Legal
Privacy Policy
Last updated: September 11, 2026
SignalIQ is operated by Dr3am Systems LLC ("SignalIQ", "we", "our", "us"), Florida, United States. This policy covers the SignalIQ web application at signaliq.brandconnectai.com and the SignalIQ mobile apps for iOS and Android.
1. Summary
SignalIQ reads the inboxes and direct messages you explicitly connect, scores each message for business-opportunity intent, and surfaces the ones worth your attention.
We do not sell your data. We do not use it for advertising. We do not use your messages to train AI models. We do not track you across other apps or websites.
You can disconnect any account, export your data, or delete your account at any time.
We do not sell your data. We do not use it for advertising. We do not use your messages to train AI models. We do not track you across other apps or websites.
You can disconnect any account, export your data, or delete your account at any time.
2. Information We Collect
Account information. Email address, display name, and authentication identifiers. Authentication is handled by AWS Cognito; we never see or store your password for any third-party provider.
Connected account content. When you connect a mailbox or social account, we access message content, metadata (sender, recipient, timestamp, thread), and attachments-in-reference solely to detect and score business opportunities. Section 3 lists exactly what each provider grants.
Content you create. Deals, notes, saved filters, media-kit assets (including images and video you upload), and replies you approve.
Usage and diagnostics. Product-interaction analytics (aggregated, via PostHog) and crash/performance diagnostics (via Sentry).
Payment information. Processed entirely by Stripe. We never receive or store your full card number.
We do not collect your location, your device contacts, your browsing or search history, health data, or any advertising identifier (IDFA/AAID). We do not present an App Tracking Transparency prompt because we do not track.
Connected account content. When you connect a mailbox or social account, we access message content, metadata (sender, recipient, timestamp, thread), and attachments-in-reference solely to detect and score business opportunities. Section 3 lists exactly what each provider grants.
Content you create. Deals, notes, saved filters, media-kit assets (including images and video you upload), and replies you approve.
Usage and diagnostics. Product-interaction analytics (aggregated, via PostHog) and crash/performance diagnostics (via Sentry).
Payment information. Processed entirely by Stripe. We never receive or store your full card number.
We do not collect your location, your device contacts, your browsing or search history, health data, or any advertising identifier (IDFA/AAID). We do not present an App Tracking Transparency prompt because we do not track.
3. Connected Accounts — Exactly What We Request
You choose which accounts to connect. Each grants a narrow, specific permission set:
We request read access by default. Send permissions are used to deliver a reply you have approved in the dashboard, or, if you have configured an automation (from the Automations tab) to do so, a reply sent by that automation without your review of that specific message — you control this by configuring, editing, or turning off the automation. Disconnecting an account in Settings removes SignalIQ's stored token immediately, so we can no longer read or send through that account; it does not revoke the grant on the provider's side, which you can do from that provider's own account settings.
| Provider | Permissions requested | Why |
|---|---|---|
| Google / Gmail | gmail.readonly, gmail.send, openid, email, profile | Read incoming mail to detect opportunities; send replies (either ones you approve, or, if you configure an automation to do so, ones SignalIQ sends on its own — see Section 3); identify your account. |
| Google / YouTube | youtube.force-ssl | Read channel comments and messages for opportunity detection. |
| Meta / Instagram | instagram_business_basic, instagram_business_manage_messages | Read direct messages to detect brand-deal enquiries. |
| Meta / Facebook Pages | pages_show_list, pages_messaging, pages_manage_metadata | Read Page messages routed to your business. |
| Meta / WhatsApp Business | whatsapp_business_messaging, whatsapp_business_management | Read and reply to business enquiries. |
| TikTok | user.info.basic, dm.read, dm.write | Read direct messages; send approved replies. |
| X (Twitter) | tweet.read, users.read, dm.read, dm.write, offline.access | Read direct messages; send approved replies. |
| r_liteprofile, r_emailaddress, w_member_social | Identify your account and post approved content. |
We request read access by default. Send permissions are used to deliver a reply you have approved in the dashboard, or, if you have configured an automation (from the Automations tab) to do so, a reply sent by that automation without your review of that specific message — you control this by configuring, editing, or turning off the automation. Disconnecting an account in Settings removes SignalIQ's stored token immediately, so we can no longer read or send through that account; it does not revoke the grant on the provider's side, which you can do from that provider's own account settings.
4. Google API Services — Limited Use
SignalIQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described in this policy.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for advertising.
- We do not allow humans to read your Gmail data, except: with your explicit consent for a specific issue you raise with us; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data is aggregated and anonymised.
- We do not use Gmail data to develop, improve, or train generalised AI or machine-learning models. Classification is performed by third-party models under enterprise agreements that contractually prohibit training on our data.
5. How AI Processing Works
Messages pass through a three-tier pipeline designed to minimise what leaves our infrastructure:
Anthropic and Mistral process this data as our sub-processors under enterprise terms that prohibit using it to train their models and require deletion per their retention schedules.
AI classifications are probabilistic and can be wrong. Review anything before acting on it.
- Tier 1 — deterministic pattern matching on our own servers. No message content is sent anywhere.
- Tier 2 — ambiguous messages are classified by Mistral AI or Anthropic Claude Haiku. A truncated snippet is sent.
- Tier 3 — borderline cases only are escalated to Anthropic Claude Sonnet for deeper analysis.
Anthropic and Mistral process this data as our sub-processors under enterprise terms that prohibit using it to train their models and require deletion per their retention schedules.
AI classifications are probabilistic and can be wrong. Review anything before acting on it.
6. Sub-processors
We share data only with the providers below, each under a data-processing agreement:
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
Note: Nylas has been removed as a sub-processor, and Microsoft/Outlook mailbox connectivity is no longer offered. We no longer transmit mailbox content or tokens to Nylas, and no longer request Outlook mailbox access.
| Provider | Purpose | Data |
|---|---|---|
| Amazon Web Services | Hosting, database, storage, authentication | All service data (United States) |
| Anthropic | Message classification and draft generation | Message snippets |
| Mistral AI | Message classification (cost-optimised tier) | Message snippets |
| Stripe | Payment processing | Billing details; we never see card numbers |
| PostHog | Product analytics | Aggregated interaction events, hashed user id |
| Sentry | Crash and performance diagnostics | Error traces, hashed user id |
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
Note: Nylas has been removed as a sub-processor, and Microsoft/Outlook mailbox connectivity is no longer offered. We no longer transmit mailbox content or tokens to Nylas, and no longer request Outlook mailbox access.
7. Security
OAuth tokens are encrypted at rest with AES-256-GCM before storage; we never store third-party passwords. All data at rest is encrypted in AWS DynamoDB and S3. All traffic uses HTTPS/TLS. Access is gated by JWT authentication, per-tenant isolation, rate limiting, CSRF double-submit protection, and a strict Content Security Policy. Multi-factor authentication is available, and enforceable organisation-wide by workspace administrators.
8. Data Retention and Deletion
While your account is active, signals and messages are retained so the product works. Short-lived records (OAuth state, sessions) expire automatically via database TTL.
Disconnecting a connected account (Settings → Integrations → Disconnect) removes the stored access token immediately, so SignalIQ stops reading that account and cannot use it again without you reconnecting. It does not, on its own, notify the provider to revoke the grant on their side — you can additionally do that from the provider's own account settings — and it does not delete signals, messages, or classifications already derived from that account; those follow the account-deletion process below.
To delete your account and its data, email privacy@brandconnectai.com from your account address. A person on our team reviews and processes the request; we will confirm by email once it is done, and can tell you the current expected timeframe when you write in.
Stripe independently retains payment records as required by financial regulation. See Data Deletion for the full procedure.
Disconnecting a connected account (Settings → Integrations → Disconnect) removes the stored access token immediately, so SignalIQ stops reading that account and cannot use it again without you reconnecting. It does not, on its own, notify the provider to revoke the grant on their side — you can additionally do that from the provider's own account settings — and it does not delete signals, messages, or classifications already derived from that account; those follow the account-deletion process below.
To delete your account and its data, email privacy@brandconnectai.com from your account address. A person on our team reviews and processes the request; we will confirm by email once it is done, and can tell you the current expected timeframe when you write in.
Stripe independently retains payment records as required by financial regulation. See Data Deletion for the full procedure.
9. Your Rights
Regardless of where you live, you can access, correct, export, or delete your data, and withdraw consent by disconnecting an account. Export and deletion are handled by our privacy team: email privacy@brandconnectai.com from your account address, or use the request buttons in Settings, which open a pre-filled email. We confirm by email once the request is complete, and we respond within 30 days.
EEA/UK (GDPR). Our lawful bases are contract (delivering the service), legitimate interests (security, service improvement), and consent (connecting an account). You may object to processing, request restriction or portability, and lodge a complaint with your supervisory authority. We respond within 30 days.
California (CCPA/CPRA). You may know, delete, correct, and opt out of sale or sharing — though we do neither — and you will not be discriminated against for exercising these rights.
International transfers. Our infrastructure is in the United States. Transfers from the EEA/UK rely on Standard Contractual Clauses with our sub-processors.
EEA/UK (GDPR). Our lawful bases are contract (delivering the service), legitimate interests (security, service improvement), and consent (connecting an account). You may object to processing, request restriction or portability, and lodge a complaint with your supervisory authority. We respond within 30 days.
California (CCPA/CPRA). You may know, delete, correct, and opt out of sale or sharing — though we do neither — and you will not be discriminated against for exercising these rights.
International transfers. Our infrastructure is in the United States. Transfers from the EEA/UK rely on Standard Contractual Clauses with our sub-processors.
10. Children
SignalIQ is a business tool and is not directed to children. You must be at least 18 to use it. We do not knowingly collect data from anyone under 18; if we learn that we have, we delete it. Please contact us if you believe a minor has provided us data.
11. Cookies
We use strictly necessary cookies for sessions and security (
filter4_has_session, filter4_csrf, Cognito tokens, OAuth state). Optional analytics cookies load only after you consent via our cookie banner, and you can change that choice at any time. We use no advertising or cross-site tracking cookies. See our Cookie Policy.12. Mobile Apps
The iOS and Android apps collect the same categories described above. Our iOS privacy manifest declares: email address, name, user ID, in-app messages, photos/video (media-kit assets), product interaction, and crash/performance diagnostics — none used for tracking. You can delete your account from inside the app, as required by App Store guideline 5.1.1(v). The apps request no location, contacts, microphone, or camera permissions beyond the system photo picker you invoke yourself.
13. Changes
We will post material changes here and notify you by email or in-app notice at least 30 days before they take effect.
14. Contact
Privacy questions or requests: privacy@brandconnectai.com
Data controller: Dr3am Systems LLC, Florida, United States.
Data controller: Dr3am Systems LLC, Florida, United States.