Privacy policy

1. Who we are and whose data this is

argain is software that helps a business follow up on overdue invoices owed by its business customers. When a business uses argain (we call it "our customer"), it chooses which systems to connect and decides what argain does with that data. We handle that data on our customer's behalf, to run argain for them.

For our website, and for running our own business (for example, replying when you email us), we decide how the data is used.

2. Our website

Our website doesn't use analytics, advertising or tracking cookies. If you email us, we receive your email address and message and use them to reply.

The workspace uses your browser's storage only to keep you signed in and to remember things like an unsent draft or a layout choice.

3. What argain handles when a business uses it

DataExamplesWhere it comes from
Account detailsName, work email, role, sign-in records, two-step verification settings, approvalsYou and your company
Accounting dataYour company record, customers, contacts (name, email, role), invoices, payments, credit notesThe accounting system your company connects. argain reads it and doesn't post entries to it.
Mailbox dataEmail messages (sender, recipients, subject, headers and plain-text body) and attachments that pass a malware check. For Gmail this is every message except spam and trash; for Microsoft 365, the folders your company selects.The company mailbox your company connects
Documents and evidenceContracts, purchase orders, timesheets, proof of deliveryFiles your users upload or import
Records argain createsCase history, drafts, AI interpretations of replies, approvals, audit recordsargain, as your team works
Connection credentialsTokens that let argain reach the systems you connectThe provider, when your administrator connects it. Stored encrypted.

Sign-in runs on Firebase Authentication, a Google service. If you sign in with a password, it goes to Firebase directly; argain never sees or stores it.

argain is not meant for payment card numbers, bank sign-in details, health data or debts owed by individuals. Some of this may still arrive inside an email or attachment.

4. How we use it

  • To run argain for our customer: bring invoices, replies and evidence together, suggest the next step, draft follow-ups, and, where your company has turned sending on, send the emails your team approves.
  • To keep argain and our customers' data secure, and to investigate problems.
  • To meet legal obligations.

Playbook learning is optional and stays off until your company agrees to a separate notice. It studies your past reminders and the payments that followed, to suggest a draft collection playbook that a person reviews before anything changes. Its results keep only derived facts such as dates, amounts, labels and reply types, not email subjects or text, and they stay inside your company's workspace. A temporary encrypted working file exists only while a run is in progress. Withdrawing the agreement deletes the results at once, and so does disconnecting the mailbox (for Microsoft 365, at our next background check). Playbook learning doesn't train or fine-tune any AI model.

We don't sell personal data, we don't use it for advertising, and we don't use our customers' data to train or fine-tune AI models.

5. Google user data

When your company connects a Gmail or Google Workspace mailbox, argain asks Google for:

  • Read access to email (gmail.readonly) and your email address. argain copies the mailbox's messages (except spam and trash) and their attachments into your workspace, to link customer replies to the right invoices and cases, notice disputes, payment claims, requests to stop and bounced emails, and show them to your team. This includes older mail, and mail that has nothing to do with your customers: argain sets that aside but doesn't delete it. Only company Google accounts can be connected, not personal gmail.com addresses.
  • Permission to send email (gmail.send), only if an administrator chooses to allow sending. argain then sends the emails your team approves, from your mailbox, in your name.

argain doesn't change, label or delete anything in your mailbox. Google user data is used only to provide these features to your company. In particular:

  • We don't sell it, use it for advertising, or use it to decide anyone's creditworthiness.
  • We don't use it to train AI models, and we don't build copies of it for training.
  • We don't transfer it to others, except the service providers in section 8 that run argain, or where the law requires it.
  • It is our rule that argain staff don't read it unless your company's administrator gives us temporary access for support, or it is needed for security or to comply with the law. Your own team sees it in your workspace as part of the service. The engineers who run argain can technically reach the systems where it is stored, so this is a rule we follow, not one the software enforces.

You can disconnect the mailbox in argain. argain then stops reading, asks Google to revoke its access and deletes the access token it holds. If Google doesn't confirm the revocation, argain tells you, and you can remove the permission yourself at myaccount.google.com/connections. Mail argain has already imported stays in your workspace until you ask us to delete it (see section 12).

6. Microsoft 365 data

When your company connects a Microsoft 365 mailbox, argain uses a Microsoft access token your administrator provides to read messages and attachments in the folders your company selects, and, only if your company turns sending on, to send emails your team approves. The same limits as for Google user data apply.

7. AI processing

argain uses Google's Gemini models on Google Cloud Vertex AI to read replies, suggest next steps and draft messages. For each task, argain sends the model the case facts, the relevant email text and short excerpts of documents. If your company turns on playbook learning, the subject and text of each past reminder in scope may also be sent to the model, to label the reminder's type and tone; argain keeps only the label. The model can't send email, approve anything or change a balance; balances and amounts come from your connected systems and fixed calculations.

8. Who we share data with

  • Google Cloud runs argain for us: hosting, database, file storage, backups, secret storage, AI models (Vertex AI) and sign-in (Firebase Authentication).
  • The services your company connects, such as its accounting system, mailbox, Microsoft Teams or Slack, receive argain's requests as part of the connection your company set up.
  • Others only when the law requires it, to protect people or argain from fraud or security threats, or as part of a merger or sale of our business, in which case this policy would continue to apply to your data.

9. Where data is kept

argain's application, database, files and backups run on Google Cloud in Belgium (europe-west1). AI processing goes through Vertex AI's global endpoint, so it may take place outside the EU. Our team works from Israel and may access data from there when running and supporting argain.

10. How long we keep it

  • Your company's data stays while your company uses argain, unless it asks us to delete it.
  • Imported emails, attachments, case history and audit records don't expire on their own today. They stay until your company asks us to delete them, including after a mailbox is disconnected.
  • Some working records expire on their own: completed background job records after 30 days, attachments still waiting for a malware check after 7 days, and playbook learning results 365 days after the run that produced them.
  • Database backups are kept for 14 days. A stored file that is replaced or deleted stays recoverable for up to 44 days: 30 days as an earlier version, then 14 days in Google Cloud's soft delete.
  • When your company asks us to delete its data, we delete it from the live service within 30 days, unless the law requires us to keep something, in which case we'll tell you. Today our team does this by hand. The data then leaves our backups as they expire: database backups within 14 days, stored files within 44.

11. Security

Data travels over encrypted connections, and Google Cloud encrypts everything argain stores. Credentials for connected systems are also encrypted by argain, with keys held in Google Secret Manager. Access inside a workspace follows the roles your company assigns, sensitive actions need approval, and argain keeps an audit record of what was done and by whom. New companies require two-step sign-in for administrators and approvers, and a company can require it for everyone.

12. Your choices

  • Disconnect any connected system in Settings > Connections. That stops argain's access; it doesn't by itself delete what was already brought in, so ask us if you want that deleted too.
  • Ask us for a copy of your data, or to correct or delete it, by emailing nitai@argain.app. Our team does this by hand today, and we complete it within 30 days of your request.
  • If your details reached argain because you work with one of our customers (for example, you are a contact at a company that owes them an invoice), please contact that customer first. We'll help them answer, and you can also email us.

13. Children

argain is a business tool and isn't meant for children.

14. Changes to this policy

If we change this policy in a way that matters, we'll update the date above and tell our customers by email or in their workspace before the change takes effect.

15. Contact

Questions or requests about privacy: nitai@argain.app.