SideKickLegal

Privacy Policy

Effective date: August 14, 2026

SideKick, by Forma Consulting, LLC (doing business as Forma, “we,” “us”), is a marketing and productivity tool for small businesses and the people who run them. This policy explains what we collect when you use SideKick, how we use it, who we share it with, and how you can have it deleted. It’s written to describe what the product actually does, not a generic template. For any information about your own customers or clients that passes through SideKick, your business (or the organization you work for) is the data controller and Forma acts as a processor (a service provider) on your instructions. For your own account, billing, usage, and connected-social data, Forma Consulting, LLC is the data controller.

1. What we collect

We collect only what SideKick needs to do the job you’ve asked it to do:

  • Account & organization info. Your email, the display name you set, and your organization or business name and membership role.
  • Content topics you write. What you type into Content to draft a post. Our Privacy Guard runs entirely in your browser and masks sensitive info — names, contact details, account and ID numbers, and more — before anything is sent anywhere; see “Privacy Guard” below. Our servers then independently re-screen every request and refuse any that still contains sensitive info, so what reaches an AI provider is the masked version.
  • Connected-account access. If you connect Meta (Instagram/Facebook), Google, Canva, Granola, Fathom, or Fireflies, we store the access token or API key that connection grants us, always encrypted, never in plain text. See “How connected-account tokens are stored” below.
  • Instagram/Facebook profile, posts, and performance data. If you connect Instagram or Facebook, we periodically sync your connected account’s profile, your posts, and performance metrics (reach, engagement, follower counts, and aggregated audience demographics such as age range, gender, and city) about every 6 hours. This is stored in our database, and deleted immediately and entirely when you disconnect the account.
  • Generated content. The posts, captions, and graphics SideKick generates for you, and basic metadata about each generation job (format, language, timestamps, whether Privacy Guard masked anything).
  • Calendar data (read-only). If you connect Google Calendar, we read your events to build Planner’s schedule view. Events are fetched live each time and never stored on our servers. We only read — SideKick never creates, edits, or deletes anything on your calendar.
  • Meeting notes. If you connect Granola, Fathom, or Fireflies and use the meeting-notes feature, SideKick can access the meeting notes and transcripts your account already has, to help you turn them into content ideas. We access them only when you use that feature, not continuously.
  • Imported designs. If you connect Canva, we access the designs you choose to import into SideKick, through Canva’s OAuth connection. We only see a design when you choose to import it.
  • Usage & billing data. Your plan, generation credits used, and billing history, handled through our payment processor, Stripe.
  • Cookies. We use only essential cookies for sign-in; no advertising or analytics trackers.

2. How we use it

  • To generate the copy and graphics you ask for.
  • To publish a post to Instagram/Facebook when you click Publish on a connected account.
  • To show your Google Calendar events in Planner.
  • To surface your Granola, Fathom, or Fireflies meeting notes as content ideas.
  • To import a design you choose from Canva.
  • To run your subscription, metering, and billing.
  • To operate, secure, monitor, and improve SideKick itself.

3. Privacy Guard: what never leaves your device

Before any topic you write is sent to our servers or to an AI provider, it is screened on your device, in your browser, by Privacy Guard. It detects names and other sensitive info and replaces each with a masked placeholder before the request is built. The unmasked text is never transmitted for that request — what leaves your browser is the masked version. This runs for every generation, in English, Spanish, and Portuguese.

4. How connected-account tokens are stored

Every access token from a connected account (Meta, Google, or Canva) or a pasted API key (Granola or Fathom) is sealed with envelope encryption before it’s ever written to our database: a fresh, random encryption key is generated per token, the token is encrypted under that key, and the key itself is encrypted under a separate master key. The database only ever holds ciphertext. Plaintext exists briefly in server memory, only at the moment we use the token to make the request you asked for (e.g. publishing a post or pulling a calendar).

5. Who we share data with

We share data only with the services that are part of doing what you asked, and with our own infrastructure providers. We do not sell your data, to anyone, ever, including any data received from Meta’s platforms, which we never sell, license, or transfer except as described here.

  • Google Gemini. Receives the content topic for generation, already run through Privacy Guard, so it never receives your unmasked sensitive info. Questions you ask the in-app Help assistant are also sent to Gemini.
  • Meta (Instagram/Facebook). Receives the post you choose to publish, via the account you personally connected and its own granted permissions.
  • Google. Used for sign-in and, if you grant calendar access, to read your calendar events (read-only).
  • Canva. If you connect it, we access the designs you choose to import, through Canva’s OAuth connection.
  • Granola. If you connect it, we call Granola’s API with your own API key to fetch your meeting notes.
  • Fathom. If you connect it, we call Fathom’s API with your own API key to fetch your meeting notes.
  • Stripe. Processes payments and manages your subscription. We don’t store your full card number ourselves.
  • Supabase. Our database, authentication, and file-storage provider. Your organization’s data is isolated from every other organization’s data by row-level security policies enforced at the database layer.
  • Vercel. Hosts and serves the application. Requests you make to SideKick pass through Vercel’s infrastructure.

Google Workspace API Limited Use. SideKick’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data received from Google Workspace APIs, including your Google Calendar data, is used only to provide the user-facing features you request within SideKick. We do not use, transfer, or sell that data to develop, improve, or train generalized or foundational artificial-intelligence or machine-learning models. We do not use or transfer it to serve advertising, and we do not transfer it to others except as needed to provide the features you request or as required by applicable law. We do not allow humans to read your Google Calendar data unless (a) you give specific consent, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) it has been aggregated and anonymized for internal operations. Any AI features in SideKick that process Google Workspace data use it only to deliver functionality to you, and never to build models that are personalized for, or shared with, other users.

6. Data retention

  • Account and organization data is retained for as long as your account is active.
  • Instagram/Facebook posts, performance metrics, and audience demographics are refreshed roughly every 6 hours for as long as the account stays connected, and removed the moment you disconnect it.
  • Disconnecting a connected account (Meta, Canva, Granola, Fathom, or Fireflies) from Connections deletes the stored access token, the connection record, and all synced social data (posts, metrics, and audience demographics) immediately, not on a delay.
  • Generated content history is retained for your account’s own reporting and history views.
  • Billing records are retained for as long as required for accounting, tax, and fraud-prevention purposes even after a subscription ends.
  • After a deletion request (see “How to request deletion” below), we delete personal data within 30 days, except what we’re legally required to keep.

7. Security

We take concrete, specific measures to protect your data. We don’t claim any system is perfect, so here is exactly what we do:

  • Connected-account tokens are encrypted at rest with envelope encryption (see Section 4).
  • Organization data is isolated per-organization by database-level row-level security.
  • Sensitive info is masked on your device before it’s ever sent over the network.
  • Data in transit is encrypted (HTTPS/TLS).
  • Access to production systems and the encryption key is restricted to the people who operate SideKick.

8. Your rights & how to request deletion

You can disconnect any connected account yourself, at any time, from Connections inside SideKick — that immediately deletes the stored token. To request deletion of your account or any other personal data we hold, see our Data Deletion Instructions page, or email us directly at contact@formaconsultation.com.

9. Children’s privacy

SideKick is a business tool built for small businesses and the people who run them. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

10. Changes to this policy

If we change this policy in a meaningful way, we’ll update the effective date at the top of this page and, where appropriate, let you know directly.

11. Contact us

Questions about this policy or your data: contact@formaconsultation.com.