Privacy Policy
Last updated 8 October 2026
Maze CRM (“the app”) is a private, internal client-management tool operated by Maze, a marketing and development agency. It is used only by Maze’s own staff to keep track of clients, budgets, tasks, invoices and client correspondence. It is not offered to the public, and sign-up is not possible.
Who can use the app
Access is restricted to an explicit allow-list of Google accounts belonging to Maze. Anyone else who tries to sign in is signed out immediately, and no data is stored about them beyond what our authentication provider records for the attempted sign-in.
Information we collect
- Account information: when an authorised user signs in with Google, we receive their name, email address and profile picture to identify them.
- Business records: client names, contact details, budgets, tasks, invoices and notes that authorised users enter themselves.
- Google data (optional): if an authorised user chooses “Connect Google”, the app requests read-only access to that user’s Gmail (
gmail.readonly) and Google Drive (drive.readonly), including Shared drives the user is a member of, plus permission to create Google Docs (drive.file, limited to files the app itself creates) and to create email drafts in the user's own Gmail (gmail.compose). The app only ever creates drafts; it never sends email.
How we use Gmail data
Gmail access is used for one purpose only: to show a client’s email history in that client’s activity log. When the user presses “Sync”, the app searches the user’s mailbox for messages sent to or from the email domains the user has set for that client (for example @clientdomain.com), and stores the following for each matching message:
- sender and recipient addresses
- subject line
- a short preview snippet provided by Gmail
- date, message ID and thread ID (used to link back to the message in Gmail)
The app does not read, store or process any other emails, does not store full message bodies or attachments, and never sends, deletes or modifies email.
How we use Google Drive data
Drive access is used only to let the user link specific Drive folders to a client and see what is inside them. The app stores the linked folder’s ID, name, link and (for Shared drives) the drive’s name. File listings — file names, types, last-modified time and who last modified them — are fetched live from Google when the client page is opened and are not stored. Folder search only runs when the user types a search. The app never downloads file contents, and never creates, edits, shares or deletes anything in Drive.
AI-generated summaries and task suggestions
Once a week (or when the user presses “Generate”), the app writes a short status summary for each client. To do this it sends that client’s data from the past 7 days — synced email metadata and snippets, notes, tasks, invoices, and names of Drive files changed that week — to Google’s Gemini API from servers in the EU (Frankfurt). Maze is based in the EEA, where Google applies its paid-service data terms to all Gemini API use: prompts and responses are not used to improve Google’s products. The result is stored in the app and shown only to the authorised user. In the same way, after each Gmail sync the newly synced email metadata and snippets for a client are sent to Gemini to suggest follow-up tasks; suggestions are only added to the task list when the user accepts them. This is a user-facing feature; Google user data is not used to train or improve any AI model.
AI agents
The user can assign a task to an AI agent (for example a marketing, brand or product agent). To complete it, the agent may read that client’s synced emails, list and read the text of files in the client’s linked Drive folders, and search and read public websites. When a client is added, the brand, marketing and product agents do this automatically to research the client (“discovery”). This content is sent to Anthropic’s Claude API for that task only; Anthropic does not use API inputs or outputs to train its models. The agent’s draft is stored with the task and shown only to the authorised user. If the user chooses “Save as Google Doc”, the draft is saved as a new Google Doc in the client’s linked Drive folder. Agents only produce drafts: they cannot send email, publish content or change anything else in Google services.
Meeting notes
The user can paste a meeting transcript or their own notes onto a client. The text is stored with that client and sent to Anthropic's Claude API once to produce a summary, suggested tasks, notes for an offer and a draft follow-up email. If the user chooses “Create draft in Gmail”, the edited email is saved as a draft in their own Gmail for them to review and send. Meeting participants should be told that notes are being taken. Meetings can be deleted at any time, which removes the transcript and summary.
Offer pages and shared learnings
The user can build an offer page for a client together with an agent. Offer pages are private drafts until the user publishes them; a published offer is visible to anyone who has its unguessable link and is excluded from search engines. When the user (or an agent at the user's request) uses a photo from the client's Drive folder on an offer page, a web-sized copy of that one photo is stored in the app's public image storage so the page can show it; other Drive files are never copied. Copies can be deleted on request. The user can unpublish or delete it at any time. Agents can also save short “learnings” (what worked and what didn’t) that other agents read when working for Maze; these are stored in the same protected database and can be deleted on request.
Google API Services — Limited Use
Maze CRM’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide the activity-log, linked-folder, weekly-summary, task-suggestion and AI-agent features described above.
- Google user data is not sold, and is not used for advertising, retargeting or profiling.
- Google user data is not used to develop, improve or train generalised AI or machine-learning models.
- No human reads Google user data except the authorised user themselves, or where needed for security, to comply with law, or with the user’s explicit consent.
- Google user data is not transferred to third parties except the infrastructure and AI providers named in this policy, solely to provide these features.
Where data is stored
Data is stored in a database hosted by Supabase (EU region, Frankfurt), and the app runs on Vercel. Both act as data processors on our behalf. Data is encrypted in transit (HTTPS) and at rest, and database access is restricted by row-level security to the authorised Maze account(s). The Google refresh token that enables Gmail sync is stored in the same protected database and is used only by the app’s server. AI summaries and task suggestions are generated by Google’s Gemini API, and agent drafts by Anthropic’s Claude API, as described above.
Retention and deletion
- Emails and notes can be removed individually from a client’s activity log at any time.
- Deleting a client permanently deletes all of its tasks, invoices and activity entries.
- Linked Drive folders can be unlinked from a client at any time; this does not affect the folder in Drive.
- Google access can be revoked at any time at myaccount.google.com/permissions. On request, we delete the stored token, all synced email data and all linked-folder records within 30 days.
Your rights
Maze is based in Denmark and processes personal data in line with the EU General Data Protection Regulation (GDPR). You may request access to, correction of, or deletion of personal data about you — including if you are a client contact whose emails appear in the activity log. You can also lodge a complaint with the Danish Data Protection Agency (Datatilsynet).
Contact
Questions about this policy or requests about your data: mikkelvasen@gmail.com.