01Who we are
Gigi (Gigi, we, us) is a relationship intelligence platform that helps you structure, search, and share your personal and professional network to facilitate trusted, consent-based introductions.
This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. It covers the Gigi website (including the beta waitlist) and the Gigi product. Gigi is the data controller for the processing described here, unless stated otherwise.
02Who can use Gigi
Gigi is intended for individuals aged 18 or older. By using the Service you confirm that you meet this requirement.
03Data we collect
Data you provide directly.
- Waitlist: the email address you submit to join the beta waitlist.
- Account: name, email address, and profile details you confirm during onboarding.
- Content: introduction requests, asks, notes, drafts, shortlists, and other content you create in the product.
- Correspondence: messages you send to us, for example support requests.
Data from accounts you connect. With your explicit consent, Gigi connects to accounts such as Google to power core features:
- contacts and calendar event metadata (such as attendees and frequency), used to identify existing relationships and estimate closeness,
- email metadata and, only for features you actively invoke (such as drafting a message or viewing a thread), email content,
- you can disconnect any account at any time, from Gigi or from the provider's own security settings.
Enriched and public data. We may enrich profiles in your network with publicly available professional information (for example public profile and company data) and data from third-party enrichment providers. Enrichment is contextual and informational. We do not guarantee its accuracy or freshness, and you can ask us to correct or remove it.
Data collected automatically. Log data (IP address, timestamps, pages viewed), device and browser information, approximate location derived from IP, and product analytics events describing how the Service is used.
Sensitive data. Gigi does not require sensitive personal data and does not ask for it. Notes you choose to write may contain opinions or context; they are processed solely to provide the Service, are visible only to the people you share them with, and are never used for profiling or automated decision-making.
04Google user data
Gigi’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data only to provide and improve user-facing features of Gigi,
- we do not use Google user data for advertising,
- we do not sell Google user data,
- we do not use Google user data to train generalized AI or machine-learning models,
- humans do not read your Google data, except with your explicit consent, where necessary for security or abuse investigation, to comply with law, or when the data is aggregated and anonymized for internal operations.
When you send an email through Gigi, it is sent from your own account, and only after you have reviewed and approved its content, recipients, and timing. Gigi never sends messages autonomously.
05How we use your data
- operate, maintain, and secure the Service,
- build and search your network, and estimate relationship closeness,
- surface matches and facilitate introductions, only upon your explicit action,
- help you draft messages, always subject to your review,
- manage the waitlist and contact you about access, launches, and material product news (you can opt out at any time),
- detect, prevent, and investigate abuse, fraud, and security incidents,
- improve product functionality and fix problems,
- comply with legal obligations.
06Legal bases
Where the GDPR or similar laws apply, we process personal data on these bases:
- Contract: operating the Service you signed up for.
- Consent: connecting accounts such as Google, joining the waitlist, and receiving product emails. Consent can be withdrawn at any time.
- Legitimate interests: securing the Service, preventing abuse, and improving the product, balanced against your rights.
- Legal obligation: where processing is required by law.
07AI processing
Some features rely on third-party AI providers operating under data processing agreements.
- your data is not used by us or by our AI providers to train their models,
- AI outputs are assistive and informational only,
- Gigi does not carry out automated decision-making that produces legal or similarly significant effects on you or on the people in your network.
09Data retention
- Waitlist emails: kept until you get access, ask to be removed, or 24 months after your last interaction with us, whichever comes first.
- Account data and content: kept for the life of your account. When you delete your account, personal data is deleted or anonymized within 30 days.
- Backups: residual copies are purged on a rolling schedule within 90 days.
- Logs and security records: kept up to 12 months unless needed longer for an ongoing investigation.
- Data we must keep to comply with legal obligations is kept for the legally required period only.
10Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you,
- correct inaccurate data,
- delete your data,
- receive a portable copy of data you provided,
- object to or restrict certain processing,
- withdraw consent at any time, without affecting prior processing,
- lodge a complaint with your data protection authority.
If you are a California resident, you additionally have the rights to know, delete, correct, and to not be discriminated against for exercising them. We do not sell or share personal information as those terms are defined in the CCPA.
To exercise any right, email clara@gigi.co. We may need to verify your identity before acting on a request, and we respond within the timelines required by law.
11International transfers
Your data may be processed in countries other than your own, including the United States. Where data is transferred out of the EEA, the UK, or Switzerland, we rely on adequacy decisions or standard contractual clauses, together with appropriate technical and organizational safeguards.
12Security
We protect your data with industry-standard measures, including encryption in transit and at rest, access controls and least privilege for our staff, isolated environments, and monitoring. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authorities as required by law.
14Children
The Service is not directed at children and may not be used by anyone under 18. If we learn that we hold personal data of a child, we delete it.
15Changes to this policy
We may update this policy from time to time. We will post the new version here with an updated date, and if a change is material we will notify you, for example by email or in the Service, before it takes effect.
16Contact
Privacy questions and requests: clara@gigi.co