Legal

Privacy Policy

Effective July 22, 2026 · Airgapped LLC · Franklin, Tennessee

Who we are

Airgapped LLC ("Airgapped," "we," "us") is a Tennessee limited liability company based in Franklin, Tennessee. We design, install, and manage private, on-premises AI infrastructure for professional and regulated businesses. Our contact information is at the end of this policy.

What this policy covers

This policy explains how Airgapped handles personal information in three separate contexts:

  • Website visitors: people who browse airgapped.co.
  • Prospective clients: people who contact us, book a call, or complete our discovery intake form.
  • Client system data: data that flows through the software we build for our clients, including data authorized through Google, Microsoft, and other connected accounts.

The third category is the important one, and it is where our approach differs materially from most software companies. Please read it carefully.

The short version Airgapped operates on a zero-custody model for client system data. When a client connects their Google Workspace, Microsoft 365, QuickBooks, Dropbox, or similar account to their Airgapped-built AI system, the data flows directly from those services to hardware the client owns and controls. Airgapped does not receive, store, or transmit that data. We are the developer of the software; we are not a custodian of the data it processes.

Website visitors

When you visit airgapped.co, our web host and content delivery network (Cloudflare) automatically log standard information about the request: your IP address, browser type, referring page, and the pages you view. We use this information to operate and secure the site.

We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that build a profile of you across the web. If we add analytics in the future, we will update this policy and use a privacy-respecting product (for example, a self-hosted or cookieless option).

Prospective clients

If you contact us by email, book a call through our scheduling link, or complete our Operations Discovery Intake, you provide us with information such as your name, company, email address, phone number, and details about how your business operates. We use this information only to respond to you, prepare for and hold our conversations, and, if you become a client, to design and build your systems.

We do not sell this information, share it with advertisers, or use it to train public AI models. Your discovery answers are covered by the confidentiality terms of any agreement we sign with you.

Client system data

When you become an Airgapped client, we build software that runs on hardware you own (or, in a managed-hosting arrangement, in an isolated environment provisioned for you alone). That software connects to your business systems on your behalf. The data those systems contain, and the outputs the AI produces from them, are yours.

Airgapped's role and access:

  • We do not receive your credentials. Passwords, API keys, and OAuth tokens are entered by your team, in your browser, into your on-premises system. They are stored in a local secrets vault on your hardware. Airgapped never sees or holds them.
  • We do not receive your content. Email, calendar events, files, accounting records, CRM records, and other data pulled from your connected accounts flow directly to your on-premises system. That data is not transmitted to Airgapped or to any third party.
  • Support access is disclosed. For managed clients, we maintain a secure remote-management connection to your hardware for monitoring, updates, and support. That access is disclosed in your handoff packet, is used only for the services described in our agreement, and can be revoked by you at any time.
  • Local AI, not public AI. Our default architecture uses open-weight language models running locally on your hardware. Your data is not sent to public AI providers for inference. If any part of a workflow uses a third-party AI service, that will be disclosed and agreed to in your Statement of Work.

Google user data

Airgapped's software can be configured, at your direction, to connect to Google Workspace services (Gmail, Google Calendar, Google Drive) through Google's official OAuth 2.0 authorization framework. This section describes that connection, as required by Google's API Services User Data Policy, including the Limited Use requirements.

What data we request access to

Depending on the workflows you enable, our software may request permission to access:

  • Gmail messages and metadata (read, and where authorized, send and modify)
  • Google Calendar events (read and, where authorized, create and modify)
  • Google Drive files (read, and where authorized, modify)

You choose which scopes to grant during activation. You can grant, deny, or later revoke any of them.

How the data is used

Google user data accessed through this connection is used only to provide the AI features you have enabled in your Airgapped system (for example, an executive-assistant agent that drafts replies, an agent that follows up on pending items, or a knowledge base that indexes documents you designate). Uses are limited to the direct benefit of the authorized user and their organization.

Where the data goes

Google user data is transmitted from Google directly to your on-premises Airgapped system over a TLS-encrypted connection. It is processed and stored on your hardware. It is not transmitted to Airgapped's servers, and it is not shared with any third party. It is not used to train, improve, or personalize any generalized AI model.

Limited Use compliance

Airgapped's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell, transfer, or disclose Google user data except as necessary to provide, improve, and secure the features you have authorized, and as required by law.

Revoking access

You can revoke Airgapped's access to your Google account at any time from your Google Account's Security settings at myaccount.google.com/permissions. Revoking access will stop the affected workflows on your Airgapped system.

Microsoft 365 data

The same principles apply to Microsoft 365 connections (Outlook, Calendar, OneDrive, and related services accessed through Microsoft Graph). Your tenant administrator authorizes the connection through Microsoft's OAuth flow. Data flows directly from Microsoft to your on-premises system, is not transmitted to Airgapped, and is used only for the features you have authorized. Access can be revoked from your Microsoft Entra admin center.

Other integrations

Your Airgapped system may connect to additional services such as QuickBooks, Dropbox, Insightly, Fonn, or bid portals. In every case, the same zero-custody principle applies: credentials are entered by you into your local system and stored in your local vault, data flows directly between the third-party service and your hardware, and Airgapped does not act as an intermediary custodian of that data.

How we share data

For information we do hold (prospective-client contact details, project documents you send us before or during a build, records of our work with you), we share it only:

  • With Airgapped personnel and contractors who need it to do the work.
  • With service providers we use to run our business (for example, our email provider, our scheduling and video-conference tools, our accounting software), each under their own privacy commitments.
  • When required by law, valid legal process, or to protect our legal rights.

We do not sell personal information. We do not share personal information with advertisers.

Retention

We keep prospective-client and client-relationship information for as long as we have a relationship with you and for a reasonable period afterward, generally consistent with our tax, accounting, and legal obligations. You can ask us to delete your information at any time; we will do so unless we are required to retain it.

Data that resides on your on-premises Airgapped system is retained according to your own policies. You control it.

Security

We use commercially reasonable technical, administrative, and physical safeguards to protect information we hold. Our client architecture is designed to minimize the amount of client data we hold in the first place. No system is perfectly secure, but our zero-custody model is our strongest safeguard: we cannot lose data we never held.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or restrict the processing of personal information we hold about you, and to object to processing or withdraw consent. To exercise these rights, contact us at the address below. We will respond within the timeframes required by applicable law.

Children

Airgapped's services are directed to businesses and professionals, not to children. We do not knowingly collect personal information from anyone under 13.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the effective date at the top of the page and, where appropriate, notify clients directly. Continued use of our website or services after an update means you accept the revised policy.

Contact

Questions, requests, or concerns about this policy or our data practices:

Airgapped LLC
Franklin, Tennessee, USA
Email: hello@airgapped.co
Phone: +1 (615) 657-5023