Version 2.0
Schemon, Inc.
Last Update: August 18, 2026
This Privacy Policy explains how Schemon Inc. ("Schemon," "we," "us," or "our") collects, uses, discloses, retains, and protects Personal Data when you use the Schemon services.
This Privacy Policy applies to:
Together, these are the "Service."
This Privacy Policy does not replace a business customer's own privacy notice. Business customers that use Schemon to process Personal Data about their own clients, personnel, invitees, or other individuals are generally responsible for providing those individuals with an appropriate privacy notice.
Schemon Inc. is a Delaware corporation located at:
For privacy questions or requests, contact us at legal@schemon.com.
Depending on the circumstances, Schemon may act in different privacy roles.
Schemon generally determines why and how Personal Data is processed when we process information for our own purposes, including to:
For these activities, Schemon generally acts as a controller, business, or equivalent entity under applicable privacy law.
Business customers may submit, store, retrieve, transmit, or otherwise process Personal Data through the Service on behalf of their own organization. We call this information "Customer Data." For Customer Data, the business customer generally acts as the controller or business, and Schemon generally acts as its processor or service provider.
Our processing of Customer Data is governed by the applicable agreement with the customer and, where applicable, the Schemon Data Processing Agreement ("DPA"). The DPA forms part of the applicable Schemon service agreement and describes our processor obligations, subprocessors, international transfer terms, and technical and organizational measures.
If you are an individual whose Personal Data was submitted to Schemon by a business customer, please contact that business customer first. We will assist the customer with your request as required by law and the DPA.
For purposes of this Privacy Policy:
The Personal Data we collect depends on how you interact with the Service, which features you use, your Device and settings, and whether you use the Service directly or through a Business Customer.
We may collect:
We collect only the profile fields made available by the Service and selected by you or your organization. Some profile fields are optional.
Depending on the features used, Customer Data and User Content may include:
Business Customers determine what Customer Data they submit and are responsible for ensuring that they have a lawful basis and any required notices or consents.
We use Stripe to support payment processing and related billing functions. When a payment is made through a Stripe-hosted or Stripe-enabled flow, payment-critical information, such as complete card data, is generally submitted directly to Stripe rather than stored by Schemon.
Schemon may receive and retain information such as:
Stripe may process additional transaction, device, identity, and fraud-prevention information under Stripe's own terms and privacy notice. Depending on the activity, Stripe may act as our processor or as an independent controller.
We use Intercom to support customer service, support messaging, and ticket management. When you contact us, we may process:
Please remove information that is not needed for the support request before sending files or diagnostic data. Support attachments can contain sensitive information that is not apparent from the filename.
When you connect to or use a Schemon MCP server or an AI-enabled integration, Schemon may process:
The exact data depends on the tool called, the permissions granted, the selected records, and the MCP client or third-party service used. Section 7 provides additional information about MCP and AI integrations.
When you use the iOS or Android applications, we may automatically collect or receive:
The app will request a Device permission only when a feature needs it. You can review or revoke permissions in your Device settings, although doing so may prevent the relevant feature from working.
Apple and Google may independently process app store account, download, purchase, Device, and diagnostic data under their own terms and privacy policies.
Our websites and web applications may use cookies, local storage, pixels, tags, scripts, and similar technologies to:
Usage Data may include IP address, browser type and version, Device identifiers, pages viewed, referring pages, dates and times, time spent, interactions, and diagnostic data.
For more information and available choices, see our Cookie Policy and any cookie preference controls made available on the Service.
We may receive Personal Data from:
The mobile applications provide access to some or all of the same Account and Customer Data available through the web Service. Data entered or retrieved in an app may be synchronized with Schemon's cloud systems and may be accessible through other authorized Devices and integrations.
Depending on the features you enable, a mobile app may request access to Device capabilities such as notifications, camera, microphone, photos or files, calendar, or contacts. Schemon processes information from a Device permission only for the feature you request and subject to your settings. The exact permissions and data practices for each released app version must also be reflected in the Apple App Store privacy information and Google Play Data Safety disclosures.
A Schemon MCP server allows an authorized MCP client, such as an OpenAI or Anthropic product or another compatible application, to request information from or perform supported actions in Schemon. A typical transaction may involve:
As a result, Personal Data and Customer Data may travel between Schemon and the MCP client or AI provider. The returned data may become part of a prompt, conversation, output, log, memory, project, or other record maintained by that provider, depending on the provider's product, account type, configuration, and terms.
You control whether to establish an MCP connection and which permissions or scopes to grant. Only connect an MCP client that you trust. Before approving a tool call or sharing data, review the requested action and the information that may be sent.
You and, where applicable, your Business Customer are responsible for:
If Schemon engages an AI provider under Schemon's own contract to perform part of the Service, that provider may act as a Schemon subprocessor for the applicable Customer Data. Those providers are addressed in the DPA and its subprocessor list.
If you connect your own OpenAI, Anthropic, or other third-party account, client, credentials, or workspace to a Schemon MCP server, that provider is generally a customer-selected third-party service and is not a Schemon subprocessor merely because data passes between it and Schemon. The provider's processing is governed by your agreement and settings with that provider.
OpenAI and Anthropic offer different consumer, business, enterprise, and API products, and their retention and model-improvement practices can differ by product and configuration. Review the privacy terms and controls that apply to the specific account and product you use.
We may maintain connection records, audit events, security logs, and diagnostic information to authenticate requests, prevent misuse, investigate incidents, enforce permissions, and support the Service. Request or response content is retained only where needed for these purposes, to provide the requested functionality, to comply with law, or as configured by the Customer. Third-party MCP clients and AI providers may retain their own copies under their terms.
Disconnecting an integration stops future access but does not necessarily delete data already transferred to a third party. To delete that data, you may also need to use the third party's deletion tools or contact that provider.
We may use Personal Data for the following purposes:
Where we rely on legitimate interests, we consider whether those interests are overridden by your rights and interests. Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.
When we process Customer Data as a processor, the Business Customer determines the legal basis and purposes, and our legal basis is the performance of our agreement and the Customer's documented instructions.
We may disclose Personal Data in the following circumstances.
If your Account is administered by a Business Customer, that Customer and its authorized administrators may access and control your Account, Customer Data, permissions, integrations, and activity. Information you share with other users, clients, invitees, or service providers through the Service is disclosed as directed by you or the Customer.
We use vendors to help provide, secure, support, and improve the Service. These may include:
When a vendor processes Customer Data on Schemon's behalf, it is subject to contractual data-protection obligations as described in the DPA. A current list and the applicable role notes are included in the DPA or a linked subprocessor notice.
We disclose data when you or a Business Customer connects or directs us to interact with a third-party service, including an MCP client, OpenAI, Anthropic, a calendar, communications service, or another integration. The third party's own terms and privacy policy apply to its processing.
We may disclose information where we reasonably believe disclosure is necessary to:
Where legally permitted, we will seek to notify the affected Customer before disclosing Customer Data in response to a compulsory request.
Personal Data may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction. Where required, we will provide notice before Personal Data becomes subject to a materially different privacy policy.
We may disclose Personal Data for another purpose when you consent or direct us to do so.
Schemon does not sell Personal Data for money.
Depending on the jurisdiction, certain advertising or analytics technologies may be treated as a "sale," "sharing," or processing for targeted advertising even when no money changes hands. Where required, we provide consent or opt-out controls through our cookie settings or another designated method. We do not use Customer Data exchanged through MCP tools for cross-context behavioral advertising.
Schemon is based in the United States, and our Service Providers may operate in the United States, the European Economic Area, the United Kingdom, and other countries. Personal Data may therefore be processed in countries whose privacy laws differ from those in your country.
Where required, we use appropriate transfer safeguards, which may include:
For Customer Data, additional international-transfer terms are set out in the DPA.
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, comply with law, resolve disputes, enforce agreements, maintain security, and meet legitimate business needs.
Our typical retention approach is:
Deletion from active systems may be followed by deletion from backups according to our backup rotation and secure deletion processes. We may retain limited information where required by law or necessary to establish, exercise, or defend legal claims.
Business Customers may configure or contract for different retention periods. The DPA and applicable service agreement control if they conflict with this general description.
We use technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. Measures may include encryption in transit, encryption at rest where appropriate, multi-factor authentication for critical systems, least-privilege access, access reviews, logging and monitoring, secure development practices, vulnerability management, incident response, backups, and personnel confidentiality and training.
No method of Internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your Account credentials, using available security settings, reviewing connected applications, and promptly notifying us of suspected unauthorized access.
For more information, see our Security Policy. Business Customers may also review the technical and organizational measures in the DPA.
Depending on your location and the context, you may have the right to:
You can update some Account information and communication settings in the Service. Marketing emails include an unsubscribe mechanism, although we may continue to send necessary service, billing, or security communications.
To exercise a right, email legal@schemon.com. We may need to verify your identity and authority. You may use an authorized agent where permitted by law, but we may require proof of authorization. We will not unlawfully discriminate against you for exercising a privacy right.
If Schemon processes your information on behalf of a Business Customer, submit your request to that Customer. If you contact us directly, we may forward the request to the Customer or ask you to identify the relevant Customer.
You may request deletion of your Account and associated Personal Data through the Account settings made available in the Portal or mobile application, or by contacting legal@schemon.com.
Deletion may be subject to:
Deleting a Schemon Account does not automatically delete copies of data previously transferred to Stripe, Intercom, OpenAI, Anthropic, another MCP client, or another third-party service. You may need to submit a separate request to that provider.
The Service may allow a Business Customer to submit information that is considered sensitive or special-category data under applicable law. The Customer is responsible for determining whether such processing is lawful, providing required notices, obtaining required consent or another valid legal basis, limiting access, and using appropriate Service settings.
Unless Schemon expressly agrees otherwise in writing and executes a Business Associate Agreement, the Service is not intended to receive or process Protected Health Information regulated by the U.S. Health Insurance Portability and Accountability Act (HIPAA). Do not submit HIPAA-regulated Protected Health Information to the Service without that written agreement.
Do not submit government identification numbers, financial account credentials, full payment-card details, passwords, authentication secrets, or other highly sensitive data unless the applicable feature expressly requires it and you are authorized to do so.
The Service is not directed to children under 13 or to anyone below the minimum age required in their jurisdiction to use the Service without parental or guardian consent. We do not knowingly collect Personal Data from a child in violation of applicable law.
If you believe a child has provided Personal Data unlawfully, contact legal@schemon.com. We will investigate and take appropriate steps, which may include deleting the information. Business Customers are responsible for obtaining any parental or guardian consent required for data they submit about minors.
The Service may link to or integrate with services not operated by Schemon. We do not control the privacy, security, or content practices of those third parties. Review their terms and privacy notices before providing information or enabling an integration.
We may update this Privacy Policy from time to time. We will post the updated version and change the "Last updated" date. If a change is material, we will provide additional notice where required, such as by email, in-product notice, or a notice on the Service.
For questions, requests, or complaints about this Privacy Policy or our privacy practices, contact:
You may also contact the Business Customer that provided you with access to the Service if your request concerns Customer Data controlled by that Customer.