Privacy Policy
Last updated 4 August 2026
Choir is a private, invitation-only tool built and operated by GTM Fabric. Our team uses it to draft, review, approve and schedule LinkedIn posts before publishing them from their own LinkedIn profiles. This policy explains what personal data Choir handles, why, and who else touches it.
Choir is not a consumer product. You can only use it if a GTM Fabric administrator has invited you, or if someone has sent you a private review link for a specific post.
Who we are
GTM Fabric is the data controller for the personal data described here. For any privacy question, or to exercise the rights set out below, email hello@gtmfabric.ai.
Data we receive from Google Sign-In
Signing in with Google is the only way members access Choir. We request three scopes, all of which Google classes as non-sensitive:
- openid and userinfo.email — your email address, and whether Google has verified it.
- userinfo.profile — your name and profile picture.
We use these for one purpose: to identify you and match your email address to an invited member of the workspace. If it does not match, you are refused access and nothing is stored. Your name and picture appear next to your drafts, comments and approvals so colleagues can see who did what.
Choir requests no other Google access. It cannot read your Gmail, Drive, Calendar or Contacts, and it does not ask for permission to.
Google API Services Limited Use disclosure
Choir's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through Google Sign-In is used only to provide and secure Choir's sign-in and identity features. We do not transfer it to third parties except as needed to run the service (see Processors below) or where law requires. We do not use it for advertising, we do not sell it, we do not use it to train generative AI or machine-learning models, and no human reads it except where you ask us to for support, or where security or law requires.
Other data Choir holds
- Content you create. Post drafts and their version history, titles, comments, approval decisions and notes, and any images you upload.
- Workspace records. Your membership and role, notifications addressed to you, and an activity log of actions taken in the workspace (who did what, and when).
- Review-link technical data. When someone opens or acts on a private review link, we record the IP address and browser user-agent of that request. This exists to rate-limit abuse and to show who approved what. It is security data, not analytics.
- A session cookie. A single signed cookie holds your user id so you stay logged in. It is not used for tracking, and Choir sets no advertising or analytics cookies.
Choir has no integration with LinkedIn. It never connects to your LinkedIn account, holds LinkedIn credentials, or posts on your behalf. When a post is published, a person copies the approved text into LinkedIn themselves, and Choir simply records that it happened and stores the resulting public post URL.
Processors we share data with
We keep this list short on purpose. Each of these is a service provider acting on our instructions.
| Provider | What it handles | Where |
|---|---|---|
| Sign-in and identity only | Global | |
| Vercel | Application hosting and request logs | United States |
| Supabase | Database and uploaded image storage | European Union (Ireland) |
| Anthropic | AI drafting. The post text and instructions you submit are sent to Claude only when you use a drafting feature | United States |
| Resend | Transactional email: review requests, approval codes, notifications | United States |
| Slack | Optional internal nudges. Only a short message and a link, never full post content | United States |
Anthropic does not use data submitted through its API to train its models. Where a provider is outside the UK or EEA, transfers rely on that provider's standard contractual clauses or an equivalent safeguard.
We do not sell personal data, we do not share it with advertisers, and we do not use it for automated decisions that produce legal effects.
How long we keep it
Workspace content and its history are kept while they are useful to the business, so that the record of who approved what stays intact. Your account details are kept while you are a member. When you leave, or on request, we delete or anonymise your personal data unless we must keep it for a legal or accounting reason.
Security
Access is invitation-only and authenticated through Google, so Choir stores no passwords for members. Traffic is encrypted in transit. Private review links carry a single-use random token, expire, and can be revoked. Comments are separated into internal and external threads, and the external view can only ever read the external thread.
Your rights
If you are in the UK or EEA you may request access to your personal data, correction of it, deletion, restriction of processing, or a copy in portable form, and you may object to processing. Email hello@gtmfabric.ai and we will respond within one month. You can also revoke Choir's access to your Google account at any time at myaccount.google.com/permissions, though doing so will stop you signing in. If you believe we have handled your data poorly you may complain to your local data protection authority.
Children
Choir is a workplace tool and is not intended for anyone under 16.
Changes
If we change how Choir handles personal data we will update this page and move the date at the top. Material changes affecting members will also be sent by email.