Data protection
Privacy Policy
This policy explains how Turbine uses data sparingly, why we process it, and how users stay in control of connected sources.
Last updated: June 23, 2026
Controller and contact
Turbine is currently operated from Switzerland by its founders. Until a Swiss company name is published here, the Turbine founding team is the controller for personal data processed through the service.
For privacy questions, access requests, correction requests, deletion requests, or objection requests, contact privacy@turbine.so.
Data minimisation and user control
Turbine is designed around data minimisation and user control. We aim to process only the personal data reasonably necessary to provide the features you choose to use, keep the service secure, comply with law, and support the product.
Connecting an integration is optional. If you do not connect a source, Turbine will not access that source. You can disconnect integrations at any time, and Turbine will stop future access to that source unless you reconnect it.
Some features may stop working or become less accurate when an integration is disconnected, because Turbine can only plan from the sources it is allowed to see.
Data we may process
Depending on the features and integrations you enable, Turbine may process the following categories of data. We do not collect all of these categories from every user.
Account data: name, email address, authentication identifiers, organization or workspace information, settings, preferences, and support messages.
Connected-source data: only from integrations you authorize, and only to the extent needed for enabled Turbine features. This may include calendar events and busy times, task and project data, issue data, email metadata, email snippets or message content where authorized, participants, collaborators, and source links.
Product data: chat messages, approvals, generated plans, scheduled blocks, action history, activity logs, onboarding choices, feedback, and usage events created while using Turbine.
Technical data: device and browser information, IP-derived approximate location, logs, security events, error traces, and cookie or local-storage state needed to operate, secure, and debug the app.
Why we process data
We process data to provide Turbine features you use: syncing authorized sources, building schedule context, generating day plans, answering questions, showing relevant work, creating approved actions, and keeping the workbench accurate.
We also process data where reasonably necessary to secure the service, debug issues, prevent abuse, communicate with users, improve product quality, comply with legal obligations, and enforce our terms.
AI and model providers
When Turbine uses AI or model providers, we aim to send only the context needed for the requested feature or background workflow. This may include selected prompts, conversation context, schedule facts, task facts, or connected-source excerpts relevant to the assistant response.
We do not intentionally send entire connected accounts where a narrower excerpt is sufficient. We do not sell user data or use Google user data for advertising.
Google user data
Turbine accesses Google user data only after you authorize a Google integration and only for the Turbine features connected to that authorization. If you do not connect Google, Turbine will not access Google user data.
If you connect Google services, Turbine uses Google user data only to provide and improve user-facing Turbine features such as calendar availability, scheduled task blocks, email context, and source-aware assistant responses.
You can revoke Google access through Turbine or your Google Account settings.
Turbine's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Legal basis and consent
Under Swiss data protection law, we process personal data transparently, proportionately, and for the purposes described here. Where consent is required, for example when connecting an integration, you can withdraw it by disconnecting the integration or contacting us.
If the EU or UK GDPR applies to a specific use, we rely on performance of a contract, consent, legitimate interests, and legal obligations as appropriate.
Sharing and subprocessors
We do not sell personal data. We share personal data with service providers only where reasonably necessary to operate, secure, support, or improve Turbine, or where required by law.
These service providers may include hosting, database, authentication, analytics, error monitoring, email, model, and integration providers.
We may also disclose data if required by law, to protect users or the service, in connection with a company transaction, or with your direction or consent. Our subprocessor list is available at /subprocessors.
International transfers
Turbine is operated from Switzerland, but some providers may process data in other countries. Where required, we use adequacy decisions, contractual safeguards, or other lawful transfer mechanisms.
Retention and deletion
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required for legal, security, backup, or dispute-resolution reasons.
Where practical, we delete or anonymise data that is no longer needed.
You can request deletion by contacting privacy@turbine.so. Some records may remain for a limited time in backups, logs, audit records, or where retention is required by law or security needs.
Your rights
Depending on applicable law, you may have rights to access, correct, delete, receive, restrict, object to, or ask for information about personal data processed by Turbine.
We may need to verify your identity before acting on a request, especially where connected-source data or workspace data is involved.
Security
We use technical and organizational measures designed to protect personal data, including encrypted transport, restricted access, OAuth token protections, logging, and operational controls.
No system is perfectly secure. If we identify a data security breach that likely creates a high risk for affected people, we will handle notifications according to applicable law.
Children
Turbine is not intended for children. Do not use Turbine if you are not old enough to use productivity, email, calendar, or work-management services under applicable law.