user data is not sold, and is not transferred to advertising platforms, data brokers, or information resellers.
- Google user data is not used for advertising, and is not used to build a profile for advertising purposes.
- Human review of Google user data does not occur except where the user explicitly requests it, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized.
- Google user data is used only to provide or improve the user-facing features that the user obtained the data for.
5.Other data the application stores
Alongside any connected Google data, the application stores the material it needs in order to function:
- Account information: the email address associated with the sign-in, and authentication tokens managed by the authentication provider.
- Conversations and agent output: messages exchanged with agents, documents and files those agents produce, and any files a user uploads to a conversation.
- Operational records: an audit trail of which agent performed which action, whether an action was approved or denied, and token and cost usage per run. These exist so activity in the system can be reconstructed and reviewed.
6.Service providers that process data
AI Den is assembled from third-party infrastructure. Data is processed by these providers only to deliver the features described above, and each is bound by its own terms:
- Anthropic, for the language models that generate agent output. Content sent to the Anthropic API for processing is not used by Anthropic to train its models under its commercial API terms.
- Supabase, for the application database, authentication, and file storage.
- Vercel, for application hosting and scheduled jobs.
- Google, where a user has connected a Google account, for the scopes listed above.
- Tavily, for web search and page retrieval when an agent researches a topic. Search queries are sent to this provider.
- ElevenLabs, for optional speech synthesis, where a user chooses to have a response read aloud.
Data is not sold, rented, or shared with any party for that party's own independent purposes.
7.Retention, deletion, and withdrawing access
- A user may disconnect their Google account at any time from the application's settings, or by revoking access directly at myaccount.google.com under Third-party apps and services. Revoking access stops all further data collection immediately.
- A user may request deletion of stored conversations, generated documents, and account data by writing to the address in section 1. Deletion requests are honored within 30 days.
- Operational and audit records may be retained after content deletion where needed to maintain an accurate record of system activity, and are retained no longer than necessary for that purpose.
8.Security
Access to the application requires authentication. Data is encrypted in transit. Database access is governed by row-level security policies, and actions that carry real-world consequence, including sending external correspondence, require an explicit human approval before they execute. No system is perfectly secure, and no assurance is given that a determined attacker could never obtain data.
9.Children
AI Den is a business tool and is not directed to children. It is not intended for use by anyone under 18, and the operator does not knowingly collect personal information from children.
10.Changes to this policy
This policy may be updated as the application changes. The effective date at the top of this page reflects the current version. Material changes affecting how Google user data is handled will be reflected here before the change takes effect.