Privacy Policy

Last updated 2026-09-10.

DramaLabs is a Slack-native AI assistant (“Nisa”) that performs work on the tools you connect — on your instruction, and with your explicit approval for any outbound or irreversible action. This policy explains what personal data we process, why, on what legal basis, who processes it on our behalf, and your rights.

1. Controller

DramaLabs is operated by Practible AI UG (haftungsbeschränkt), Beim Grünen Jäger 26, 20359 Hamburg, Germany, which is the controller responsible for processing under the GDPR. Data-protection contact: privacy@dramalabs.co.

2. What we process

  • Account & workspace data— your Slack workspace + user identity, and configuration you set.
  • Content from sources you connect— only to perform the tasks you ask for: email (Gmail), Slack messages, Google Drive/Docs/Sheets, Notion, and advertising data (Meta Ads, Google Ads). We access the minimum needed for the requested task.
  • Google user data— when you connect a Google account (Gmail, Drive, Docs, Sheets, Calendar, Contacts, Search Console), Nisa reads and writes that data only to carry out the task you asked for, shows drafts to you before anything is sent, and never uses it for advertising, for training AI models, or for any purpose you did not request. DramaLabs’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Added 8 September 2026.
  • Company brain— the facts you and Nisa curate about your company. You can view, correct, and remove any of them in the “What Nisa knows” view.
  • Conversations, runs & outputs— chat history, task inputs, step logs, tool calls, results, and cost.
  • Credentials— API keys / tokens you add are stored encrypted at rest, are write-only through the API (never returned to the browser), and are never injected into worker sandboxes beyond the scope of the task.
  • Outreach recipients— where you use outbound/recruiting features, we process business-contact data of the people you choose to contact (see section 8).

WhatsApp. Nisa can also be reached on WhatsApp, and that channel processes three things: your phone number (the WhatsApp id Meta sends with every message), the WhatsApp profile name Meta attaches to it, and the text of the messages you send her. The number and the profile name are kept so the number can be matched to your account and stay matched, along with the times that link was created and last used; the message text is answered and then kept as ordinary conversation history, exactly like a chat in the app. Both are part of providing the service you asked for, on the same basis as the rest of it: performance of a contract, Art. 6(1)(b). One case differs. A message from a number that is not linked to any account is answered with a link to connect it, and the number and profile name are kept only to send that link, on legitimate interests, Art. 6(1)(f); the link is valid for 24 hours and works once. Voice notes, photos and files are not read at all: they get an automatic reply saying so, and never reach the assistant. The messages travel throughMeta in both directions (section 5). You can unlink the number at any time in Settings, which detaches it from your account and your workspace and leaves the number itself on record as unlinked; to have that record removed too, write to privacy@dramalabs.co.

iMessage (where enabled).This experimental channel is disabled by default. When you use it, Apple’s iMessage service and the Photon integration handle your phone number or email address, message content, attachments you send, conversation identifiers, timestamps and delivery information. DramaLabs uses these to link your private conversation to your account, answer your messages and track delivery. Supported attachments may be read for your requested task; message content becomes conversation history. Unlinked senders are limited to account linking before the assistant can work with their messages. You can unlinkiMessage in Settings > Channels to revoke the binding and cancel queued work. This cannot recall a message already being sent or erase existing conversation history or copies held by Photon, Apple or a recipient. Unlinking retains the revoked binding record; account deletion removes our binding and queue records. For data-deletion requests, contact privacy@dramalabs.co (sections 7 and 9). Photon-managed SMS/MMS/RCS fallback to the same recipient is allowed where supported. Carriers and messaging providers on that path may also handle the content and metadata; iMessage-only delivery and end-to-end encryption through Nisa are not guaranteed.

3. Purposes & legal basis (Art. 6 GDPR)

  • Providing the service(running the tasks you request, reading your connected sources, maintaining your brain) — performance of a contract, Art. 6(1)(b).
  • Securing and improving the service— legitimate interests, Art. 6(1)(f).
  • Outbound outreachto business contacts — legitimate interests, Art. 6(1)(f), subject to a balancing test and an easy opt-out (section 8).
  • Optional integrationsyou explicitly authorize — your consent, Art. 6(1)(a), withdrawable at any time by disconnecting them.

4. Approval-first & your control

Everything Nisa draftsfor you — emails, Slack messages, calendar invites, ATS entries, ad changes, outreach — arrives as an approval card. Approve, edit or reject: only your click sends it. You can review, correct, or delete what Nisa knows at any time, and disconnect any source.

Where this does not reach yet.A tool you have explicitly connected and authorized can also be called directly while Nisa works on a task, without a card. Today that gate covers the advertising actions; the remaining connectors are being brought behind the same card. We name the gap here rather than imply a guarantee we cannot yet keep — the same rule this page applies to data-processing agreements above.

5. Processors & recipients

We use the following processors. Where a data-processing agreement is not yet in place we say so rather than imply one.

  • Hetzner (Germany, EU) — API + data hosting.
  • Vercel(US company; our application runs in its Frankfurt, EU region) — hosting of the web dashboard at app.dramalabs.co, listed on 2 September 2026, the day it went live there. No database, no backups; its global network terminates your connection at the node nearest to you, so a request from outside the EU passes through a node outside the EU on its way to Frankfurt.
  • OpenAI (US) — AI model inference for Nisa’s reasoning.
  • Anthropic, Perplexity, OpenAI, Google(US) — queried ONLY to measure whether your brand is recommended by AI answer engines. They receive a generated search query that deliberately omits your brand name; no conversation content, no personal data.
  • Backblaze B2(EU Central, Amsterdam) — off-site database backups, taken hourly, so a complete copy of your data is held there at rest.
  • Resend (US) — delivery of transactional email: recipient addresses and content.
  • Microsoft(US / Global) — a second surface Nisa can live in; messages in and out pass through Microsoft’s Bot Connector. Listed on 19 August 2026, the day the Teams connector was switched on. The bot resource is registered with global residency, so this leg is routed outside the EU; your data at rest stays in Germany.
  • Meta(US / Global) — a third surface Nisa can live in; WhatsApp messages in and out pass through Meta’s WhatsApp Business Cloud API. Listed on 26 August 2026, the day the WhatsApp channel was switched on. No data-residency option is configured on our side, so this leg is routed outside the EU; your data at rest stays in Germany.
  • Photon and Apple— the optional iMessage path, disabled by default. Where enabled, Photon connects Nisa to Apple’s iMessage service and processes message content, recipient identifiers, attachments and delivery metadata. Photon-managed SMS/MMS/RCS fallback is allowed to the same recipient where supported; it does not authorize another recipient or additional messages. Carriers and other messaging providers involved in fallback may also process this content and metadata. We do not guarantee iMessage-only delivery. For this path we do not claim EU-only processing, a signed data-processing agreement, or end-to-end encryption through Nisa: the integration and assistant must process readable content. Provider retention and transfer safeguards remain to be verified; our EU hosting statement does not describe provider-held copies.
  • Composio — managed connections to the tools you authorize.
  • E2B — isolated sandbox execution of tasks.
  • The providers you connect(Slack, Google, Meta, Notion, etc.) — they process your data per your authorization and their own policies.

6. Hosting & international transfers

Data in our core application is stored and processed in the EU(API and database on Hetzner, Germany; the web dashboard served by Vercel from Frankfurt; backups in the EU with Backblaze B2). AI model inference for Nisa’s reasoning is performed byOpenAI, which may process prompt content in theUnited States; transactional email is delivered through Resend in the US. (The answer engines receive only generated search queries used to measure AI-answer visibility — no conversation content, no personal data.) These transfers currently rely on those providers’ published data-processing terms. We are completing the corresponding data-processing agreements; until that is done we will not claim a transfer mechanism we cannot show you, and we will name it here when it is in place. We do not sell your data, and we do not use your content or your customers’ advertising data to train third-party models.

7. Retention & deletion

We keep data only as long as needed for the service. Your conversations, runs and brain content are retained for as long as your workspace exists, so that your assistant can refer back to them. You can delete conversations, runs, connections, secrets, and brain facts in the app at any time, and you can request full deletion of your account data by contacting us — that removes the workspace and everything in it, including cached content from connected sources. Access tokens for a source are revoked and deleted the moment you disconnect it.

8. Notice to people we contact (Art. 14 GDPR)

If you received outreach from a DramaLabs customer through this service: the customer (the controller for that outreach) processes your business-contact data (e.g. name, role, company, business email) for the purpose of relevant business contact, on the legal basis of legitimate interests (Art. 6(1)(f)). The data originates from the customer’s own records or from business-contact sources (e.g. professional data providers / publicly available professional information). You have the rights in section 9, including the right to object — every message includes a clear way to opt out, and you can also reach us at privacy@dramalabs.co to be removed.

9. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests, as well as to withdraw consent. To exercise any of these, contact privacy@dramalabs.co. You also have the right to lodge a complaint with your data-protection supervisory authority.

10. Security

Tasks run in ephemeral, isolated sandboxes — never in the API process. Data is tenant-isolated, credentials are encrypted at rest and write-only, and platform secrets are never exposed to task sandboxes.

11. Changes & contact

We update this policy as the service evolves; the date above reflects the latest version. Questions: privacy@dramalabs.co. See also our Terms.