Legal

Privacy Policy

Effective date: August 19, 2026

This Privacy Policy explains how Baro collects, uses, discloses, and protects information when you use our website, mobile application, connected-inbox tools, and related services.

Information we collect

We collect information you provide when you create and manage a Baro account, including your name, email address, phone number, business name, business profile, services, operating details, qualification priorities, and other business context you choose to provide.

When you connect Gmail or Outlook, we process the connected account identifiers, authorization tokens, mailbox metadata, and email conversations needed to identify customer inquiries and provide Baro’s inbox and assistant features. Baro does not receive or store your email-provider password.

We process customer information contained in eligible conversations, which may include names, email addresses, phone numbers, message content, requested services, timing, location, and other details customers provide. We also create conversation summaries, qualification signals, lead ratings, recommended actions, and handoff notes.

We collect product and technical information such as device or browser type, app version, pages or features used, request identifiers, request status and duration, diagnostic logs, notification tokens, and product events.

If you purchase a subscription, Stripe collects payment details through its payment interface. Baro receives payment-method identifiers and billing and subscription records, such as Stripe customer and subscription identifiers, subscription status, and renewal dates. Baro does not receive or store complete payment-card numbers.

How we use information

We use information to authenticate accounts, connect and synchronize inboxes, recognize customer inquiries, organize conversations and leads, generate or send eligible replies, prepare drafts for review, qualify leads, support owner takeover, deliver notifications, provide customer support, process subscriptions, and maintain the security and reliability of Baro.

Baro uses automated and artificial-intelligence systems to interpret conversations, draft responses, determine whether a useful follow-up is appropriate, summarize lead context, and decide when owner input is needed. Depending on the response mode you select, Baro may send eligible replies automatically or wait for your approval. You can take over conversations and review or change lead information.

We may use product usage events and technical information that do not contain Google Workspace API data to understand product performance, diagnose issues, and improve Baro.

Google Workspace API data, including Gmail message content, metadata, and information derived from that data, is used only to provide or improve the specific user-facing features that you request or enable within Baro.

Baro does not use Google Workspace API data to develop, train, fine-tune, or improve generalized or non-personalized artificial-intelligence or machine-learning models. We do not use customer message content or AI Knowledge free text for advertising profiles.

Connected inboxes

When you connect Google or Microsoft, Baro accesses mailbox data only as needed to provide the features you enable. You can disconnect an inbox through Baro or revoke access through your provider. Disconnecting removes the connected account’s stored authorization credentials and stops future Baro access, but it does not automatically delete conversations, leads, or other information already stored in Baro.

Google Workspace API Data

When you connect a Gmail account to Baro, Baro may access Google Workspace API data including Gmail message content, conversation history, email metadata, and information derived from those messages.

Baro uses Google Workspace API data only to provide or improve the specific user-facing functionality that you request or enable. Depending on the features you use, this may include identifying customer and lead inquiries, retrieving and processing relevant email conversations, understanding conversation context, organizing and qualifying lead conversations, generating responses, sending authorized responses, summarizing conversations or lead information, and supporting user review or takeover of conversations.

Baro does not use Google Workspace API data for advertising, retargeting, creating advertising profiles, selling information to data brokers or information resellers, determining creditworthiness, lending purposes, creating unrelated databases, or other purposes unrelated to Baro’s user-facing functionality.

Baro does not use Google Workspace API data, including raw, aggregated, anonymized, or derived data, to develop, train, fine-tune, or improve generalized, foundational, or non-personalized artificial-intelligence or machine-learning models.

Relevant Google Workspace API data may be transferred to service providers only when necessary to provide or improve the specific Baro functionality requested or enabled by the user, maintain the security and reliability of the service, or comply with applicable law.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Artificial Intelligence Processing

Baro uses OpenAI as a third-party artificial-intelligence service provider to support certain user-facing features.

When necessary to provide functionality requested or enabled by the user, Baro may send relevant conversation and business context to OpenAI to perform tasks such as understanding a customer or lead conversation, qualifying a lead, generating a response, summarizing conversation or lead information, or determining whether user input is needed.

Baro does not send Google Workspace API data to OpenAI for the purpose of developing, training, fine-tuning, evaluating, or improving generalized or foundational artificial-intelligence or machine-learning models.

Google Workspace API data is transferred to OpenAI only as necessary to provide Baro’s specific user-facing functionality.

How information is shared

We share ordinary account, business, billing, product-usage, and technical information with service providers that help us operate Baro, including infrastructure, database, authentication, product analytics, application logging, push notification, customer-support email, and payment providers. Google Workspace API data is transferred only as described in the Google Workspace API Data section and is not shared with product analytics providers.

We share connected-inbox and conversation information other than Google Workspace API data with email integration, delivery, and artificial-intelligence service providers when needed to provide the Baro features requested or enabled by you. Transfers of Google Workspace API data are limited as described in the Google Workspace API Data and Artificial Intelligence Processing sections.

We may disclose information other than Google Workspace API data when required by law; to protect the rights, safety, and security of Baro, our users, customers, or others; in connection with a merger, financing, acquisition, or sale of assets; or when you direct or consent to the disclosure. Google Workspace API data is disclosed only as described in the Google Workspace API Data section.

We do not sell personal information for money. We also do not share personal information for cross-context behavioral advertising.

Data retention and security

We retain account, business, conversation, lead, billing, and technical information for as long as reasonably needed to provide Baro, comply with legal obligations, resolve disputes, prevent abuse, and maintain appropriate business records. Retention depends on the type of information and why it was collected.

Deleting a conversation or lead removes it from the active product as described by the applicable feature. Limited copies may remain temporarily in backups, logs, or records we must retain for security, fraud prevention, billing, or legal compliance.

Account deletion removes the active Baro account and associated application records. Limited information may remain in service-provider billing records, operational logs, webhook processing records, backups, or records retained for legal, security, billing, fraud-prevention, dispute-resolution, or other legitimate purposes.

We use reasonable administrative, technical, and organizational safeguards, including access controls and encryption for connected-inbox credentials. No method of storage or transmission can guarantee complete security.

Your choices and rights

You can update business information and assistant settings in Baro, change assistant response modes, disconnect an inbox, manage notifications, and delete supported conversations or leads. You may also request access to, correction of, or deletion of personal information, subject to legal, security, and operational limits.

You may delete your Baro account through Account Settings in the mobile application or web application. Account deletion removes your account and associated personal information from the active Baro application, except information we may need to retain for legal, security, billing, fraud-prevention, dispute-resolution, or other legitimate purposes.

Depending on where you live, applicable privacy law may provide additional rights, including the right to know, correct, delete, or obtain a copy of certain personal information and to appeal a denied request. We may need to verify your identity before completing a request.

You can manage device permissions for push notifications. Service messages needed to operate your account may still be sent even if you opt out of marketing communications.

Customer information

Business users determine which inboxes to connect and how Baro handles their customer conversations. For customer information processed on a business user’s behalf, that business may be responsible for providing its own notices and responding to customer privacy requests. Customers should generally contact the business they communicated with first; we will assist our business users where required.

Children’s privacy

Baro is intended for business users who are at least 18 years old and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13.

Changes to this policy

We may update this Privacy Policy as Baro or applicable requirements change. We will post the updated policy here and revise the effective date. We may provide additional notice when a change is material.

Contact Baro about privacy

Submit privacy questions or requests through our contact page or visit www.letbaro.com/contact.