Last updated 19 August 2026

Privacy Policy

Effective date: 15 April 2026.

This Privacy Policy explains how Cypress Labs, Inc., a Delaware corporation ("Cypress," "we," "us," or "our"), collects, uses, and shares information in connection with our websites, applications, and services (collectively, the "Services"). Cypress provides an AI platform that helps business owners understand and operate their businesses. The Services are built for businesses and the people who run them, not for personal or household use.

Our Role: Controller and Processor

We handle personal information in two distinct capacities, and your rights depend on which one applies:

  • As a controller. For information about you as a business owner, team member, website visitor, or prospective customer (your account details, your messages with our agents, your usage of the Services), Cypress decides how and why the information is processed. This policy describes that processing.
  • As a processor. Connected accounts and integrations may include personal information about your own customers (for example, customer names and purchase records from a point-of-sale system). We process that information on your behalf and on your instructions, to provide the Services to you. Your business is responsible for its own privacy obligations to its customers; if one of your customers contacts us about their information, we will refer them to you and support your response.

Information We Collect

Information you provide

We collect information you give us directly, including your name, phone number, email address, business details, and the contents of messages and other communications you exchange with us or with our agents through channels such as messaging apps, email, and our applications.

Business and account data

When you connect a third-party account or integration (for example, a point-of-sale system, payment processor, or messaging provider), we receive data from that account as authorized by you. This may include orders, customers, products, inventory, transactions, and related operational records used to model and report on your business.

Financial account information

If you choose to link a financial account, we use trusted third-party financial data providers to establish the connection on your behalf. Through these providers we may access information such as account balances and transaction history. We use this information solely to provide financial insights back to you and the account owner, and we access only the data needed for that purpose. You explicitly initiate and authorize each connection, and you may disconnect a linked account at any time. We do not receive or store your banking credentials.

Information collected automatically

When you use our websites and applications, we may automatically collect technical and usage information such as IP address, device and browser type, pages viewed, and interactions with the Services. We use cookies and similar technologies to operate, secure, and improve the Services. Where the law requires consent for non-essential cookies, we will ask for it.

How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, and improve the Services;
  • Build and maintain a model of your business and surface insights, reports, and recommendations to you;
  • Communicate with you, respond to requests, and provide support;
  • Personalize your experience and develop new features;
  • Monitor and analyze usage, and ensure the security and integrity of the Services;
  • Comply with legal obligations and enforce our agreements.

Legal bases (UK and EEA)

Where UK or EEA data protection law applies to our processing as a controller, we rely on the following legal bases:

  • Contract. Processing needed to provide the Services you have signed up for, including operating your agent and responding to your messages.
  • Legitimate interests. Improving and securing the Services, understanding how they are used, communicating with business contacts, and running our business, balanced against your rights and interests.
  • Consent. Where we ask for it, such as optional account connections or non-essential cookies. You can withdraw consent at any time.
  • Legal obligation. Processing needed to comply with laws that apply to us.

How AI Processing Works

The Services use large language models operated by third-party AI providers. Content you share with your agent, and business data used to answer your questions, may be sent to these providers to generate responses. Under our agreements with them, these providers may use your information only to provide services to us and are not permitted to use it to train their own models. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as described below:

  • Service providers. We share information with vendors that perform services on our behalf, such as cloud hosting, data storage, artificial intelligence and model providers, financial data providers, identity and authentication providers, messaging and communications providers, and analytics. These providers are permitted to use the information only to provide services to us.
  • At your direction. We share information with third parties when you ask us to or authorize us to do so.
  • Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, property, or safety of Cypress, our users, or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

Data Storage and International Transfers

We store and process personal information on servers located in the United States. If you use the Services from the United Kingdom, the European Economic Area, or elsewhere outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

Where UK or EEA data protection law applies to a transfer, we protect it with appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum, the European Commission's Standard Contractual Clauses, or another mechanism recognized under applicable law, together with additional technical and organizational protections. You can contact us for more information about the safeguards we use.

Data Retention

We retain personal information for as long as needed to provide the Services, to comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer required, we take reasonable steps to delete or de-identify it. You may request deletion of your information as described below.

Security

We implement reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your Choices and Rights

You may disconnect linked accounts and integrations at any time, and you can opt out of marketing communications by using the unsubscribe option in any marketing message or by contacting us.

United Kingdom and EEA

If UK or EEA data protection law applies, you have the right to request access to, correction of, or deletion of your personal information; to receive a copy of it in a portable format; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. To exercise these rights, contact us using the details below. You also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner's Office (ico.org.uk); we would appreciate the chance to address your concern first.

United States

Depending on your state, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to appeal a decision we make about a rights request. We honor these requests as described in this policy regardless of whether a particular state law applies to us. We do not sell personal information or use it for targeted advertising as those terms are defined under US state privacy laws.

If we hold information as a processor for one of our business customers (for example, records about you held on behalf of a business you buy from), we will refer your request to that business and support its response.

Children's Privacy

The Services are not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will take appropriate steps to delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the date above and, for material changes, provide additional notice such as an email or an in-product message. Your continued use of the Services after an update constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, or want to exercise your rights, contact us at [email protected]. You can write to us at Cypress Labs, Inc., attention Privacy.