Privacy Policy
Last updated: July 31, 2026
Scope and Internal Use
This Privacy Policy applies to the internal services available at ticket.cerebrew.ai, invoice.sider.ai, and invoice.apps.wisebox.ai (collectively, the "Internal Services"). These services are private business tools intended exclusively for authorized company employees and other company-approved personnel. They are not public or customer-facing services.
Information We Collect
Depending on the Internal Service you use, we may process your company account details, name, email address, authentication identifiers, access and security logs, device and browser information, ticket messages, attachments, customer support records, invoice data, billing records, and internal handling or audit records.
Google Cloud Authentication
The Internal Services use Google authentication to verify that a user is authorized company personnel. When you sign in, we may receive basic account information from Google, such as your name, company email address, profile identifier, and authentication or security metadata. We use this information only for sign-in, access control, account administration, security, and auditing. We do not receive or store your Google password.
Gmail Support Mailbox Access
ticket.cerebrew.ai connects to the company-authorized support mailbox through the Gmail API. It reads incoming support messages, including message bodies, headers, sender and recipient addresses, timestamps, thread identifiers, and attachments, so that those messages can be converted into support tickets and displayed to authorized support personnel. The system stores the information needed to preserve ticket history, investigate requests, prevent duplicate imports, and maintain operational and security records.
When an authorized support employee reviews a response and selects Send Reply, the system uses the Gmail API to send that approved response from the support mailbox and associate it with the relevant conversation. The system does not use Gmail access to delete, archive, mark as read, or otherwise modify mailbox messages, and it does not send customer replies without an authorized employee initiating or approving the action.
Google API Limited Use
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the internal authentication and customer-support features described in this policy. It is not sold, used for advertising, or used to determine creditworthiness.
How We Use Information
We use information to authenticate authorized personnel, operate the Internal Services, manage access, investigate issues, respond to support requests, create and manage invoices, maintain internal records, improve service quality, protect security, support audits, and build internal knowledge such as FAQs and reports.
Sharing and Access
Access is limited to authorized company personnel who need the information to perform their job responsibilities. We may use vetted service providers, including Google Cloud, to provide authentication, hosting, infrastructure, or other operational support. We do not sell personal information. We do not intentionally include private customer data in reusable FAQ content.
Retention
Authentication, support, invoice, billing, and audit records may be retained for operational, financial, legal, compliance, product quality, and security purposes for as long as reasonably necessary or required by company policy.
Security and Access Control
We use administrative, technical, and organizational safeguards designed to protect information within the Internal Services. Access may be monitored, logged, restricted, or revoked by the company. Authorized users must follow company security and data-handling policies.
Contact
For privacy-related questions about the Internal Services, contact your company administrator or the internal support team through an approved company channel.