THE TL;DR
Your data is always encrypted, never sold, and never used to train AI models. Your leads are your leads — and everything is yours to export, anytime.
Our security and privacy commitment
Your data is yours. We protect it with industry best practices and a commitment to privacy.
Your files stay in your tools
Your emails, docs, and calendars keep living where they belong — Gmail, Notion, and your other tools. The Librarian syncs only what it needs to help you, and deletes it when you disconnect a source or delete your account.
No AI Training
We use enterprise LLM APIs designed for security. Your information—including your leads and conversations—is never used to train any models. Ever.
End-to-End Encryption
Your data is encrypted at rest and in transit using using AES-256 encryption for disk storage, the industry-leading standards.
No Human Access
All syncing is done by machines. If something breaks, you must give explicit consent before a human can investigate.
No Deletions Without Consent
The Librarian never deletes anything on its own. Emails, calendar events, etc, can only be deleted after you explicitly approve it.
Your Leads Are Your Leads
Your leads and client data belong to you. We never sell them or share them with other agents, and you can export your data at any time.
Frequently asked questions
We use industry-standard encryption (AES-256) to secure your data both in transit and at rest. All communications between your device and our servers are encrypted using HTTPS/TLS.
Only you can access your data. Our team does not access your information unless you explicitly request support and grant permission. We have strict internal controls and audit logs to monitor access.
Your data is stored securely on servers located in reputable data centers with strong physical and digital security measures. We comply with relevant data protection regulations in the regions we operate.
Yes. You can request deletion of your account and all associated data at any time. Upon receiving a verified deletion request, we will delete your data from our production systems within 30 days. Data in encrypted backup archives will be purged within an additional 90 days.
Yes. Your data is portable. You can request a complete export of your information at any time by emailing privacy@thelibrarian.io — your leads, contacts, and content leave with you.
We do not sell or share your personal data with third parties for marketing purposes. We only share data with trusted service providers as necessary to deliver our services, and they are bound by strict confidentiality agreements.
No — never. Your leads are your business asset, not our product. We do not sell, rent, or trade your leads, your contacts, or any of your data to advertisers, other agents, or anyone else. This commitment is written into our Privacy Policy.
If you discover a vulnerability or have concerns about security, please contact us via email. We take all reports seriously and investigate promptly.
We request only the minimum permissions needed to provide our features. All integrations are designed with privacy in mind, and you can revoke access at any time.
We regularly review and update our security policies and practices to stay ahead of emerging threats and comply with the latest standards.
How it works
No training, no storage, no human in the loop. The Librarian is built with privacy and security in mind.
1
You grant permission
You connect your tools using secure OAuth.
2
Data is processed
The Librarian accesses the contents of your connected services, such as Gmail messages, Calendar events, and Drive files, to power the features you use. We process only what's needed to deliver the requested feature and do not use your content to train generalized models.
3
Query sent to LLM
Your request is securely processed via leading industry safe LLMs. Your data is not used to train the model.
4
Results returned securely
We send back answers or summaries instantly—fully encrypted.
Certification you can count on
From data encryption to strict privacy governance, we continuously invest in robust safeguards so you can use The Librarian with complete confidence.
SOC
SOC 2 Type 1 in Progress
We are completing our SOC 2 Type 1 audit, attesting to the design effectiveness of our security and confidentiality controls. Type 1 report expected Q3 2026. Type 2 will follow over the subsequent observation period.
Google CASA
Google CASA Certified
The Librarian has passed Google’s Cloud Application Security Assessment (CASA), meeting strict requirements for secure user data access and handling.
Google CASA Certified
The Librarian completed Google's Cloud Application Security Assessment (CASA), a third-party security audit required for applications accessing restricted Google API scopes. CASA evaluates controls covering data handling, authentication, encryption, secure development, and incident response.