Privacy policy
Last updated: 2026-09-04
Charles stores the quotes you upload, the conversations you hold with your customers through it, and encrypted credentials for the services you connect. We never read your mailbox, never sell data, and never train models on it.
1. Who is responsible
[RAZÓN SOCIAL], tax ID [CIF], registered at [DIRECCIÓN, CÓDIGO POSTAL, CIUDAD, PAÍS], is the controller of the personal data processed through Charles (usecharles.com).
You can reach us at privacidad@usecharles.com at any time.
2. What we process
We process the following categories of data:
- Account data: your email, your name, and your company's name and settings.
- Quote data: what you import by CSV or from your CRM, including your customers' name, email, phone and company, plus the quote number, amount, date and status.
- Conversation content: the follow-ups you send from Charles and the customer replies that reach our reply address, with subject, body and timestamps.
- Context notes: the text your team writes to guide the drafting.
- Third-party credentials: Gmail and CRM tokens, always encrypted with AES-256-GCM and reachable only from the server.
- Usage and billing data: the count of follow-ups sent and your Stripe customer and subscription identifiers. We never store card details.
3. Why we process it, and on what basis
Account and quote data are processed to provide the service you signed up for, on the basis of performing our contract. Usage and billing data are processed to manage the subscription and to meet legal and accounting obligations.
When you import your customers' data you act as the controller of that data and we act as your processor: we handle it on your instructions and only to provide the service.
4. Google data and Limited Use
If you connect Gmail, Charles requests only the gmail.send, userinfo.email and userinfo.profile scopes. That means we can send messages on your behalf and know your address and name, but we cannot read, search or otherwise access the contents of your mailbox at any time.
Charles's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not use Google data for advertising, we do not sell or transfer it to third parties, we do not use it to train artificial-intelligence models, and we allow humans to read it only where you give explicit consent, where it is necessary for security, or where the law requires it.
You can revoke access at any time from your Google account or from Charles's settings. On disconnection we delete the token we held.
5. Artificial intelligence
To write drafts we send the AI provider the quote details, the conversation history and the context notes. We never send it your credentials or payment data.
We work with providers whose commercial API terms do not allow the content sent to be used to train their models.
Drafts are proposals: no email leaves without a person reviewing it and pressing send.
6. Processors and recipients
We rely on the following providers, each under the data-processing agreements required:
- Supabase — database and authentication.
- Vercel — application hosting.
- Resend — notification delivery and reply reception.
- Google — sending mail through your account, if you connect it.
- Anthropic or OpenAI — generating the drafts.
- Stripe — subscription payments.
- Attio — only if you connect your CRM.
7. Retention
We keep your data while your account is active. If you close it, we delete or anonymise the data within 90 days, except what we must keep by law, such as invoices.
Tokens for connected services are deleted the moment you disconnect the service.
8. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacidad@usecharles.com. We answer within one month.
If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (aepd.es) or to your local supervisory authority.
9. Security
Data is encrypted in transit. Third-party credentials are additionally encrypted at rest with AES-256-GCM and are reachable only from the server, never from the browser. Database access is restricted by row-level policies, so each company reaches only its own data.
10. Changes
We may update this policy. If a change is material we will tell you by email or in the app. Last updated: 2026-09-04.