Updated: 19 August 2026

Privacy notice

How Overall handles your data, in plain English.

On this page
  1. Information, purposes, and legal bases
  2. Connected Sources
  3. Providers and transfers
  4. Retention
  5. Cookies
  6. Your rights
  7. Automated processing
  8. Controller and contact

Connected Sources

Overall receives information from a Source only when an authorized account deliberately connects it or uses it in a requested feature. That information can include content and personal data present in the Source. You must be entitled to connect the Source and make its information available through Overall.

Providers and transfers

Overall uses the following providers only to the extent needed to operate the relevant feature:

  • Google Cloud and Google Identity Platform for hosting, databases, and account identity;
  • Resend for account and security emails;
  • Cloudflare Turnstile for abuse prevention;
  • Nango to establish a Source connection with supported providers; and
  • Mistral's EU endpoint when you use an enabled AI feature.

Overall's hosted services run in a European Google Cloud region and its AI calls use Mistral's EU endpoint. The provider of a Source you choose to connect may also receive requests needed for that connection. Some other providers or connected Source providers may process information outside the European Economic Area. Where that happens, Overall relies on the transfer mechanism required by applicable law. Details are available from the privacy contact below.

Retention

Access and security material associated with an account is revoked or disabled when the account closes. Organization, Source, work, and evidence information can remain with the organization after an individual account closes when it is needed to provide the service or preserve attributable work. Limited security and technical information is retained for the time needed to protect the service, resolve an incident, or meet a legal obligation. A verified deletion request is assessed against those criteria.

Cookies

Overall uses cookies and browser storage that are necessary for sign-in, sessions, OAuth, CSRF protection, and security. It does not intentionally use advertising cookies. If Overall adds a non-essential tracker, it will ask for consent before using it.

Your rights

Where applicable, you may ask to access, correct, erase, restrict, or object to the processing of your personal data, or request portability. Where processing relies on consent, you may withdraw it at any time. Use the privacy contact below. Overall may ask for the information needed to verify your identity and will normally reply within one month. You may also lodge a complaint with the data protection authority that applies to you.

Automated processing

Overall may use AI to prepare classifications, summaries, drafts, or recommendations from the context needed for a requested feature. It does not make solely automated decisions that produce legal or similarly significant effects. Customer data is not used to train shared models without explicit, scoped, revocable owner consent. Outputs remain subject to human review and decision.

Controller and contact

Data controller. Mathieu Ramage.

Privacy contact. mathieu@getoverall.com