Privacy Policy

Last updated: 29 August 2026

This policy explains what personal data PopcornTeam collects, why we collect it, where it is stored and who else can see it. It covers this website and the PopcornTeam web application.

PopcornTeam is in private beta. Only email addresses on an allowlist can create an account, so the people using it are the team and people we invited. Several sections below are short because the product genuinely does not do the thing the section would otherwise describe.

1. What we collect

When you create an account:

  • Your email address. It is also your account identifier, so we cannot operate an account without it.
  • A display name — either the one Google gives us, or one derived from the first part of your email address.
  • If you sign in with Google, the name and profile-picture URL on your Google account.
  • An optional password, which our authentication library stores only as a hash.

While you use the product:

  • Session records, so we know you are signed in.
  • What you create — threads and messages, agent and flow definitions, documents, and files you upload.
  • Credentials for any third-party service you choose to connect. These are encrypted before storage.
  • Operational telemetry about agent runs: internal trace, thread, agent and tool identifiers, timings and cost. It carries no name, no email address and no message text.

If you send the contact form, we store the name, email address, company, company size, topic and message you typed into it.

2. Signing in with Google

Google sign-in asks Google for the standard OpenID Connect scopes and nothing more: openid, email and profile. Those give us your email address, your name and your profile-picture URL. We request no access to Gmail, Drive, Calendar or any other Google service in order to sign you in.

We use what Google gives us for exactly two things: to create and identify your account, and to check your address against the allowlist. We do not sell it, we do not use it for advertising, and we do not use it to train any model.

Connecting Gmail or another Google service as an integration inside the product is a separate, explicit authorization that you grant later. It is covered below, not here.

3. Cookies and local storage

Every cookie we set is functional. We run no advertising cookies and no analytics cookies, which is why you see no cookie banner — there is nothing to consent to beyond the cookies that make signing in work.

  • admin-session — your signed-in session. Our authentication library also sets its own session cookie during sign-in.
  • popcornteam-desktop — remembers that you opened the app from the desktop client.
  • nova-active-workspace — remembers the workspace you last used.
  • nova-local-daemon-token — set only in local-workspace mode, so the app can reach a daemon on your own machine.
  • gmail_oauth_state and figma_oauth_state — short-lived values that protect those connect flows against cross-site request forgery.

Your browser also keeps your theme and font choice in local storage, so the page does not flash the wrong colours while it loads. That never leaves your browser.

4. Analytics

No third-party tracker runs on this site. There is no Google Analytics, no PostHog, no Microsoft Clarity, no Plausible and no browser error-reporting SDK.

We do measure page-loading performance in your browser and send those measurements to our own server. The payload is a metric name, a number and the path of the page. It carries no identifier for you.

Google Analytics, PostHog, Sentry and Clarity do appear inside the product — as integrations you can connect to read your own data from them. Connecting one does not start any tracking of this website.

5. Where your data is stored

PopcornTeam runs on Cloudflare. Accounts, sessions and application records are in a Cloudflare D1 database; uploaded files, avatars and generated media are in Cloudflare R2; agent-run coordination uses Durable Objects and KV; agent memory embeddings are in Vectorize; run metrics are in Analytics Engine.

Part of the application data still lives in Google Firebase (Firestore). We are moving it to Cloudflare, and until that finishes both stores hold data.

Cloudflare and Google both operate globally, so your data may be processed outside the country you are in.

6. What an agent run sends to a model provider

Running an agent sends its instructions, the conversation and any tool results to a large-language-model provider. We use our own API keys for this, so it happens on every run — it is how the product works, not an option you can switch off.

Depending on the model an agent is set to use, the provider can be Anthropic, OpenAI, Google (Gemini or Vertex AI), xAI, DeepSeek, Groq, Fireworks, Mistral, Cohere, Together, Cerebras or OpenRouter. Each has its own terms for the data it receives.

The practical rule: do not put anything into an agent that you would not be willing to send to that provider.

7. Who else receives your data

  • Cloudflare — hosting, storage, and delivery of our sign-in emails.
  • Google — Firebase storage, and Google sign-in.
  • The model providers listed in the previous section.

We do not sell personal data, we do not share it for advertising, and we run no ad network.

Integrations you connect are deliberately not on that list. They receive data only because you connected them and told an agent to use them. You choose them, you can disconnect them, and each one has its own privacy policy.

8. Payments

We do not charge for access during the private beta, we run no billing, and we hold no payment-card details for you. Stripe appears in the product only as an integration you can connect to your own Stripe account.

9. How long we keep it

  • A signed-in session expires after 7 days.
  • A magic sign-in link expires after 1 hour. A one-time code expires within minutes.
  • A desktop sign-in hand-off token expires after 3 minutes and works once.
  • Everything else — your account, your threads and your files — is kept for as long as your account exists.

Ask us and we will delete your account and its content. Because the beta is small, that is a request to a person, not a self-service button yet: email popcornteam-support@googlegroups.com.

10. Security

  • Sign-up is allowlisted, so an address we did not authorize cannot create an account, and a deactivated account cannot sign back in.
  • Every request is checked at the edge for a session, and each API route makes its own authorization decision again.
  • Credentials for connected integrations are encrypted with a key held outside the database.
  • All traffic is served over HTTPS.

No system is perfectly secure, and we do not claim otherwise. We hold no security certification, and this policy makes no compliance claim.

11. Your choices

Email popcornteam-support@googlegroups.com to ask for a copy of what we hold about you, to correct it, or to have it deleted. Because the beta is allowlisted, you can also ask us to remove your address, which ends your access entirely.

12. Children

The Service is not open to the public and is not intended for children. We do not knowingly collect personal data from a child.

13. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will tell the accounts it affects by email.

14. Contact

Questions about this policy, or about the data we hold, go to popcornteam-support@googlegroups.com.