Who we are
Operate With Intelligence (“OWI”) is a product of With Intelligence Inc., a Florida corporation incorporated in July 2026. This policy covers www.operatewithintelligence.com and the Mission Control and client-room software reached through it.
For anything in this policy, write to admin@operatewithintelligence.com or access@operatewithintelligence.com.
Limited Use of Google user data
We use Google user data only to provide the Operate With Intelligence service the client asked for. We do not sell it. We do not use it to train general-purpose models. A named person approves anything that goes out.
What we collect
We collect only what the service needs to do its job.
- Account details. The email address you sign in with, and whether that address is on our staff list or is a member of a client workspace.
- What you tell us about the business. Everything entered in the intake at
/startand in the onboard form: the business profile, the people who run it, goals, and what is currently painful. This is information you type, and you can correct it at any time. - Connection consent. When you connect a system, we record which system, who approved it, and when.
- Google, when you connect a data app. There are four separate Google clients. Each asks only for the scopes below, plus
openid,emailandprofileso we can name the account. Staff sign-in is a fifth client and asks for those three identity scopes only.- OWI Mail (/google) —
https://www.googleapis.com/auth/gmail.readonly. - OWI Business (/google/business) —
https://www.googleapis.com/auth/business.manage. Listings and reviews. We never write to Google Business Profile in this slice. Quota is 0 until Google approves Basic API Access; consent can be granted before that flips. - OWI Mail + Calendar (/google/calendar) —
gmail.readonly,https://www.googleapis.com/auth/calendar.readonly,https://www.googleapis.com/auth/gmail.compose(drafts in the Drafts folder, never sent by us) andhttps://www.googleapis.com/auth/calendar.events(holds with no attendees, never an invitation, never a deletion). Nocalendar.acls.readonly. - OWI Files (/google/files) —
https://www.googleapis.com/auth/drive.file,https://www.googleapis.com/auth/documents.readonlyandhttps://www.googleapis.com/auth/spreadsheets.readonly. Notdrive.readonly— we cannot list or search the rest of Drive. - OWI Search Console (/google/search-console) —
https://www.googleapis.com/auth/webmasters.readonly. What people searched to find you: queries, impressions, clicks, average position and which pages earn them. Read only — we cannot change the site, submit a sitemap, or request indexing. Notwebmasters, which would allow those writes.
- OWI Mail (/google) —
- Meetings and transcripts. When a meeting between you and OWI is recorded through a tool you can see (Fireflies or Granola), the transcript and the attendee list are stored against your workspace. Meetings booked with us — the title, the time and who attended — are stored the same way, taken from our own calendar and booking system rather than from yours.
We do not collect payment card details in this product, and we do not use tracking cookies for advertising.
What read-only means, exactly
gmail.readonly permits reading mail. It does not permit sending, replying, deleting or modifying anything, and Google enforces that at the token — the permission to send was never requested.
On the Mail app, reading mail is the entire grant. That client asks for nothing from Google Calendar and nothing from Google Drive. The Mail + Calendar and Files clients are separate apps with their own consent screens, listed above.
We cannot send mail as you. That is not only a statement of intent: the service has no mail-sending capability at all, and an automated test in this codebase fails the build if one is ever added.
Mail is read so the software can find the operational facts a review rests on — quotes not followed up, invoices unpaid, questions unanswered. Nothing read from a mailbox is published anywhere without a person at OWI approving it first.
The systems you can connect
One rule holds across every connector, and it is a property of what we ask for rather than a promise about how we behave: we request read access and not write access. Where a provider offers only a combined permission, we say so on the screen where you grant it.
Google is four data apps, each a separate consent. Mail, Business, Mail + Calendar, and Files — scopes listed above. Staff Google login is a fifth client and asks only for identity (openid, email, profile).
The rest are connectors we are building. Each applies when and if you connect it — none of them is reading anything until you do, and describing them here is how the limits get agreed in advance rather than discovered afterwards.
- Jobber — connected by OAuth. When you connect it we read jobs, quotes, invoices and client records, so we can see how work moves from quote to paid. We do not create, change or delete anything in Jobber.
- QuickBooks Online — connected by OAuth, for the specific company you authorise (Intuit identifies it by a
realmId). We read accounting data — invoices, payments, expenses and the chart of accounts — to show what the numbers say. We do not write invoices, bills or payments into QuickBooks. Refresh tokens rotate on Intuit’s schedule, and each company is a separate connection: authorising one does not give us any other. - Quo (formerly OpenPhone) — connected with an API key you issue, not OAuth, because that is what the provider offers. We read business phone and messaging records where they are needed to follow up on work and reviews. We do not send calls or messages through Quo. Sending costs you money and would put us in a conversation with your customer under your name — neither is something this product does.
For every one of them the credential is encrypted before it is stored, is never committed to source control, and is readable only by the service that needs it. One client’s material is isolated from another’s.
How we use it
- To operate Mission Control and your client room.
- To prepare reviews and reports, which a person at OWI reads and approves before you ever see them.
- To let AI assist that work on trusted systems. AI proposes; a person decides.
Nothing is published, sent, or posted on your behalf without a human approving that exact action. There is no automatic publishing anywhere in this product.
We do not sell personal information, and we do not use your business information to train general-purpose AI models.
Who else handles the data
These are the services we rely on. Each is listed because it is actually in use.
- Supabase — database, authentication and file storage.
- Vercel — hosting for the website and the application.
- Google — sign-in, and Gmail access where you have granted it.
- Fireflies / Granola — meeting transcription, where a meeting is recorded.
- Zoho Bookings — scheduling, if you book a call through the site.
These are not in use yet, and are named here because they are the connectors we are building. Each becomes a processor of your data only if you connect it: Jobber (field service records), Intuit / QuickBooks Online (accounting) and Quo (business phone and messaging).
Your control
Withdrawing a connection is done from your side and takes effect immediately — you do not need our agreement or our help: Googlein your Google Account’s security settings; Jobber and QuickBooks Online by disconnecting the OWI app in their own app or connection settings; Quo by revoking the API key you issued. Tell us as well and we will confirm what we can no longer see. Parts of the product that depended on it stop working, which is the honest consequence rather than a penalty.
- Withdraw Google access at any time at myaccount.google.com/permissions. It takes effect immediately and needs nothing from us. You can also ask us and we will disconnect it from our side.
- Correct what we hold about the business and its goals directly in your room.
- Ask for a copy, or ask us to delete it. Write to access@operatewithintelligence.com. We will confirm what we hold and what deleting it would remove before doing it.
How long we keep it
We keep working information for as long as we are engaged with you, and for a reasonable period afterwards so that a report can still be explained and its evidence produced. When you ask us to delete an engagement’s data we remove it from the live systems; ordinary backups age out on their own schedule.
Connection credentials are removed when a connection is revoked or an engagement ends.
Security
Access to client information is restricted at the database itself rather than only in the application, so a member of one client’s workspace cannot reach another’s. Credentials for connected systems are stored encrypted and are never written into our source code.
No system is perfectly secure, and we would rather say that than imply otherwise.
Where we operate
With Intelligence Inc. is a Florida corporation and the service is operated from the United States. If you use it from elsewhere, your information is processed in the United States.
The service is for businesses. It is not directed at children, and we do not knowingly collect information from them.
Changes
If we change what we collect or how we use it, we update this page and move the effective date. Material changes are told to the people using the service, not left to be discovered here.