Skip to main content
SoundMind

Privacy Statement

Last updated: August 15, 2026

1. Overview

This Privacy Statement explains how BTPHAM LLC, a Pennsylvania limited liability company doing business as SoundMind (“SoundMind”, “we”, “us”, “our”) handles data when you use our product and services (the “Service”).

We act in two roles. For content your organization submits to or connects with the Service (“Customer Data”), we process it on the organization’s behalf and at its direction. For account, billing, and usage data, we decide how and why it is processed. A data processing addendum for business customers is available on request at support@buildsoundmind.com.

2. Your data belongs to you

You retain ownership of your Customer Data. We do not claim ownership over your Customer Data.

3. We do not train AI models on your data

We do not use your Customer Data to train, fine-tune, or improve general-purpose AI models, and we engage our AI providers under terms that do not permit them to use your data to train theirs.

4. We do not sell your data

We do not sell your Customer Data. We also do not share your Customer Data with third parties for their marketing or advertising purposes.

5. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, organization, and role, collected when you sign up or are invited. Sign-in is provided by Stytch, our authentication provider.
  • Customer Data — the content your organization submits or connects. Connected data sources are described in section 6.
  • Usage and device information — logs and interaction data generated as you use the Service, such as pages viewed, actions taken, browser type, and approximate region, used for security, debugging, and product improvement (see section 8).
  • Support communications — messages you send us, such as email to our support address.

6. Connected data sources

The heart of the Service is connecting your organization’s existing workspaces — currently Google Drive, Microsoft OneDrive and SharePoint, and Notion — and building a searchable, canonical knowledge model from them. The same principles apply to every connector:

  • You choose what we see. We access only the files, folders, sites, pages, and databases you explicitly authorize.
  • Access is read-only. We request no permission that can create, modify, or delete anything in your source workspace.
  • One purpose. We process connected content solely to provide the Service to your organization: extracting text and structure, indexing it for search, answering questions with citations, and detecting contradictions between documents.
  • We stay in sync. We periodically re-read authorized content so the Service reflects changes — including removals — in the source.

6.1 Storage and security

We store processed versions of connected content (including extracted text and search indexes) on secure servers, encrypted in transit and at rest, with strict access controls. Content and answers are visible only within your organization’s workspace, subject to the access rules your administrators configure.

6.2 Your controls, retention, and deletion

  • Selective removal: you can remove specific files, folders, pages, or databases from the Service at any time without disconnecting the source.
  • Disconnect: you can disconnect a source at any time, which stops all access to it.
  • Deletion: when you disconnect a source or your organization deletes its account, we delete the associated content from our systems, including processed and indexed copies, typically within 30 days.

6.3 Google Drive

We access the following Google user data through the Google Drive API (including export of Google Docs, Sheets, and Slides content):

  • Files and folders you authorize: file content (documents, spreadsheets, presentations, PDFs, and other supported types), file metadata (names, dates, MIME types), folder structure, and sharing information.
  • Google account information: your email address, used to verify your identity and label the connection in your workspace.

Scopes used: drive.readonly (read-only access to files you authorize) and userinfo.email (your email address). We do not request any scope that allows writing to or modifying your Google Drive.

We use Google user data only as described in this section — to extract, index, search, answer questions over, and compare the documents you authorize — never for advertising, and never to train general-purpose AI models.

You can revoke access at any time from the source card in the Service or through your Google Account permissions page.

SoundMind’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6.4 Microsoft OneDrive and SharePoint

We access the files and folders you select from OneDrive and from SharePoint sites you authorize — file content and metadata (names, timestamps, types, and location) — through the Microsoft Graph API, plus your account’s email address and user principal name to verify your identity and label the connection. Permissions requested: Files.Read.All, Sites.Read.All, User.Read, and offline_access — all read-only; none permit changes to your files or sites.

In organizations that restrict app consent, an administrator may need to approve the connection. You can revoke access at any time from the source card in the Service or through your Microsoft account’s app permissions.

6.5 Notion

We access the pages and databases you select, including their content blocks and attachments, plus your workspace’s name and identifier to label the connection. Our Notion integration is configured with read-content capability only — it cannot create, update, or delete anything in your workspace, and it does not read comments or your workspace’s member directory.

You can revoke access at any time from the source card in the Service or from Settings → Connections in Notion.

7. When we share data

We do not sell your data or share it for marketing purposes. We only share data in the following limited situations:

  • With service providers that help us run the Service and are contractually obligated to protect the data and use it only on our instructions — currently: cloud hosting (Google Cloud, Vercel), sign-in (Stytch), email delivery (Resend), session analytics, and the AI providers that process content to provide features you request (OpenAI, Anthropic, Google, Voyage AI).
  • At your organization’s direction — for example, when an administrator connects a third-party AI application to our knowledge interface, we return answers drawn from your organization’s knowledge to that application, under your organization’s control.
  • For legal reasons if we reasonably believe disclosure is required by law, regulation, subpoena, or court order.
  • To protect rights and safety when necessary to prevent fraud, abuse, or security incidents.

Regarding Google user data specifically: information received from Google APIs is processed in accordance with the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features of the Service, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with user notice.

8. Cookies and analytics

We use cookies that are necessary to operate the Service — primarily to keep you signed in (session cookies set by our sign-in provider, Stytch). We do not use advertising cookies.

To help us debug problems and improve the product, we record activity in the signed-in dashboard — pages viewed, clicks, and interface interactions. Recordings are sanitized in your browser before they are stored: workspace content and other on-screen text are masked, typed input is never captured, and email addresses and numbers are obscured. Recordings are associated with your account email, are used solely for debugging and product improvement, are never used for advertising, and are processed by a session-analytics service provider as described in section 7. Questions or objections: contact support@buildsoundmind.com.

9. Security is our priority

We take security seriously and implement administrative, technical, and organizational measures designed to protect your data. No method of transmission or storage is 100% secure, but we work continuously to improve our security posture.

10. Data retention and deletion

We retain Customer Data for as long as your organization uses the Service; connected-source content is deleted as described in section 6, typically within 30 days of disconnection or account deletion. We retain account, billing, and audit records for as long as needed for legitimate business purposes such as compliance, dispute resolution, and enforcing agreements. You may request deletion of your account and associated data at support@buildsoundmind.com.

11. International data transfers

We are a United States company, and data is processed and stored in the United States and in other locations where our service providers operate. Where the law of your region applies additional requirements to cross-border transfers, we rely on appropriate safeguards, such as contractual protections with our providers.

12. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. Send requests to support@buildsoundmind.com; we will verify and respond as required by applicable law. Content in an organization’s workspace is controlled by that organization — where we process Customer Data on an organization’s behalf, we may refer your request to its administrators.

13. Children

The Service is a business product and is not directed to children under 16. We do not knowingly collect personal information from children.

14. Changes

We may update this Privacy Statement from time to time. When we do, we will update the “Last updated” date above, and if changes are material we will provide notice in the Service or by email.

15. Contact

BTPHAM LLC d/b/a SoundMind · support@buildsoundmind.com.

Privacy Statement