Pallium

Privacy Policy

Last updated: August 31, 2026

Insight Finder, LLC d/b/a Pallium

Effective Date: August 31, 2026

Version: 2.0

1. Introduction

Welcome to Pallium. Pallium is a product of Insight Finder, LLC, a Colorado limited liability company doing business as Pallium ("Pallium," "we," "us," or "our"). We are committed to protecting your privacy and being transparent about how we collect, use, and share personal information.

Pallium is an observational AI platform that provides organizational insights by analyzing data from the work tools your organization already uses — email, chat, and meeting transcripts — without disrupting workflows. This Privacy Policy applies to our website at palliumai.com, our web application, and our platform services (collectively, the "Services").

This Privacy Policy describes our practices regarding the personal information we collect from users, visitors, and customers, and the information we process on behalf of customer organizations. Where you use Pallium through an account provided by your employer or another organization, that organization's agreement with us and its own policies also govern how the platform is used within that organization (see Section 5).

2. Information We Collect

2.1 Information You Provide

We collect information that you provide directly to us, including:

- Account Information: Email address, name, and password when you create an account

- Onboarding Information: Role, industry, company details, and company size

- Profile Information: Additional details you choose to add to your profile

- Communication Preferences: Your preferences for receiving communications from us

- User Content: Information and content you create or upload while using Pallium (for example, client rosters, staff rosters, notes, and configuration settings)

2.2 Information We Collect Automatically

When you use Pallium, we automatically collect certain information:

- Usage Data: Pages viewed, features used, time spent, and interaction patterns

- Device Information: Browser type and version, operating system, and device type

- Log Data: IP address, access times, referrer URLs, and pages visited

- Cookies and Tracking: See Section 9 for details on cookies and similar technologies

2.3 Information from Connected Work Tools (Third-Party Integrations)

Pallium's core function is to analyze workplace communications from tools your organization connects. We only collect data from a tool after it has been authorized as described in Section 2.4, and the data we access from each integration is limited to what is necessary to provide our Services. Depending on which integrations your organization enables, this may include:

- Google Workspace: Gmail email threads and Google Meet meeting transcripts and participant information, as described in detail in Section 3

- Microsoft 365: Outlook email threads, Microsoft Teams channel messages, Teams meeting transcripts, and meeting attendance information (read-only)

- Slack: Messages in channels the Pallium app has been invited to, channel metadata, and workspace member directory information (read-only; private channels only if your organization expressly adds them)

- Fathom: Meeting transcripts, AI-generated summaries, detected action items, and meeting metadata for meetings recorded by your organization's Fathom account (covering meetings held on Zoom, Google Meet, Microsoft Teams, and other platforms Fathom supports)

- Read.ai: Meeting transcripts and metadata delivered to Pallium by webhook when a recorded meeting ends

Integration content we collect is read-only. Pallium cannot send email or messages, modify or delete content, or create meetings in your connected tools. We may add integrations over time; when we do, we update this Policy and our in-product disclosures before collecting new categories of data.

2.4 How Integrations Are Authorized

Integrations can be connected in two ways:

- Individual authorization: You connect a tool yourself through the provider's standard sign-in and consent flow (for example, OAuth). Pallium then accesses only the data that your own account in that tool can access.

- Organization-level authorization: An authorized administrator of your organization connects a tool on behalf of the organization (for example, a Slack workspace admin installing the Pallium app, a Microsoft 365 administrator granting tenant consent, or a Google Workspace super administrator authorizing access as described in Section 3.2). In this model, individual employees do not separately consent; the organization authorizes the access, determines whose data is in scope, and is responsible for providing any legally required notices to its personnel. If you have questions about whether your data is in scope, contact your organization's administrator.

In both models, access can be revoked at any time as described in Sections 3.6 and 8.4.

2.5 Information from Other Sources

- Publicly available information from company websites and professional networks

- Data from partners or affiliates (with appropriate permissions)

- Analytics and usage data from third-party analytics services

Information from these other sources is not combined with Google user data (as described in Section 3) except as necessary to provide user-facing features of the Services.

2.6 Notice at Collection (CCPA)

For California residents, at or before the point of collection, we provide notice of the categories of personal information being collected, the purposes for use, whether information is sold or shared (we do not sell or share personal information for cross-context behavioral advertising), and your rights. For complete details, see Section 8.

3. Google User Data

This section applies to information Pallium receives from Google APIs when your organization or you connect Google Workspace to Pallium ("Google user data"), and it supplements the rest of this Policy. Where this section is more restrictive than any other statement in this Policy or in our other terms, this section controls for Google user data.

Limited Use disclosure: Pallium's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.1 What We Access

When Google Workspace is connected, Pallium requests read-only access limited to:

- Gmail: Email threads (message content, headers, and conversation structure) in in-scope mailboxes

- Google Meet: Meeting transcripts (where transcription was enabled) and meeting participant information (names, participant types, and join/leave times)

- Directory/Contacts: Workspace directory information used to resolve meeting participants and email addresses to people

- Calendar: Limited event metadata associated with meetings (used to connect meetings to participants; Pallium does not analyze your calendar itself)

Pallium does not access: email drafts, spam, or trash; email attachment contents; Google Chat or Google Spaces messages; Google Drive files (except where your organization deliberately shares a specific folder with Pallium for transcript delivery, as described in Section 3.2); or any write capability of any kind. Pallium cannot send mail, modify or delete messages or labels, or create or change meetings or events.

3.2 How Access Is Granted

- Individual connection: You sign in with Google and grant the scopes above through Google's standard OAuth consent screen. Pallium then accesses only the Gmail threads and Meet transcripts your own Google account can access.

- Organization-wide connection (domain-wide delegation): For organization-wide deployments, your organization's Google Workspace super administrator authorizes read-only Gmail access for the organization through Google's domain-wide delegation mechanism (Admin Console → Security → API controls → Domain-wide delegation), typically using a service account created and owned by your organization. Under this model, Google's authorization applies at the domain level; Pallium's systems are configured to access only the mailboxes of the personnel on the roster your organization provides, and never enumerate or access other mailboxes. Your organization controls the roster, is responsible for having the authority to grant this access and for providing any required notices to its personnel, and can revoke the entire grant at any time in the Admin Console, which stops access immediately.

- Transcript folder delivery (optional): Some organizations deliver meeting transcripts (for example, from Fathom via an automation) into a single, purpose-created Google Drive folder that the organization shares with its service account. Pallium reads only that designated folder; no other Drive content is accessible.

3.3 How We Use Google User Data

We use Google user data solely to provide and improve user-facing features of the Services that are prominent in Pallium's interface — for example, surfacing client health signals, engagement and relationship insights, action items, and account summaries derived from your organization's communications. We do not use Google user data for advertising of any kind, and we do not allow humans to read it except as described in Section 3.5.

Artificial intelligence and machine learning: Pallium uses AI, including large language models, to generate the insights described above. We do not use Google Workspace user data to develop, improve, or train generalized (non-personalized) AI or machine learning models. Any model training, fine-tuning, or learning that involves Google user data is personalized — scoped to the specific customer workspace from which the data came and used only to provide user-facing features to that customer. Google user data is never used to train models made available to other customers or third parties, and is never retained in model weights that serve other customers.

3.4 How We Share Google User Data

We do not sell Google user data, and we do not transfer it to advertising platforms, data brokers, or information resellers, or use it to determine creditworthiness or for lending purposes. We transfer Google user data only:

- To our service providers (subprocessors, such as our cloud hosting provider) acting on our instructions as necessary to provide user-facing features of the Services;

- With the in-scope organization or user (that is, surfacing insights within the customer workspace the data came from);

- For security purposes (for example, investigating abuse);

- To comply with applicable law; or

- As part of a merger, acquisition, or sale of assets, after providing notice and obtaining any consent required by the Google API Services User Data Policy.

Aggregated or de-identified statistics that we share externally (Section 6.6) are never derived from Google user data.

3.5 Human Access

Pallium staff do not read Google user data unless: (i) we have your affirmative agreement to view specific messages, files, or other data (for example, in a support session you initiate); (ii) it is necessary for security purposes, such as investigating abuse or a bug; (iii) it is necessary to comply with applicable law; or (iv) the data has been aggregated and anonymized and is used only for internal operations.

3.6 Storage, Retention, and Revocation

Google user data is stored in Pallium's cloud environment as described in Section 7, encrypted in transit and at rest, and isolated per customer. On first connection Pallium imports a limited history window (by default, approximately 90 days, or the backfill window agreed with your organization), then syncs new data periodically.

- Revoking access: Individuals can revoke Pallium's access at any time from their Google Account security settings (myaccount.google.com/permissions) or from within Pallium; organizations can revoke domain-wide access at any time in the Google Admin Console. Revocation stops collection immediately.

- Deletion on disconnect: When a Google integration is disconnected or access is revoked, we delete the Google user data collected from that integration within thirty (30) days, except where retention is required by law.

- Deletion on termination: When a customer account or agreement terminates, Google user data is deleted on the schedule in Section 7.3.

4. How We Use Your Information

4.1 To Provide the Services

- Create and manage your account

- Deliver Pallium features and functionality, including analyzing connected communications to surface signals, action items, and account-level insights

- Personalize your experience based on your preferences and usage

4.2 To Improve the Services

- Analyze usage patterns, feature adoption, and engagement to improve, optimize, and enhance the platform

- Develop new features and services

Improvement and development activities use account, usage, device, and log data, and de-identified or aggregated data. They do not use the content of your organization's communications (email, messages, or transcripts) to build generalized models or products, and Google user data is used only as described in Section 3.

4.3 To Communicate with You

- Send service-related emails (account verification, notifications, updates)

- Respond to your support requests and inquiries

- Send product updates, announcements, and marketing communications (with the ability to opt out of marketing at any time)

4.4 For Security and Compliance

- Protect against fraud, abuse, and unauthorized access

- Enforce our Terms of Service and other agreements

- Comply with legal obligations and regulatory requirements

- Protect the rights, safety, and security of Pallium and our users

4.5 Legal Bases for Processing (GDPR)

For users in the European Economic Area, UK, and Switzerland, we process personal information based on:

- Contract Performance: Processing necessary to provide the Services you or your organization have requested

- Legitimate Interests: Improving our Services, security, and fraud prevention (balanced against your privacy rights)

- Consent: Marketing communications and optional features (you may withdraw consent at any time)

- Legal Obligation: Compliance with applicable laws and regulations

5. Our Roles: When We Act as a Controller and as a Processor

Pallium serves organizations, and much of the data we handle is workplace data.

- Pallium as processor/service provider: For the content we collect from connected work tools on behalf of a customer organization (including Google user data, Microsoft 365 data, Slack messages, and meeting transcripts), the customer organization determines the purposes of processing, and we process that data on the organization's behalf under our agreement with it. If you are an employee or other member of a customer organization and wish to exercise privacy rights over this data, we may direct your request to that organization, and we will assist it in responding as required by law.

- Pallium as controller/business: For account information, usage, device and log data, billing information, website visitor data, and marketing data, Pallium determines the purposes of processing and acts as a controller (or "business" under the CCPA).

6. How We Share Your Information

6.1 With Your Consent

We share your information when you explicitly authorize us to do so.

6.2 With Service Providers (Subprocessors)

We share information with third-party vendors who help us operate Pallium, including cloud hosting and infrastructure providers, email delivery services, analytics providers (for usage data, not communications content), and customer support tools. These service providers are bound by confidentiality and data protection obligations and may only use the information to provide services to us. Sharing of Google user data with service providers is further limited as described in Section 3.4.

6.3 Within Your Workspace

Insights and data may be visible to other authorized members of your organization's Pallium workspace for collaborative features and shared reporting, consistent with the roles and permissions your organization configures.

6.4 For Legal Reasons

We may disclose information when required by law or to: comply with laws, regulations, or legal process; respond to lawful requests from government authorities; protect our legal rights and the rights of others; or prevent fraud or security issues. Where legally permitted, we will notify the affected customer before disclosing customer content.

6.5 Business Transfers

In connection with any merger, acquisition, or sale of company assets, information may be transferred. We will notify you of any such change in ownership, and any transfer of Google user data will comply with the Google API Services User Data Policy (see Section 3.4).

6.6 Aggregated or De-Identified Data

We may share aggregated or de-identified data that cannot reasonably be used to identify any individual or customer — for example, aggregate usage statistics — for analytics, research, or marketing purposes. We do not attempt to re-identify such data, and we require recipients not to do so. Aggregated or de-identified data that we share externally is derived from usage and transaction data — not from Google user data and not from the content of your organization's communications.

6.7 We Do Not Sell Personal Information

Pallium does not sell, rent, or trade your personal information to third parties, and does not share personal information for cross-context behavioral advertising. We do not share personal information for monetary or other valuable consideration. This applies to all users, including California residents under the CCPA/CPRA.

7. Data Storage, Security, and Retention

7.1 Data Storage

Your data is stored in the United States using secure cloud infrastructure (Amazon Web Services), with each customer's data logically isolated from other customers. We implement redundancy and backup practices to protect against data loss.

7.2 Security Measures

We implement industry-standard security measures to protect your information:

- Encryption in transit using HTTPS/TLS for all customer-facing endpoints and backend connections

- Encryption at rest (AES-256) for stored data, including integration content and OAuth tokens

- Per-customer (tenant) isolation of stored data and secrets

- Access controls, authentication mechanisms, and least-privilege access for personnel

- Read-only integration design: Pallium does not store your passwords for connected tools and cannot alter data in them

- Regular security audits and testing, including an annual independent security assessment under Google's Cloud Application Security Assessment (CASA) framework for our Google Workspace integration

- Employee training on data protection practices

7.3 Data Retention

We retain personal information only as long as necessary to provide the Services and fulfill the purposes described in this Policy, subject to legal requirements. In particular:

- Integration content (communications data from connected tools): retained while the integration remains connected and the account active; deleted within thirty (30) days after an integration is disconnected (see Section 3.6 for Google user data)

- Customer account data and remaining content: upon account or agreement termination, deleted or anonymized within ninety (90) days, except as needed to comply with legal obligations, resolve disputes, or enforce agreements

- Backups: encrypted backups age out on our routine backup cycle following deletion

- Account, billing, and log records: retained as required for legitimate business and legal purposes

Enterprise customers' agreements may specify export and deletion procedures, which control for those customers.

7.4 Limitations

While we implement strong security measures, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for activity under your account.

7.5 Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users and customers without undue delay; comply with GDPR requirements (including notification to the supervisory authority within 72 hours where required); comply with applicable U.S. state breach notification laws; provide information about the breach, the affected data, and the protective steps being taken; and offer guidance on measures you can take to protect yourself.

8. Your Rights and Choices

8.1 Your Rights

Pursuant to applicable data protection and consumer privacy laws, you may contact us to request the exercise of certain rights concerning your personal information, including the right to: (i) request that we disclose the categories and specific pieces of personal information we have collected about you; (ii) confirm whether we process your personal information and know the purposes; (iii) request information about our disclosure practices; (iv) object to or ask us to restrict certain processing (which may require ending your subscription); (v) request a copy of your personal information in a portable format; (vi) request that we correct inaccuracies; and (vii) request that we delete your personal information. You also have the right to lodge a complaint with a supervisory authority. Depending on where you are located, some of these rights may not apply or may be subject to limitations. For example, we may limit the number of requests you make or charge reasonable fees as legally permitted. YOU WILL NOT FACE DISCRIMINATION FOR EXERCISING YOUR RIGHTS WITH RESPECT TO YOUR PERSONAL INFORMATION.

8.2 Requests Concerning Workplace Data

If your request concerns data we process on behalf of your employer or another customer organization (Section 5), we may refer the request to that organization and assist it in responding, as applicable law requires.

8.3 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@palliumai.com or through the settings in your Pallium account. Your request must provide enough information to let us reasonably verify that you are the person about whom the request is made and describe the request with enough detail to let us understand, evaluate, and respond to it.

We will use commercially reasonable efforts, consistent with applicable law, to respond within: 30 days for GDPR requests (extendable by two months for complex requests, with notice); 45 days for CCPA requests (extendable by an additional 45 days, with notice); and 30 days for general requests.

8.4 Managing Integrations

You (or your organization's administrator, for organization-level connections) can disconnect any integration at any time from Pallium's settings or from the third-party service itself — for example, your Google Account security settings, the Google Admin Console, Slack's app management page, or Fathom's settings. Disconnection stops collection immediately, and stored data from that source is deleted as described in Section 7.3.

8.5 Identity Verification

To protect your privacy and security, we verify your identity before processing requests: account holders through authenticated login; non-account holders by matching identifying information against our records; authorized agents through written authorization or power of attorney.

9. Cookies and Tracking Technologies

9.1 What Are Cookies

Cookies are small text files stored on your device that help us provide and improve our Services. We also use similar technologies such as web beacons, pixels, and local storage.

9.2 Types of Cookies We Use

- Essential Cookies: Required for site functionality, authentication, and security; deployed automatically

- Analytics Cookies: Help us understand usage patterns and improve our Services (consent required where applicable law requires, including for EU users)

- Preference Cookies: Remember your settings and preferences (consent required where applicable)

- Marketing Cookies: Deliver relevant advertising for our own Services, if used (consent required where applicable)

9.3 Third-Party Cookies

We may use third-party services that set cookies, such as analytics providers. Cookies are used on our website and application; they are not connected to the content of your organization's communications.

9.4 Cookie Consent

Where consent is required: essential cookies are deployed automatically as necessary for functionality; non-essential cookies (analytics, marketing, preference) require explicit opt-in consent before they are set; and you can withdraw consent at any time.

9.5 Cookie Management

You can control cookies through your browser settings, our cookie preference center (if available), and third-party opt-out tools. Disabling certain cookies may impact site functionality.

9.6 Do Not Track

We respond to Do Not Track (DNT) browser signals. When DNT is enabled, we limit the deployment of non-essential tracking technologies.

10. Third-Party Services

10.1 Integrated Services

Pallium integrates with the third-party services described in Section 2.3. When these services are connected: access is authorized as described in Section 2.4; the data accessed is limited to what is necessary for our Services; and access can be revoked at any time through your account settings, your organization's administrator, or the third-party service.

10.2 Third-Party Privacy Policies

Our integrated third-party service providers have their own privacy policies and terms that apply to your use of those services. You (and your organization) are responsible for reviewing and complying with them. Pallium is not responsible for the privacy practices of third-party services.

10.3 Third-Party Links

Pallium may contain links to third-party websites. We are not responsible for the privacy practices of these third-party sites and encourage you to review their privacy policies before providing any personal information.

11. International Data Transfers

11.1 Data Transfer Locations

Your information is primarily processed and stored in the United States. If you access Pallium from outside the United States, your information will be transferred to and processed in the United States.

11.2 GDPR Compliance

For users in the European Economic Area, UK, or Switzerland: we use Standard Contractual Clauses or other approved transfer mechanisms; we implement appropriate safeguards for international data transfers; and we rely on adequacy decisions where applicable.

11.3 Notice to International Users

By using Pallium, you acknowledge that your information will be transferred to the United States and other countries where our service providers operate, which may have different data protection laws than your country of residence.

12. Children's Privacy

12.1 Age Restriction

Pallium is a workplace tool and is not intended for use by individuals under the age of 16. If you are under 16, please do not access our Services or provide any personal information to us. We do not knowingly collect personal information from children under 16.

12.2 Parental Notice

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@palliumai.com. We will take steps to delete such information upon verification.

13. Changes to This Privacy Policy

13.1 Right to Modify

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the top indicates when it was most recently revised. If we materially expand the categories of data we collect from an integration, we will update this Policy and applicable consent screens before doing so.

13.2 Notice of Material Changes

If we make material changes, we will notify you by email to the address associated with your account, by in-app notification or banner, and/or by prominent notice on our website, before the changes take effect. Your continued use of Pallium after the effective date constitutes acceptance of the updated Policy.

13.3 Prior Versions

Previous versions of this Privacy Policy are archived and available upon request.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Inquiries Email: privacy@palliumai.com

Mailing Address Insight Finder, LLC d/b/a Pallium 6024 Youngfield Street Arvada, CO 80004 United States

Data Protection Officer For GDPR-related inquiries, you may contact our Data Protection Officer at privacy@palliumai.com.

Response Time We strive to respond to all privacy inquiries within 30 days. For GDPR and CCPA requests, the timeframes in Section 8 apply.

California Privacy Rights Pallium does not sell personal information and does not share personal information for cross-context behavioral advertising. California residents, see Section 8 for your privacy rights.