Skip to content

Legal

Privacy policy

Last updated 1 October 2026.

Draft. This text has not yet been reviewed by a lawyer and may change before launch.

Who we are

SmashSSO is operated by SmashSSO LLC (“we”, “us”). This policy explains what personal data we process when you use smashsso.com and the SmashSSO application. Contact: hello@smashsso.com.

What we collect

  • Account data. When you sign in with Google: your name, email address, profile picture and Google Workspace domain.
  • Directory data. With your permission, a read-only copy of your Google Workspace user directory: names, email addresses, job titles, departments, profile pictures and account status.
  • Tool data. For each tool you connect: the session or API token that lets us act for you, the tool's roles, and its members' names, email addresses or usernames and roles.
  • Activity data. A record of the changes you request, the steps taken to carry them out, and screenshots of the tool's admin pages taken during a run.
  • Technical data. Standard server logs such as IP address, browser type and timestamps.

How we use it

To provide the service: to show who has access to what, and to add, change and remove access when you ask. To keep the service secure, to send you alerts you have turned on, and to answer your messages. We do not sell personal data and we do not use it for advertising.

Google user data

SmashSSO's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the directory scope only to list the users in your Workspace. We do not use Google user data to train AI models.

Who processes data for us

  • Vercel hosts the application and runs the isolated browsers used by agents.
  • PlanetScale hosts the database.
  • Anthropic provides the AI model that operates tools' admin pages. Page content and screenshots from those pages, which can include your team's names and email addresses, are sent to it during a run.
  • Cloudflare provides DNS and sends alert emails.
  • Google provides sign-in and the directory.

Security

Sessions, API tokens and Google refresh tokens are encrypted at rest. We do not store the passwords or two-factor codes you use to log in to your tools. See the security page for detail and for the limits of these protections.

Retention

We keep your data while your workspace exists. Disconnecting a tool deletes its stored session or token. You can ask us to delete your workspace and its data at any time by writing to hello@smashsso.com.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. Write to hello@smashsso.com and we will respond within 30 days. If you are an employee whose data appears in a customer's workspace, please contact that customer first; we act on their instructions.

Changes

If we change this policy in a way that matters, we will tell workspace owners by email before the change takes effect.