Privacy policy
Last updated 4 October 2026
Who we are
Acro is the AI-native revenue system at https://getacro.ai. The product app is at https://app.getacro.ai. Questions about this policy go to hello@getacro.ai.
Who this covers
This policy covers:
- Visitors to the website.
- People with a workspace account.
- People whose details a customer stores in Acro, including leads and contacts.
- People who submit a public form a customer published.
Information you give us
When a workspace is created, we collect the account name, email address, and password. The password is handled by the sign-in service. We do not keep it as plain text in the product. If you choose Google sign-in, we receive the Google identity used to sign in. That sign-in does not include access to Gmail.
A workspace also stores the organization profile and the records people enter there: leads, contacts, opportunities, accounts, calls, meetings, chats, tasks, notes, and the custom objects and fields that workspace defines.
Information from the website
Demo bookings are taken on Cal.com. Cal.com receives what you submit there. The marketing site does not run an analytics or advertising cookie.
Public forms
A form at app.getacro.ai/form/… belongs to the customer who published it. A submission goes into that customer’s workspace. The customer decides what the form asks and what notice the person submitting it receives. Acro processes the submission so it arrives in that workspace.
Google user data
Signing in with Google and connecting Gmail are separate. Sign-in does not grant mail access. Connecting Gmail uses a separate consent, on a separate OAuth client. The only scope that connection requests is https://www.googleapis.com/auth/gmail.send.
Acro uses that access to send email the workspace asked it to send. That includes a person clicking send, and a workflow the workspace turned on. Acro does not read, scan, or store the mailbox.
For a connected Gmail account, Acro stores:
- The connected email address.
- An encrypted access token and refresh token.
- A record of messages Acro sent: recipient, subject, status, and the provider message id.
Acro does not sell Google user data. Acro does not use it for advertising. Acro does not use it to train generalized AI models. People at Acro do not read it, except to fix a security issue, to comply with the law, or with the user’s permission.
A workspace admin, or the user who connected their own account, can disconnect Gmail in the product. Disconnecting stops send access. Revoking Acro in Google Account settings does the same.
Other connections
These connections stay off until a workspace turns them on. WhatsApp Business covers messages the workspace sends and receives through the connected account. Meta lead ads cover the lead fields Meta delivers for the forms the workspace connects.
AI features
When a workspace turns on AI, Acro sends the model provider that workspace has configured — OpenAI or Anthropic — only the content needed for that request, such as the conversation or record the user is working on. The workspace supplies the provider key.
Acro does not use customer data or Google user data to train Acro’s own models. AI output can be wrong. A person should review it before it is sent to a lead.
How we use information
We use personal information to:
- Run the workspace and authenticate users.
- Send product email, such as invitations, through Resend.
- Send the Gmail and WhatsApp messages the workspace asked for.
- Score and follow up on leads the workspace asked the product to work on.
- Keep the service secure.
- Answer a message sent to hello@getacro.ai.
Who we share it with
We do not sell personal information. We share it with the providers below only to run the feature that needs them, and with the customer’s own users inside that customer’s workspace. We also share it when the law requires it.
| Provider | When data goes there |
|---|---|
| Sign-in, if you choose Google. Gmail send, if the workspace connects Gmail. | |
| Meta | WhatsApp Business and Meta lead ads, if the workspace connects them. |
| OpenAI or Anthropic | An AI request, if the workspace has turned that provider on. |
| Resend | Product email, such as workspace invitations. |
| Cloudflare | Hosting of the marketing site and the product app. |
| Cal.com | A demo booking you submit on the website. |
Cookies
The product app uses an httpOnly session cookie to keep a user signed in. The marketing site does not set analytics or advertising cookies.
How long we keep it
Workspace data stays while the workspace is open. To close a workspace or ask for deletion, email hello@getacro.ai. We delete the personal data in that workspace, except what we still need for security, fraud prevention, or a legal obligation.
Security
Workspaces are isolated from each other. Integration secrets, including Gmail tokens, are encrypted at rest.
Children
Acro is a business product. It is not directed at children.
Changes
We post updates on this page and change the date above. A material change to how Google user data is used is reflected here before that use starts.
Contact
Email hello@getacro.ai. The terms of service describe use of the product.
