How Pilot handles your data
Quick summary
- Pilot is an AI calendar from Carovo GmbH in Berlin. It turns tasks into time blocks in your Google or Outlook calendar automatically.
- Account and content data sits with Supabase in Frankfurt, Germany. The web app itself is delivered by Vercel, a US provider with a worldwide delivery network.
- For requests routed through OpenRouter, zero data retention is configured. Nothing is stored there permanently or used for training; short-term storage of up to 30 days for abuse and security monitoring is unaffected by that.
- For every AI service in use, meaning OpenAI, OpenRouter and AssemblyAI, it is contractually agreed that content is not used to train the models.
- After you delete your account, Pilot deletes or anonymizes account and content data within 30 days, unless a statutory retention obligation stands in the way.
- There is no team or manager view. Every account plans its own calendar and nothing else.
This page summarizes the legally binding privacy policy in plain language. Where the two differ, the privacy policy governs. Read the full privacy policy
Where your data lives
Tasks, appointments, notes and projects are stored by Pilot with Supabase, Inc. Data residency is in the EU, specifically Frankfurt, Germany. Supabase itself is a US company; Carovo GmbH covers the parent company's access through Standard Contractual Clauses. Technical caching runs on Redis Cloud, also in Frankfurt. The web app is delivered by Vercel, Inc. That covers running the interface rather than storing your content, but it does run over a worldwide delivery network headquartered in the US.
Source: Privacy Policy, Section 8
What calendar data Pilot reads
Connecting Google Calendar or Outlook grants read permission via OAuth for calendar information within the scope you allow. With a full calendar connection that covers the title, description, location, time and attendees of existing appointments, so rather more than free/busy status. Pilot needs this to spot conflicts and put new blocks where there is genuinely room. Data from Google interfaces is additionally covered by Google's Limited Use policy: it may only serve the features you requested and may not be released for training AI models. You can revoke the permission at any time, in the app or directly in your Google or Microsoft account.
Source: Privacy Policy, Section 7
What the AI does with your data
For automatic day planning, for suggestions and for voice input, Pilot sends selected content to OpenAI, L.L.C. and, via OpenRouter, Inc., to downstream model providers, both in the US. Transcription of voice recordings is handled by AssemblyAI, Inc. The route through OpenRouter is configured for zero data retention. Beyond the time needed for processing, nothing is stored there permanently, though short-term storage of up to 30 days for abuse and security monitoring is unaffected. For all three services it is contractually agreed that your content does not feed into model training.
A note on sensitive content
Free-text entries can accidentally contain special categories of personal data, a health detail in a note for instance. Content like that is better kept out of the AI features.
Source: Privacy Policy, Section 6
How long data is kept
| Data type | Retention period |
|---|---|
| Account and content data | As long as the account exists. Deleted or anonymized within 30 days of deletion |
| Calendar connection tokens | Until the connection is revoked or the account is deleted |
| Log and diagnostic data | Up to 30 days |
| Billing data | 6 or 10 years depending on document type (statutory retention) |
Source: Privacy Policy, Section 10
Data processing agreements and third-country transfers
Carovo GmbH has concluded agreements under Art. 28 GDPR with its processors. Stripe is the exception: for payment processing and fraud prevention the payment provider acts in part as an independent controller rather than a processor, and Stripe's own privacy terms apply there. Where data goes to countries outside the EEA, for instance to the US providers behind the AI features, Carovo GmbH relies primarily on the European Commission's Standard Contractual Clauses. That holds regardless of whether the recipient also carries a certification.
Source: Privacy Policy, Sections 8 and 9
A data processing agreement for your company
Companies deploying Pilot for a team usually need their own DPA with Carovo GmbH as processor. We issue it on request; there is no self-service download yet. An email to info@usepilot.de is enough.
No employee monitoring
Pilot has no team or manager view showing what individual users are working on, for how long, or how productive they were. Every account plans its own calendar and nothing else. Evaluations of individual employees do not exist, nor does a manager dashboard. That describes the product as it stands today and is not a promise for all time. If your works council agreement needs it in writing, we will put it in writing.
Frequently asked questions from IT and data protection
Is Pilot a high-risk AI system under the EU AI Act?
Pilot proposes time slots for tasks. Every suggestion is yours to confirm, move or discard. The system makes no automated decision with legal or similarly significant effect on a person, and it does not assess work performance. Final classification under the AI Act nonetheless remains a matter for the deploying company as part of its own compliance review. A technical description of how the feature works is ready for that.
What does our IT need for approval?
Sign-in runs through the standard OAuth flow from Google or Microsoft. Nobody has to install a separate company app. For an organization-wide admin approval in the Google Admin Console or Microsoft Entra ID, and for a technical security review, we put the necessary details together on request.
What is the legal basis for Pilot's processing?
Processing of account and content data rests on Art. 6(1)(b) GDPR, performance of the contract. The same applies to the calendar connection, together with your explicit OAuth authorization. If you deliberately enter special categories of data into the AI features, Art. 9(2)(a) GDPR is added, the explicit consent you can withdraw at any time by not using the feature. The full mapping is in Section 5 of the privacy policy.
Do we get the technical and organizational measures (TOMs)?
Yes, as an annex to the DPA. Section 17 of the privacy policy describes the security measures in outline; the detailed TOM annex under Art. 32 GDPR is sent on request. There is no self-service download for it yet, which is honestly a gap compared with larger providers.
What about the US CLOUD Act when providers are US companies?
The CLOUD Act can oblige US providers to hand over data even when it physically sits in the EU. For Pilot that makes for a mixed picture. Content data is in Frankfurt, but Supabase is a US company, and the AI processing happens at US services anyway. We set that out openly rather than advertising a blanket sovereignty promise that would not hold up technically. The full list of providers in use therefore belongs in any risk assessment.
Can we pay by invoice instead of credit card?
Billing currently runs through a payment method held with our payment provider, and you get an invoice after each charge. A company contract with different payment terms is something we can discuss; there is no self-service route for it yet.
What happens to our data if we cancel?
After you delete your account, Pilot deletes or anonymizes account and content data within 30 days, unless a statutory retention obligation stands in the way. What often gets overlooked in practice is that the time blocks Pilot created live in your own Google or Outlook calendar. They stay there even after you cancel. A data export beforehand runs through support.
Do you have ISO 27001 or SOC 2 certification?
Pilot itself currently holds no certification of its own. Database provider Supabase states it is ISO/IEC 27001:2022 certified and SOC 2 Type II compliant across its whole platform, which you can read up at supabase.com/security. That covers the infrastructure your data sits on and says nothing about Pilot as a product. For a young company, that is the honest position.
Documentation for your review
DPA, TOM annex, list of processors, or a technical description for IT. Tell us what your data protection team needs and we will put it together. Pilot costs 25 € per month, with the first 3 days free.
info@usepilot.de