← Boomtown

Privacy Policy

Last updated September 22, 2026

Boomtown Control Tower is a governance platform for firms that use AI assistants against their own business data. This policy explains what we access, what we do and do not store, and the controls you keep over your own information.

1. Who this covers

This policy applies to Boomtown Control Tower and the boomtown-ai.com website, operated by Boomtown. Our customers are organizations; the people who use the product are members of those organizations. Where a customer connects a third-party service, this policy describes how Boomtown handles the data reached through that connection.

2. What we access

Boomtown connects to services you already use, and only ever with permission you grant yourself. When you connect an account, Boomtown can read only what that service already allows you to see. There is no administrative override, no impersonation, and no shared or organization-wide mailbox access.

Google Workspace

Boomtown requests the following Google OAuth scopes. All are read-only, and each is requested only for the connector you choose to enable:

ScopeWhat it allowsWhy we request it
gmail.readonlyRead your email messages and settingsSo you can ask questions about your own mail and have the assistant answer from it.
drive.readonlyRead and download your Drive filesSo the assistant can find and reference documents you already have access to.
calendar.readonlyRead calendars you can accessSo the assistant can answer questions about your meetings and schedule.
openid, emailYour account identityTo record which Google account is connected, so access is attributable in the audit log.

Boomtown never requests write, send, modify or delete permission on any Google service. Read-only is enforced twice: by the permission Google grants, and independently inside Boomtown, which blocks any request that is not an approved read.

3. Google Limited Use

Boomtown's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Boomtown does not:

  • use Google user data for advertising of any kind;
  • sell Google user data, or transfer it except as described in this policy;
  • allow humans to read your Google user data, except with your explicit permission, where necessary for security purposes or to comply with applicable law, or when the data has been aggregated and anonymized;
  • use Google user data to train or improve generalized artificial intelligence or machine learning models.

4. What we store — and what we do not

We do not store the contents of your connected accounts. Boomtown does not copy, index, cache or retain your email, files or calendar events. When you ask a question, Boomtown calls the service directly using your own credential, uses the result to answer, and keeps nothing.

One thing to be precise about: if you use Boomtown's own chat, that conversation is saved so you can return to it. An answer in that conversation may quote information the assistant read from a connected service, so that quoted material is stored as part of your chat history. Conversations are private to you, and are deleted when your account is removed.

When you instead use Boomtown through an outside assistant — connecting Claude or ChatGPT to Boomtown — the conversation lives in that assistant, not here. Boomtown retains only the audit record of which tool was called.

What Boomtown does store:

  • Your access credential — held in AWS Secrets Manager, encrypted at rest, never written to our application database and never written to logs. It is scoped to you individually.
  • The identity of the connected account — for example the email address of the Google account you connected, so you and your administrator can see what is connected and to whom.
  • An audit record of each request — who made it, which tool was used, which connector it reached, its data classification, and when. This record captures the fact of the access, not the content returned. Audit records are tamper-evident.
  • Your chat history, if you use Boomtown's built-in chat — the questions you asked and the answers given, so a conversation can be resumed. Private to you; your administrator cannot read another member's conversations.

5. Who else processes this data

Boomtown uses a small number of service providers, and only as necessary to operate the product:

  • Amazon Web Services — hosting, encrypted storage of credentials and application data.
  • Anthropic — the AI assistant that answers your questions. When you ask something that requires data from a connected service, the relevant content is sent to Anthropic's API to generate the response. It is processed to answer that request and is not used to train models.

We do not sell data, and we do not share it for advertising.

6. Retention and deletion

  • Connected-account content — never retained, so there is nothing to delete.
  • Credentials — deleted when you disconnect the connector, when your account is removed, or when your organization ends its agreement.
  • Chat history — kept until you or your administrator delete it, and removed automatically when your account is removed or your organization's agreement ends.
  • Audit records — retained for the life of the customer's account, as they are the governance record the product exists to provide. Deleted on request when the agreement ends, subject to any legal obligation to retain them.

7. Your controls

  • Disconnect at any time inside Boomtown, which removes the stored credential.
  • Revoke directly with Google at myaccount.google.com/permissions, which takes effect immediately and independently of us.
  • Your administrator can permit or revoke Boomtown for the whole organization through their own Google Workspace controls, and disabling your account there invalidates any credential we hold.

8. Security

  • Encryption in transit (TLS) and at rest.
  • Credentials isolated per person; no administrative impersonation path exists.
  • Read-only enforced independently of the permission granted.
  • Tamper-evident, hash-chained audit records.
  • Hardened, least-privilege production runtime.

9. Changes

If this policy changes materially we will update this page and the date above, and notify customers through the product or by email.

10. Contact

Questions about this policy, or a request relating to your data: admin@boomtown-ai.com.