Overview
Gesta, Inc. ("Gesta", "we", "us") builds an automation platform that connects your business tools and runs workflows on your behalf. To do that, we process some information about you and your organization. This policy explains what we collect, why, and what control you have over it.
It applies to the Gesta web application, our website, and any related services. It does not cover third-party products you connect to Gesta — those are governed by their own privacy policies.
Information we collect
Information you give us
- Account details — your name, work email, country, industry, and organization name when you request access or create an account.
- Billing information — processed by our payment provider; we store only the last four digits of your card and your billing country.
- Content you create — playbooks, prompts, workflow configurations, and any context you add to help the AI act on your behalf.
Information we collect automatically
- Usage data — which features you use, run counts, timestamps, and performance metrics.
- Device & log data — IP address, browser type, and diagnostic logs needed to keep the service secure and reliable.
Information from connected tools
When you connect a tool like Gmail, Slack, or HubSpot, Gesta accesses only the data needed to run the workflows you configure — scoped to the permissions you grant during connection. You can revoke any connection at any time.
How we use your information
- To provide, operate, and maintain the Gesta platform.
- To run the playbooks and automations you set up.
- To process payments and manage your subscription.
- To send you product, security, and service updates.
- To improve our product, diagnose issues, and prevent abuse.
We don't sell your data, and we don't use the content of your connected tools to train third-party AI models. Your operational data is yours.
How we share information
We share information only in these limited cases:
- Service providers — infrastructure, payment processing, and analytics vendors who process data on our behalf under contract.
- AI model providers — to execute the automations you request, scoped to that task and bound by data-processing agreements.
- Legal reasons — when required by law, or to protect the rights, safety, and security of Gesta and our users.
- Business transfers — if Gesta is involved in a merger or acquisition, with notice to you.
Connected tools & permissions
Each integration requests a specific scope of access. Gesta stores access tokens encrypted and uses them only to perform the actions in your playbooks. Disconnecting a tool from Settings → Connections immediately revokes Gesta's access and deletes the associated tokens.
Data retention
We keep your information for as long as your account is active. Run logs and audit trails are retained for the period shown in your plan. When you delete your account, we delete or anonymize your personal data within 30 days, except where we're required to keep it for legal or accounting reasons.
Security
We protect your data with encryption in transit and at rest, scoped access tokens, role-based permissions, and continuous monitoring. No system is perfectly secure, but we work hard to meet enterprise-grade standards and to notify you promptly if an incident ever affects your data.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these directly in your account settings, or by contacting us. We won't discriminate against you for exercising any of these rights.
Cookies
We use a small number of cookies to keep you signed in, remember your preferences, and understand how the product is used. You can control cookies through your browser settings; disabling essential cookies may affect how Gesta works.
Changes to this policy
We may update this policy as our product evolves. When we make material changes, we'll update the date above and, where appropriate, notify you in the app or by email. Continued use of Gesta after a change means you accept the revised policy.
Contact us
Questions about privacy or your data? Reach our team at privacy@gesta.io or through our contact page. We reply within one business day.