1. Who we are
Picnic is operated by Picnic Technologies Ltd (company number 17283444), a company registered in England and Wales ("Picnic", "we", "us", "our"). Our registered office is at Techspace C/O Antler C/O Picnic, 140 Goswell Rd, London, EC1V 7DY, United Kingdom. If you have any questions about this policy or how we handle your data, contact us at legal@joinpicnic.com.
This policy covers the Picnic web application at joinpicnic.com, the companion Picnic desktop application, and our marketing site and blog (together, "the Service").
2. Scope, early access, and our role
Picnic is in early access. Features and data practices will evolve, and we will keep this policy in step: material changes update the "Last updated" date above and, where appropriate, are notified to your registered email address.
Picnic is a workspace product. For your account data and our website, we act as the data controller. For the content of your organisation's workspace — the sources your team connects and the material Picnic derives from them — we process data to provide the Service to your organisation, which controls what is connected and who may see it.
3. Information we collect
We collect the following categories of information:
- Account data. Your name, email address, and profile information, provided when you sign up through our identity provider (WorkOS, including sign-in with Google), together with your organisation membership and role.
- Content from connected sources. The content of the tools you or your organisation connect to Picnic. The "Content from connected sources" section lists each integration and what it reads.
- Content you create in Picnic. Documents and their version history, comments, todos, canvases, chat messages, your conversations with the Picnic assistant (both your messages and the assistant's replies are stored), and files you upload.
- Derived data. The structured items Picnic's AI infers from your content — todos, opportunities, summaries, and approvals — together with short evidence excerpts from the source material that show why an item was suggested, plus search indexes and vector embeddings built over stored content.
- Usage data. Product analytics events such as page views, feature usage, and onboarding progress; after you sign in, these are associated with your account (see "Analytics, cookies, and similar technologies").
- Device and log data. IP address, browser or desktop-client version, operating system, server-side logs, and error reports generated in the normal operation of the Service.
4. Content from connected sources
Each integration is connected explicitly, by you or by an organisation admin, through the provider's own OAuth consent screen. What each one reads:
- Slack. Messages in public channels the Picnic bot has joined and private channels it is invited to, the workspace member directory, and — only if you grant it — your own direct messages and group DMs.
- Gmail. Messages in your mailbox: bodies, subject lines, labels, and message metadata.
- Google Drive. Files you can access, together with their sharing permissions, which Picnic mirrors so files are only surfaced to teammates who could already see them in Drive.
- Notion. Pages shared with the integration.
- Confluence (admin-connected, org-wide, read-only). Spaces and pages.
- Granola. Meeting notes, attendee lists, and full meeting transcripts.
- Linear and Jira. Issues, projects, and teams — your assigned work, or workspace-wide read-only access when an admin connects the whole workspace.
- Intercom (admin-connected, org-wide, read-only). Support conversations, including customer messages.
- Stripe (admin-connected, org-wide, via a restricted read-only key). Customers, invoices, subscriptions, and revenue data from your organisation's own Stripe account.
- GitHub (org-wide app install). Repository files are read on demand when you ask a question that needs them; repository content is not ingested or stored.
Picnic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we use information
We use the information we collect to:
- Provide the Service. Ingest and index your connected sources, run AI inference to derive todos, opportunities, and summaries, power search, and keep your workspace's shared context current.
- Send you notifications. Picnic notifies you primarily by Slack direct message and, as a fallback or where you choose it, by email (for example digests, requests directed at you, and document-approval asks).
- Improve the product. Analyse aggregate usage and your interactions with inferred items (confirmations, dismissals, corrections) to improve ranking and inference quality.
- Keep the Service secure. Detect and prevent abuse, enforce rate limits, and maintain audit logs of sensitive actions.
- Support you. Respond to enquiries and troubleshoot issues.
- Tell you about Picnic. Send marketing communications where you have subscribed or where otherwise permitted by law — you can opt out at any time using the unsubscribe link in any marketing email.
- Meet legal obligations. Where processing is required by law.
We do not sell your personal data and we do not use your data for third-party advertising. We never use your content to train third-party foundation models, and content from several connected sources is excluded from model improvement entirely — see "AI processing".
6. Legal bases (UK GDPR)
Where UK GDPR or EU GDPR applies, we rely on the following legal bases:
- Performance of a contract. Processing your account data, connected-source content, and derived data is necessary to deliver the Service you or your organisation signed up for.
- Legitimate interests. Product analytics, error tracking, security monitoring, and service improvement — where those interests are not overridden by your rights and freedoms.
- Consent. Connecting a personal source (such as your Gmail mailbox or your Slack direct messages) happens only through your explicit authorisation, which you can withdraw by disconnecting the source. Newsletter subscriptions are opt-in.
- Legal obligation. Where processing is required to comply with a legal duty.
7. AI processing
Picnic sends content to third-party AI model providers to provide its core features: deriving todos and opportunities, summarising, answering questions in the assistant, generating embeddings for search, and reranking search results. Specifically:
- Anthropic is our default model provider for inference and assistant conversations, and performs web search and retrieval of URLs you paste when those features are used.
- OpenAI generates the vector embeddings used for search, and serves OpenAI models where selected.
- Google serves Gemini models where selected.
- Cohere (accessed via Vercel's AI Gateway) reranks search results.
We use these providers through their business APIs, under terms that prohibit using your content to train their models. Content sent for a given task is scoped to what that task needs.
Improving Picnic. We may use content you create in Picnic (documents, assistant conversations, and uploads), your interaction signals, and usage data — together with content from connected sources whose platform terms permit it (currently Linear, Jira, Confluence, and Granola) — to improve Picnic's own features, including models we use to provide the Service, only ever on an aggregated and/or de-identified basis.
Content from Slack, Gmail, Google Drive, Notion, Intercom, and Stripe is never used to train or improve any AI model, in any form (aggregated and de-identified included), in line with those platforms' developer terms — it is processed solely to provide the Service to your workspace. GitHub repository content is never stored at all. And we never use your content, from any source, to train third-party foundation models.
Bring your own key. If you or your organisation add your own API key for a provider, requests funded by that key are made to the provider under your agreement with them. Keys are stored encrypted (AES-256-GCM), are never shown back to a client beyond their last four characters, and can be removed at any time.
8. What we store, and for how long
Picnic stores the content it ingests so that search, evidence links, and the assistant can work over it. In plain terms:
- Slack messages and Gmail messages. Message bodies, subject lines, and their embeddings are stored when ingested and automatically deleted 90 days later by a daily job. Message identifiers, timestamps, and participant metadata are retained so that links back to the source keep working. Items Picnic derived from a message (todos, summaries, evidence excerpts) are their own records and are not affected by this expiry.
- Other ingested content — Notion, Google Drive, and Confluence documents, Granola meeting notes and transcripts, Linear and Jira issues, Intercom conversations, and Stripe records — is retained while the source remains connected and your workspace is active.
- Content you create — documents and their version history, comments, chats, assistant conversations, and uploaded files — is retained until you delete it. Deleting an uploaded file removes the file's bytes from storage.
- Search indexes and embeddings exist alongside the stored content and are removed when the underlying content is deleted or expires.
- OAuth tokens for connected sources are held in a dedicated token vault operated by Nango — not in our database — and are revoked and deleted when you disconnect a source.
- Audit logs of sensitive actions are append-only and retained for accountability.
Disconnecting a source stops ingestion immediately and revokes our access tokens. Content already ingested from that source generally remains available to your workspace — with one exception: disconnecting Granola deletes the meeting notes and transcripts it brought in. You can ask us to remove previously ingested content at any time.
Account and workspace deletion. Email legal@joinpicnic.com to delete your account or your organisation's workspace. We complete verified deletion requests within 30 days, except where we are required or permitted by law to retain certain data for longer (for example for tax, audit, or fraud-prevention purposes); residual copies in encrypted backups age out on a rolling schedule after that.
9. Sub-processors
We use the following sub-processors to deliver the Service, each under a data processing agreement:
- WorkOS — authentication and identity management.
- Vercel — application hosting (served from London) and AI gateway.
- PlanetScale — primary Postgres database.
- Amazon Web Services (S3) — storage for uploaded files and avatars.
- Nango — OAuth token vault and integration sync infrastructure for connected sources.
- Inngest — durable background-job orchestration for ingestion and inference.
- Anthropic, OpenAI, Google, Cohere — AI model providers (see "AI processing").
- PostHog (EU-hosted) — product analytics (see "Analytics, cookies, and similar technologies").
- Sentry (EU-hosted) — error tracking.
- Resend — transactional email and newsletter delivery.
- Upstash — rate limiting and resumable AI response streams.
- Liveblocks — realtime presence on collaborative canvases.
- Sanity — content management for our public blog.
We will update this list when we add or change sub-processors and give existing customers reasonable notice before a new sub-processor processes their data.
12. People who are not Picnic users
Connected sources naturally contain information about people other than the Picnic user who connected them — teammates who wrote messages, meeting attendees in transcripts, customers in support conversations or billing records. We process that information on behalf of the workspace that connected the source, only to provide the Service to that workspace, and subject to the same protections as everything else in this policy.
If you believe a Picnic workspace holds information about you and you want it reviewed or removed, contact the workspace's organisation, or email us at legal@joinpicnic.com and we will help.
13. Your rights
UK / EU residents. Under UK GDPR and GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") in certain circumstances.
- Portability of your data in a structured, machine-readable format.
- Restriction of processing in certain circumstances.
- Objection to processing based on legitimate interests.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email legal@joinpicnic.com. We will respond within one month, and may need to verify your identity before acting on a request. Where the data in question is workspace content we process on an organisation's behalf, we may direct you to that organisation as the controller. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk, or with the supervisory authority in your EU member state.
California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use it, to request deletion, to correct inaccurate information, and to non-discrimination for exercising your rights. We do not sell or share personal information for cross-context behavioural advertising. To submit a request, email legal@joinpicnic.com.
14. International transfers
Some of our sub-processors (including our AI model providers) are based outside the UK or EEA, principally in the United States. Where personal data is transferred internationally, we put appropriate safeguards in place:
- UK International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as applicable.
- Transfers under UK adequacy decisions where available, including the UK–US Data Bridge for certified recipients.
You can request details of the safeguards in place for a specific transfer by emailing legal@joinpicnic.com.
15. Security
We implement technical and organisational measures to protect your data, including:
- Encryption in transit (TLS) and at rest.
- OAuth tokens for connected sources held in a dedicated token vault, never in our application database; API keys you bring are sealed with envelope encryption (AES-256-GCM).
- Permission-aware retrieval: content is only surfaced to workspace members who could access it in the source system — Google Drive sharing permissions are mirrored, Slack DMs remain visible only to the person who connected them, and documents carry read gates.
- Uploaded files live in a private bucket and are served only through short-lived signed URLs.
- On the desktop app, credentials are stored in the operating system's keychain, and the local cache is wiped at sign-out.
- Least-privilege access for our team, append-only audit logs, and daily automated checks that enforce our internal data-handling invariants.
No system is completely secure. If you discover a security vulnerability, please report it responsibly to legal@joinpicnic.com.
16. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us at legal@joinpicnic.com and we will delete it promptly.
17. Changes to this policy
We may update this policy from time to time. For material changes, we will update the "Last updated" date at the top of this page and send a notice to your registered email address at least 14 days before the change takes effect. For minor changes (such as clarifications, or adding a sub-processor with reasonable notice), we will update the date and post the new policy.
18. Contact
For any questions about this policy or to exercise your data rights, please contact:
Picnic Technologies LtdCompany number 17283444, registered in England and Wales
Registered office: Techspace C/O Antler C/O Picnic, 140 Goswell Rd, London, EC1V 7DY, United Kingdom
legal@joinpicnic.com