Privacy Policy

Version 2.0
Schemon, Inc.
Last Update: August 18, 2026

1. Introduction

This Privacy Policy explains how Schemon Inc. ("Schemon," "we," "us," or "our") collects, uses, discloses, retains, and protects Personal Data when you use the Schemon services.

This Privacy Policy applies to:

  • the Schemon website at https://www.schemon.com and the Schemon blog;
  • the Schemon portal and other Schemon-hosted web applications;
  • the Schemon mobile applications for Apple iOS and Google Android;
  • Schemon application programming interfaces (APIs);
  • Schemon Model Context Protocol (MCP) servers, tools, connectors, and related integrations;
  • customer support, billing, communications, and other services that link to this Privacy Policy; and
  • any other Schemon product or service that states that this Privacy Policy applies.

Together, these are the "Service."

This Privacy Policy does not replace a business customer's own privacy notice. Business customers that use Schemon to process Personal Data about their own clients, personnel, invitees, or other individuals are generally responsible for providing those individuals with an appropriate privacy notice.

2. Who We Are

Schemon Inc. is a Delaware corporation located at:

  • Schemon Inc.  
  • Christiana Corporate Business Center  
  • 200 Continental Dr, Suite 401, PMB 1578  
  • Newark, Delaware 19713  
  • United States

For privacy questions or requests, contact us at legal@schemon.com.

3. Our Privacy Roles

Depending on the circumstances, Schemon may act in different privacy roles.

3.1 Schemon as controller or business

Schemon generally determines why and how Personal Data is processed when we process information for our own purposes, including to:

  • create and administer Schemon accounts;
  • operate and secure the Service;
  • manage subscriptions, billing, and payments;
  • provide customer support;
  • communicate about the Service;
  • understand product usage and improve the Service;
  • comply with law and enforce our agreements; and
  • market Schemon, where permitted by law.

For these activities, Schemon generally acts as a controller, business, or equivalent entity under applicable privacy law.

3.2 Schemon as processor or service provider

Business customers may submit, store, retrieve, transmit, or otherwise process Personal Data through the Service on behalf of their own organization. We call this information "Customer Data." For Customer Data, the business customer generally acts as the controller or business, and Schemon generally acts as its processor or service provider.

Our processing of Customer Data is governed by the applicable agreement with the customer and, where applicable, the Schemon Data Processing Agreement ("DPA"). The DPA forms part of the applicable Schemon service agreement and describes our processor obligations, subprocessors, international transfer terms, and technical and organizational measures.

If you are an individual whose Personal Data was submitted to Schemon by a business customer, please contact that business customer first. We will assist the customer with your request as required by law and the DPA.

4. Definitions

For purposes of this Privacy Policy:

  • Account means an account used to access the Service.
  • Business Customer or Customer means an organization or person that subscribes to or administers the Service for business purposes. It is also called "Provider" throughout the Service.
  • Customer Data means data processed by Schemon on behalf of a Business Customer through the Service.
  • Device means a computer, phone, tablet, or other device used to access the Service.
  • End User means a person who uses the Service through or at the direction of a Business Customer, including the customer's personnel, clients, invitees, or service recipients.
  • MCP means the Model Context Protocol and related server, client, tool, resource, prompt, authentication, and connector functionality.
  • Personal Data means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual. It includes "personal information" and similar terms under applicable law.
  • Service Provider means a vendor or other third party that processes data to help us provide or support the Service.
  • Usage Data means data generated through use of the Service or its supporting systems.
  • User Content means information, files, messages, notes, records, media, and other content submitted to or generated through the Service.

5. Personal Data We Collect

The Personal Data we collect depends on how you interact with the Service, which features you use, your Device and settings, and whether you use the Service directly or through a Business Customer.

5.1 Account, profile, and contact data

We may collect:

  • name and surname;
  • email address;
  • telephone number;
  • mailing or billing address;
  • profile image;
  • preferred language, time zone, and communication preferences;
  • username, account identifier, and authentication information;
  • organization name, role, and account permissions;
  • company contact details and VAT or tax information; and
  • social media or third-party account details when you choose to connect them.

We collect only the profile fields made available by the Service and selected by you or your organization. Some profile fields are optional.

5.2 Customer Data and User Content

Depending on the features used, Customer Data and User Content may include:

  • appointment, calendar, availability, booking, and scheduling information;
  • names and contact details of clients, invitees, personnel, or other participants;
  • service descriptions, intake information, forms, and responses;
  • messages, chat content, email content, comments, and notifications;
  • files, images, documents, notes, and other records;
  • audio, video, recordings, transcripts, or summaries when a relevant feature is enabled;
  • customer relationship and service delivery records;
  • payment requests, invoices, transaction references, and payment status;
  • information shared during support or troubleshooting; and
  • other information a Customer or End User chooses to submit to the Service.

Business Customers determine what Customer Data they submit and are responsible for ensuring that they have a lawful basis and any required notices or consents.

5.3 Payment and transaction data

We use Stripe to support payment processing and related billing functions. When a payment is made through a Stripe-hosted or Stripe-enabled flow, payment-critical information, such as complete card data, is generally submitted directly to Stripe rather than stored by Schemon.

Schemon may receive and retain information such as:

  • customer and billing contact details;
  • payment or customer identifiers;
  • payment method type and limited payment method details;
  • transaction amount, currency, date, and status;
  • invoice, refund, dispute, payout, or fraud-related status; and
  • tax and business information needed for invoicing or legal compliance.

Stripe may process additional transaction, device, identity, and fraud-prevention information under Stripe's own terms and privacy notice. Depending on the activity, Stripe may act as our processor or as an independent controller.

5.4 Customer support data

We use Intercom to support customer service, support messaging, and ticket management. When you contact us, we may process:

  • your name, email address, organization, and Account identifiers;
  • the contents of your request and our responses;
  • files, screenshots, recordings, diagnostic reports, or other attachments you provide;
  • technical and Usage Data relevant to the support request; and
  • support history, routing, status, and satisfaction information.

Please remove information that is not needed for the support request before sending files or diagnostic data. Support attachments can contain sensitive information that is not apparent from the filename.

5.5 MCP and AI integration data

When you connect to or use a Schemon MCP server or an AI-enabled integration, Schemon may process:

  • the identity of the connected Account, organization, user, MCP client, or integration;
  • authentication and authorization information, such as OAuth tokens, access tokens, scopes, and connection identifiers;
  • MCP tool names, resource requests, prompts, arguments, parameters, and invocation metadata;
  • records or Customer Data selected, requested, created, updated, or returned through an MCP tool;
  • tool results, error messages, audit events, and diagnostic information;
  • the date, time, IP address, Device, client application, and security metadata associated with the connection; and
  • limited request or response content when needed to perform the requested operation, protect the Service, investigate abuse, or troubleshoot a problem.

The exact data depends on the tool called, the permissions granted, the selected records, and the MCP client or third-party service used. Section 7 provides additional information about MCP and AI integrations.

5.6 Mobile application, Device, and Usage Data

When you use the iOS or Android applications, we may automatically collect or receive:

  • Device type, manufacturer, model, and operating system version;
  • app version, installation identifier, and language or regional settings;
  • IP address and approximate location derived from the IP address;
  • network, browser, and mobile carrier information;
  • dates and times of access, screens or features used, and interaction events;
  • crash reports, performance data, error logs, and diagnostic information;
  • security events and authentication activity;
  • push-notification token and notification preferences, if notifications are enabled; and
  • information made available through Device permissions that you choose to grant.

The app will request a Device permission only when a feature needs it. You can review or revoke permissions in your Device settings, although doing so may prevent the relevant feature from working.

Apple and Google may independently process app store account, download, purchase, Device, and diagnostic data under their own terms and privacy policies.

5.7 Website Usage Data, cookies, and similar technologies

Our websites and web applications may use cookies, local storage, pixels, tags, scripts, and similar technologies to:

  • keep you signed in and remember preferences;
  • provide security and prevent fraud or abuse;
  • maintain sessions and load balancing;
  • measure use and performance;
  • understand which pages and features are useful; and
  • provide communications or marketing where permitted.

Usage Data may include IP address, browser type and version, Device identifiers, pages viewed, referring pages, dates and times, time spent, interactions, and diagnostic data.

For more information and available choices, see our Cookie Policy and any cookie preference controls made available on the Service.

5.8 Data from third parties

We may receive Personal Data from:

  • a Business Customer that creates or administers your Account;
  • another user who invites you, schedules with you, communicates with you, or submits information about you;
  • connected calendar, communications, identity, social, payment, or other services that you authorize;
  • Stripe, Intercom, app stores, hosting and security providers, and other Service Providers;
  • OpenAI, Anthropic, or another MCP client or AI service when you authorize it to communicate with a Schemon MCP server; and
  • public sources or business partners, where permitted by law.

6. Mobile Applications

The mobile applications provide access to some or all of the same Account and Customer Data available through the web Service. Data entered or retrieved in an app may be synchronized with Schemon's cloud systems and may be accessible through other authorized Devices and integrations.

Depending on the features you enable, a mobile app may request access to Device capabilities such as notifications, camera, microphone, photos or files, calendar, or contacts. Schemon processes information from a Device permission only for the feature you request and subject to your settings. The exact permissions and data practices for each released app version must also be reflected in the Apple App Store privacy information and Google Play Data Safety disclosures.

7. MCP Servers and AI-Enabled Integrations

7.1 How MCP data flows work

A Schemon MCP server allows an authorized MCP client, such as an OpenAI or Anthropic product or another compatible application, to request information from or perform supported actions in Schemon. A typical transaction may involve:

  1. the MCP client sending Schemon a tool or resource request;
  2. Schemon authenticating the connection and checking the granted permissions;
  3. Schemon reading, creating, updating, transmitting, or otherwise processing the data needed for the requested action; and
  4. Schemon returning a result to the MCP client.

As a result, Personal Data and Customer Data may travel between Schemon and the MCP client or AI provider. The returned data may become part of a prompt, conversation, output, log, memory, project, or other record maintained by that provider, depending on the provider's product, account type, configuration, and terms.

7.2 Your authorization and control

You control whether to establish an MCP connection and which permissions or scopes to grant. Only connect an MCP client that you trust. Before approving a tool call or sharing data, review the requested action and the information that may be sent.

You and, where applicable, your Business Customer are responsible for:

  • having authority to disclose the selected data to the connected service;
  • configuring the MCP client and provider account appropriately;
  • limiting access to the minimum data and actions needed;
  • protecting connection credentials and revoking access when it is no longer needed;
  • reviewing provider retention, data residency, model-improvement, and security settings; and
  • obtaining any notices or consents required for information about other people.

7.3 Schemon-managed providers and customer-selected providers

If Schemon engages an AI provider under Schemon's own contract to perform part of the Service, that provider may act as a Schemon subprocessor for the applicable Customer Data. Those providers are addressed in the DPA and its subprocessor list.

If you connect your own OpenAI, Anthropic, or other third-party account, client, credentials, or workspace to a Schemon MCP server, that provider is generally a customer-selected third-party service and is not a Schemon subprocessor merely because data passes between it and Schemon. The provider's processing is governed by your agreement and settings with that provider.

OpenAI and Anthropic offer different consumer, business, enterprise, and API products, and their retention and model-improvement practices can differ by product and configuration. Review the privacy terms and controls that apply to the specific account and product you use.

7.4 MCP security and logs

We may maintain connection records, audit events, security logs, and diagnostic information to authenticate requests, prevent misuse, investigate incidents, enforce permissions, and support the Service. Request or response content is retained only where needed for these purposes, to provide the requested functionality, to comply with law, or as configured by the Customer. Third-party MCP clients and AI providers may retain their own copies under their terms.

Disconnecting an integration stops future access but does not necessarily delete data already transferred to a third party. To delete that data, you may also need to use the third party's deletion tools or contact that provider.

8. How We Use Personal Data

We may use Personal Data for the following purposes:

  • Purpose: Process payments and subscriptions. Examples: Billing, payment status, invoices, refunds, disputes, fraud checks. Typical Legal Basis: Performance of a contract; legal obligation; legitimate interests
  • Purpose: Provide and administer the Service. Examples:  Create Accounts, authenticate users, synchronize data, deliver app and MCP functionality, process bookings and communications. Typical Legal Basis: Performance of a contract; legitimate interests
  • Purpose: Provide support. Examples:  Respond to requests, diagnose errors, manage support cases. Typical Legal Basis: Performance of a contract; legitimate interests
  • Purpose: Communicate. Examples:  Service notices, security alerts, transactional messages, requested notifications. Typical Legal Basis: Performance of a contract; legitimate interests; legal obligation
  • Purpose: Secure the Service. Examples:  Access control, logging, fraud and abuse prevention, incident response. Typical Legal Basis: Legitimate interests; legal obligation
  • Purpose: Improve and analyze. Examples:  Product analytics, performance monitoring, troubleshooting, feature development. Typical Legal Basis: Legitimate interests; consent where required
  • Purpose:  Market Schemon. Examples:  Newsletters, offers, events, and similar communications. Typical Legal Basis: Consent or legitimate interests, depending on law and context
  • Purpose: Comply and protect. Examples:  Tax and accounting, legal requests, dispute resolution, enforcement, corporate transactions. Typical Legal Basis: Legal obligation; legitimate interests

Where we rely on legitimate interests, we consider whether those interests are overridden by your rights and interests. Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.

When we process Customer Data as a processor, the Business Customer determines the legal basis and purposes, and our legal basis is the performance of our agreement and the Customer's documented instructions.

9. How We Disclose Personal Data

We may disclose Personal Data in the following circumstances.

9.1 Business Customers and authorized users

If your Account is administered by a Business Customer, that Customer and its authorized administrators may access and control your Account, Customer Data, permissions, integrations, and activity. Information you share with other users, clients, invitees, or service providers through the Service is disclosed as directed by you or the Customer.

9.2 Service Providers and subprocessors

We use vendors to help provide, secure, support, and improve the Service. These may include:

  • Amazon Web Services for cloud infrastructure, compute, storage, databases, and backups;
  • Cloudflare for DNS, content delivery, network performance, and security;
  • Stripe for payment processing, billing, and fraud prevention;
  • Intercom for customer support messaging and ticket management;
  • OpenAI or Anthropic for a Schemon-managed AI feature, only where Schemon has engaged the provider for that purpose; and
  • other providers for communications, monitoring, analytics, security, app delivery, or similar operational functions.

When a vendor processes Customer Data on Schemon's behalf, it is subject to contractual data-protection obligations as described in the DPA. A current list and the applicable role notes are included in the DPA or a linked subprocessor notice.

9.3 Customer-selected third-party services

We disclose data when you or a Business Customer connects or directs us to interact with a third-party service, including an MCP client, OpenAI, Anthropic, a calendar, communications service, or another integration. The third party's own terms and privacy policy apply to its processing.

9.4 Legal, safety, and compliance disclosures

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with law, regulation, legal process, or a valid governmental request;
  • protect the rights, property, or safety of Schemon, our users, or the public;
  • detect, investigate, or prevent fraud, abuse, security incidents, or unlawful activity;
  • enforce our agreements and policies; or
  • establish, exercise, or defend legal claims.

Where legally permitted, we will seek to notify the affected Customer before disclosing Customer Data in response to a compulsory request.

9.5 Corporate transactions

Personal Data may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction. Where required, we will provide notice before Personal Data becomes subject to a materially different privacy policy.

9.6 With consent or at your direction

We may disclose Personal Data for another purpose when you consent or direct us to do so.

10. Sale, Sharing, and Targeted Advertising

Schemon does not sell Personal Data for money.

Depending on the jurisdiction, certain advertising or analytics technologies may be treated as a "sale," "sharing," or processing for targeted advertising even when no money changes hands. Where required, we provide consent or opt-out controls through our cookie settings or another designated method. We do not use Customer Data exchanged through MCP tools for cross-context behavioral advertising.

11. International Data Transfers

Schemon is based in the United States, and our Service Providers may operate in the United States, the European Economic Area, the United Kingdom, and other countries. Personal Data may therefore be processed in countries whose privacy laws differ from those in your country.

Where required, we use appropriate transfer safeguards, which may include:

  • an adequacy decision;
  • the European Commission's Standard Contractual Clauses;
  • the United Kingdom International Data Transfer Addendum or another valid UK transfer mechanism;
  • contractual, technical, and organizational supplementary measures; or
  • another transfer mechanism permitted by applicable law.

For Customer Data, additional international-transfer terms are set out in the DPA.

12. Retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, comply with law, resolve disputes, enforce agreements, maintain security, and meet legitimate business needs.

Our typical retention approach is:

  • Account and Customer Data: for the subscription or Account term and, unless a longer period is required, for up to 60 days after termination or an applicable deletion instruction to allow orderly export, recovery from accidental deletion, and secure deletion workflows;
  • security, access, and Usage Data: generally for up to 12 months, unless a shorter period is appropriate or a longer period is needed for security, fraud, legal, or operational reasons;
  • support records: generally for 6 months after the support matter is closed, unless needed for an ongoing matter, security, training, contract administration, or legal compliance;
  • transaction, invoice, tax, and accounting records: for the period required by applicable financial, tax, and corporate law;
  • marketing data: until you opt out, consent is withdrawn, the data is no longer accurate, or it is no longer needed; and
  • MCP data: the underlying Schemon record follows the retention period applicable to that record; connection, audit, and diagnostic data follows our security and Usage Data retention schedule. A connected third party may retain transferred data under its own terms.

Deletion from active systems may be followed by deletion from backups according to our backup rotation and secure deletion processes. We may retain limited information where required by law or necessary to establish, exercise, or defend legal claims.

Business Customers may configure or contract for different retention periods. The DPA and applicable service agreement control if they conflict with this general description.

13. Security

We use technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. Measures may include encryption in transit, encryption at rest where appropriate, multi-factor authentication for critical systems, least-privilege access, access reviews, logging and monitoring, secure development practices, vulnerability management, incident response, backups, and personnel confidentiality and training.

No method of Internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your Account credentials, using available security settings, reviewing connected applications, and promptly notifying us of suspected unauthorized access.

For more information, see our Security Policy. Business Customers may also review the technical and organizational measures in the DPA.

14. Your Choices and Privacy Rights

Depending on your location and the context, you may have the right to:

  • request access to or a copy of your Personal Data;
  • request correction of inaccurate or incomplete Personal Data;
  • request deletion of Personal Data;
  • request restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain Personal Data in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of a sale, sharing, or targeted advertising where applicable;
  • limit certain uses of sensitive Personal Data where applicable;
  • appeal a refusal of a privacy request where applicable; and
  • lodge a complaint with a competent data protection authority.

You can update some Account information and communication settings in the Service. Marketing emails include an unsubscribe mechanism, although we may continue to send necessary service, billing, or security communications.

To exercise a right, email legal@schemon.com. We may need to verify your identity and authority. You may use an authorized agent where permitted by law, but we may require proof of authorization. We will not unlawfully discriminate against you for exercising a privacy right.

If Schemon processes your information on behalf of a Business Customer, submit your request to that Customer. If you contact us directly, we may forward the request to the Customer or ask you to identify the relevant Customer.

15. Account and Data Deletion

You may request deletion of your Account and associated Personal Data through the Account settings made available in the Portal or mobile application, or by contacting legal@schemon.com.

Deletion may be subject to:

  • identity and authority verification;
  • a Business Customer's instructions where the Account is organization-managed;
  • legal, tax, accounting, fraud-prevention, security, or dispute-retention obligations;
  • the 60-day post-termination period described above; and
  • backup deletion cycles.

Deleting a Schemon Account does not automatically delete copies of data previously transferred to Stripe, Intercom, OpenAI, Anthropic, another MCP client, or another third-party service. You may need to submit a separate request to that provider.

16. Sensitive Data and Regulated Information

The Service may allow a Business Customer to submit information that is considered sensitive or special-category data under applicable law. The Customer is responsible for determining whether such processing is lawful, providing required notices, obtaining required consent or another valid legal basis, limiting access, and using appropriate Service settings.

Unless Schemon expressly agrees otherwise in writing and executes a Business Associate Agreement, the Service is not intended to receive or process Protected Health Information regulated by the U.S. Health Insurance Portability and Accountability Act (HIPAA). Do not submit HIPAA-regulated Protected Health Information to the Service without that written agreement.

Do not submit government identification numbers, financial account credentials, full payment-card details, passwords, authentication secrets, or other highly sensitive data unless the applicable feature expressly requires it and you are authorized to do so.

17. Children's Privacy

The Service is not directed to children under 13 or to anyone below the minimum age required in their jurisdiction to use the Service without parental or guardian consent. We do not knowingly collect Personal Data from a child in violation of applicable law.

If you believe a child has provided Personal Data unlawfully, contact legal@schemon.com. We will investigate and take appropriate steps, which may include deleting the information. Business Customers are responsible for obtaining any parental or guardian consent required for data they submit about minors.

18. Third-Party Sites and Services

The Service may link to or integrate with services not operated by Schemon. We do not control the privacy, security, or content practices of those third parties. Review their terms and privacy notices before providing information or enabling an integration.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version and change the "Last updated" date. If a change is material, we will provide additional notice where required, such as by email, in-product notice, or a notice on the Service.

20. Contact Us

For questions, requests, or complaints about this Privacy Policy or our privacy practices, contact:

  • Email: legal@schemon.com
  • Mail: Schemon Inc., Christiana Corporate Business Center, 200 Continental Dr, Suite 401, PMB 1578, Newark, Delaware 19713, United States

You may also contact the Business Customer that provided you with access to the Service if your request concerns Customer Data controlled by that Customer.