At Figen AI, respecting your privacy and protecting your personal data are our priority.

This privacy policy (hereinafter the "Policy") describes the processing of personal data carried out in connection with the use of the FIGEN OS application (the "Application"), available at app.figenai.com, and in particular its Google account connection feature (Gmail and Google Calendar), in accordance with the GDPR (Regulation (EU) 2016/679) and the amended French Data Protection Act.

It complements the website's general Privacy Policy, our Cookie Policy and the FIGEN OS Terms of Service.


1. Who is the data controller?

The data controller is Figen AI, a SAS registered with the Nanterre Trade and Companies Register under number 939277752, with its registered office at 49 rue de l'Abbé Jean Glatz, 92270 Bois-Colombes, France.

For the data of your own clients that you enter into FIGEN OS, Figen AI acts as a processor on behalf of your firm, under the data processing agreement (DPA) concluded with it.


2. What are FIGEN OS and the Google connection?

FIGEN OS is the workspace for wealth management professionals. It includes an AI assistant, the Super Agent, to which you address requests in natural language.

You may, optionally, connect your Google account to FIGEN OS. This connection allows you to:

  • view your Gmail inbox in FIGEN OS and ask the Super Agent to read, search or summarise your e-mails;
  • ask the Super Agent to draft a reply or a new e-mail, which is sent only after your explicit confirmation;
  • organise your e-mails (mark as read, star, archive, move to trash);
  • view, create, update or delete events in your Google Calendar, for instance to schedule a client meeting.

The connection uses Google's OAuth 2.0 protocol: you authenticate directly with Google, which shows you the list of permissions requested. FIGEN OS never sees your Google password.


3. What Google data do we process?

When connecting, FIGEN OS requests the following permissions from Google:

  • Account e-mail address (userinfo.email): to identify the connected account and display it in your workspace;
  • Read and manage e-mails (gmail.modify): read, search and organise your messages (read/unread, starred, archive, trash). This permission does not allow permanent deletion of messages;
  • Send e-mails (gmail.send): send the replies and messages you have confirmed, from your own address;
  • Calendar events (calendar.events): view, create, update and delete events in your Google Calendar.

The Google data actually processed is therefore: your e-mail address, the metadata of your messages (sender, recipients, subject, date, labels), the content of the messages you view or ask the Super Agent to process, and the calendar events you view or modify.


4. How do we use this data?

No storage of your e-mails

FIGEN OS operates without copying your mailbox. Every read, search, send or organise action is a real-time call to Google's APIs. Your e-mails and events remain hosted by Google; we build no database, archive or backup of them.

The only elements retained by FIGEN OS are:

  • the OAuth access and refresh tokens issued by Google, encrypted in our database, which are required to make calls on your behalf;
  • the e-mail address of the connected account;
  • a short-lived technical cache (message lists: 5 minutes; a single message: 10 minutes; one-line summaries: 4 hours), which avoids unnecessary calls to Google and is purged automatically and whenever the account is disconnected;
  • the excerpts of e-mails or events that the Super Agent returns in a conversation, which are part of that conversation's history in your workspace and which you can delete at any time.

Processing by artificial intelligence

To save you time, FIGEN OS generates a one-line summary of the e-mails displayed in your inbox, and the Super Agent can read, summarise or draft an e-mail at your request. To do so, the strictly necessary elements (subject, sender, excerpt or content of the message concerned) are transmitted, encrypted, to our AI model provider (Anthropic) under its commercial offering: this data is not used to train its models and is not retained by it beyond the processing of the request.

Figen AI never uses data obtained from Google APIs to develop, improve or train generalised artificial intelligence or machine learning models.

Matching with your client records

To tell you that an e-mail comes from one of your clients, the sender's or recipient's address is compared with the e-mail addresses already present in your FIGEN OS client records. This matching is done on the fly and does not result in any storage of the message content.

Limited Use commitment (Google)

FIGEN OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Google user data is:

  • never sold or transferred to third parties;
  • never used for advertising, commercial profiling or creditworthiness assessment;
  • never read by humans at Figen AI, except with your explicit consent, for security purposes (investigating abuse or an incident), to comply with a legal obligation, or in aggregated and anonymised form for internal operations;
  • used only to provide and improve the FIGEN OS features that you see and use.

5. Purposes and legal bases

  • Display your Gmail inbox and calendar in FIGEN OS and carry out your requests (read, search, summarise, send, organise, manage events)

    • Legal basis: performance of the contract
  • Maintain the connection to your Google account (OAuth tokens)

    • Legal basis: performance of the contract
  • Access your Google account

    • Legal basis: your consent, given on Google's authorisation screen, which you may withdraw at any time (see section 9)
  • Ensure the security and proper operation of the service, log actions

    • Legal basis: legitimate interest

Third-party data: the e-mails and events you access contain data about your correspondents (clients, partners). This data is processed at your initiative, under your responsibility as a professional, and solely to carry out the request you make.


6. Who are the recipients of your data?

Your data may be transmitted to the following recipients:

  • authorised Figen AI staff, only in the cases described in section 4;
  • Google, as the provider of your account, with which FIGEN OS communicates through its APIs;
  • our cloud hosting provider (Google Cloud Platform), in regions located in the European Union;
  • our AI model provider (Anthropic), solely for the processing described in section 4;
  • competent authorities upon legal request (courts, police, administration).

Where the use of a processor involves a transfer of data outside the European Union, that transfer is governed by the safeguards provided for in Chapter V of the GDPR (adequacy decision or standard contractual clauses).


7. How long do we keep your data?

  • E-mails and calendar events: not retained; they remain with Google;
  • Technical cache: 5 minutes to 4 hours, then automatic purge; immediate purge when the account is disconnected;
  • OAuth tokens and connected account address: until you disconnect the Google account from FIGEN OS, revoke access from your Google account, or close your FIGEN OS account;
  • Excerpts in the Super Agent conversation history: until you delete the conversation or close your account;
  • Technical and security logs: 12 months maximum;
  • FIGEN OS account data: for the lifetime of your account, under the conditions of the general Privacy Policy.

8. Security

  • Exchanges with Google, with your browser and with our processors are encrypted (TLS);
  • OAuth tokens are encrypted at rest with a dedicated key, separate from the platform's other secrets;
  • The OAuth authorisation flow is protected against tampering and replay (signed state, limited validity, single use);
  • Each user only accesses their own connected Google account; data is segregated per firm;
  • Actions performed by the Super Agent on your mailbox and calendar are logged and time-stamped;
  • No e-mail is sent by the Super Agent without your explicit confirmation in the interface.

9. How to revoke access to your Google account?

You can withdraw access at any time, in two ways:

  • from FIGEN OS: by disconnecting your Google account in your mailbox settings. The OAuth tokens are then deleted and the technical cache is purged immediately;
  • from your Google account: on the Third-party apps with account access page, by removing the access granted to FIGEN OS.

Closing your FIGEN OS account deletes the tokens and associated data. To request the deletion of data concerning you, write to us at the address given in section 10.


10. What are your rights?

You have the following rights:

  • Right to information (Articles 13 & 14 GDPR)
  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to restriction (Article 18)
  • Right to erasure (Article 17)
  • Post-mortem directives
  • Right to withdraw consent (Article 7)
  • Right to portability (Article 20)
  • Right to object (Article 21)

Exercising your rights: Send an e-mail to [email protected]

Proof of identity may be requested in case of reasonable doubt.

Complaint: If necessary, you may lodge a complaint with the CNIL (3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07, France).


11. Changes

We may amend this Policy at any time, in particular in the event of legal or technical developments or changes to the Application's features. Changes take effect on their publication date. You will be informed of any significant change.

Effective date: 05/09/2026