logo-darklogo-darkPipe0
  • Documentation
  • Blog

Privacy Policy

Last Updated: August 23, 2026

1. Introduction

This Privacy Policy explains how PWLL UG (haftungsbeschränkt) ("Company," "we," "us," or "our") processes personal data when you use the pipe0 platform, API, and related services. We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR).

Where we process personal data on behalf of a business customer — the records they submit to the Service and the results our pipes and searches produce — we act as their processor rather than as controller. That processing is governed by our Data Processing Agreement, not by this policy. This policy covers the data for which we are the controller.

2. Data Controller

The data controller responsible for your personal data under this Privacy Policy is:

PWLL UG (haftungsbeschränkt)
Quitzowstrasse 118 10559 Berlin, Germany

3. Data We Collect

We collect the following categories of personal data:

  • Account Information: When you sign up, we collect your name, email address, and payment details.
  • API Usage Data: We collect metadata about your API requests, including timestamps and IP addresses.
  • Communication Data: When you contact us, we collect messages, inquiries, and support requests.
  • Integration Data: When you connect a third-party service (such as Slack, Google, HubSpot, Salesforce, or Attio), we collect and store the data described in section 8.

4. Legal Basis for Processing

We process your personal data based on:

  • Contractual necessity (Article 6(1)(b) GDPR) for providing the services.
  • Legitimate interests (Article 6(1)(f) GDPR) in ensuring service security and improving our services.
  • Compliance with legal obligations (Article 6(1)(c) GDPR).

5. How We Use Your Data

We use your personal data for:

  • Providing and maintaining the platform and API service.
  • Monitoring and preventing fraudulent or abusive use.
  • Improving and optimizing the service.
  • Communicating with you about service updates and support.

6. Data Sharing and Processors

We do not sell your data. We share data with the following processors, who act under our instructions and implement appropriate security measures:

Data ProcessorPurpose
Cloudflare, Inc.Content delivery, security, and webhook resolution
Vercel Inc.Hosting and deployment services
Hetzner Online GmbHInfrastructure and storage services
Anthropic, PBCAI model inference (see section 9)
OpenAI, LLCAI model inference (see section 9)
Google LLCAI model inference (see section 9)
Vercel AI Gateway, and Z.aiPowering the "Ask AI" assistant on our documentation site

Enrichment providers

Pipes and searches route your inputs to third-party data providers. How a provider is engaged depends on the connection you use:

  • Managed connections. We supply the provider credentials and hold the account with the provider. The provider is then our sub-processor, engaged only for the pipes and searches you actually run. Each provider is named in the pipe catalog entry for the pipe or search that calls it, together with the fields that pipe transmits.
  • Custom connections. You supply your own API key or OAuth grant. You then contract with that provider directly, and it processes your data under your agreement with it rather than ours.

Our Data Processing Agreement sets out the full sub-processor terms, including how we notify you of changes and how you may object to them.

7. International Data Transfers

We are established in Germany. Several of the processors listed in section 6, and many of the enrichment providers reachable through the pipe catalog, are established in the United States or process data there.

Where we transfer personal data outside the European Economic Area, we do so on the basis of:

  • the recipient's certification under the EU–US Data Privacy Framework, where that certification covers the transfer; or
  • the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, together with any supplementary measures the transfer requires under Chapter V GDPR.

We do not currently guarantee that data is stored exclusively within the European Economic Area. If your use case requires EU-only processing, contact us at privacy@pipe0.com before you send us data.

8. Third-Party Integrations

When you connect an external service to pipe0 (for example Slack, Gmail, Google Calendar, HubSpot, Salesforce, or Attio), we store per connection:

  • The access credentials the service issues (OAuth tokens), encrypted at rest with AES-256-GCM.
  • Connection metadata: the identity of the connected workspace or account (for Slack: the workspace name and ID, the app's bot user ID, and the installer's Slack user ID), and the permissions (scopes) granted.

Content from connected services (for example a Slack message you configure a workflow to send, channel member lists you query, or a message you send to the pipe0 agent) is processed transiently to execute the operation you requested and appears in your workspace results where you store it. pipe0 does not read Slack channel history or direct messages between people.

Connection credentials and metadata are deleted when you delete the connection or your account, or when the connected service revokes the app's access.

Google API Services — Limited Use

pipe0's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is only used to provide the features you invoke, is never used for advertising, is never transferred except as necessary to provide those features or comply with law, and is never used to train generalized AI or machine-learning models.

The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements. Where an AI feature you invoke processes such data, it is processed transiently by the AI processors listed in section 6, under agreements that prohibit them from training models on it (see section 9).

9. AI Processing

Parts of pipe0 — AI pipes, message drafting, and the pipe0 agent — are powered by large language models operated by the AI processors listed in section 6. The inputs you configure or send are transmitted to these providers to generate the requested output, under agreements that prohibit the providers from training their models on this data. pipe0 does not use your data, or data received from connected services, to train AI models. AI-generated output can be inaccurate; review it before relying on it.

10. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined in this policy or comply with legal obligations. In particular:

  • Account information: for the lifetime of your account, deleted within 30 days of account deletion (except where billing records must be retained under statutory retention duties).
  • Integration credentials and metadata: until you delete the connection or your account, or the connected service revokes access.
  • API usage metadata and logs: up to 12 months.
  • API run records: the inputs and results of asynchronous pipe and search runs are retained for 21 days from creation and are then deleted automatically. Synchronous runs are not stored.
  • AI processing inputs/outputs: processed transiently; retained only as part of the results stored in your workspace.
  • Workspace data: for the lifetime of the sheet. Note that deleting a row removes it from the current version of a sheet but does not by itself erase it from the sealed earlier versions that make undo and point-in-time recovery possible. To have a record erased across sheet versions and backups, contact privacy@pipe0.com.

11. Your Rights

Under GDPR, you have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data.
  • Restriction: Limit how we process your data.
  • Objection: Object to data processing based on legitimate interests.
  • Data Portability: Receive your data in a structured format.

To exercise these rights, contact us at privacy@pipe0.com. We respond to data requests within the timeframes required by the GDPR.

If your request concerns data that one of our business customers submitted to the Service, that customer is the controller of it. We will refer you to them and inform them of your request.

12. Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse, including encryption of credentials at rest (AES-256-GCM), TLS for data in transit, and least-privilege access to production systems. Annex II of our Data Processing Agreement describes these measures in full.

13. Changes to This Policy

We may update this Privacy Policy periodically. Each version stays available at its own dated URL. Continued use of our services after updates constitutes acceptance of the changes.

14. Contact Us

For questions regarding this Privacy Policy, contact us at:

PWLL UG (haftungsbeschränkt)
Quitzowstrasse 118 10559 Berlin, Germany privacy@pipe0.com