Back to sign in →

Privacy Policy

L10, Last updated September 26, 2026

L10 (“the app”, “we”) is an internal application operated by SourceFuse for its people. Teams use it to run their weekly meeting: a scorecard of numbers, quarterly rocks, to-dos, issues and headlines. This policy explains what data the app handles, why, and the choices you have.

This is an internal tool, not a consumer product. It is open only to people with a SourceFuse Google account, and it is not intended for the general public.

1. Information we process

  • Account data: your name, work email and profile photo, which Google provides when you sign in, and your role in the app. The app refreshes your photo each time you sign in, so a change to your Google photo shows here too. L10 has no password.
  • Meeting data: what you and your teammates enter, such as scorecard numbers, rocks and their milestones, to-dos, issues and their notes, headlines, and who attended each meeting.
  • Numbers filled in automatically: a team can add scorecard lines that are filled from SourceFuse’s internal systems, such as weekly utilization or the number of projects that started without a purchase order. A line of the second kind lists the projects behind the count, with each project’s client and contract value.
  • Usage and audit data: records of sign-ins and sign-outs, changes to who is on a team, and changes to access, with who made them and when, kept for security and audit purposes.
  • Google account data, only if you choose to link Google to export a table (see Section 4).

2. How the data is collected

Your name and email come from Google when you sign in. Meeting data is what you and your teammates type into the app. Automatically filled numbers are read from SourceFuse’s internal systems on a read-only basis; the app never writes back to them.

3. How we use the data

  • To run your team’s meetings and keep a record of what was agreed.
  • To sign you in, and to show each person only the teams they belong to.
  • To keep an audit trail of security-relevant actions.
  • To tell team members about their meetings through the app’s notification bell. The app sends no email.

We do not sell personal data, and we do not use it for advertising or for any purpose unrelated to running this internal tool.

4. Google account data & “Export to Google Sheets”

The app offers an optional feature to export the table you are viewing to a Google Sheet. If you choose to use it, you link your own SourceFuse Google account, and the app requests a single, narrow permission: the Google Drive drive.file scope.

Google API Services User Data Policy, Limited Use. L10’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • The drive.file scope lets the app create and manage only the files it creates on your behalf: the export spreadsheets. It does not allow the app to see, read, or access any other files in your Google Drive.
  • Each export is created in your own Google Drive and owned by you. SourceFuse does not receive ownership of, or automatic access to, those files.
  • We store an encrypted Google refresh token so you don’t have to re-authorize on every export. It is used solely to create your exports and is never shared or used for any other purpose.
  • You can disconnect your Google account at any time, which revokes the app’s access and deletes the stored token.

5. Who can see your data

The people on a team see that team’s meeting data. A team’s organisers decide who is on it. SourceFuse administrators can see and organise every team. Nobody else can open a team’s meetings.

6. Where the data lives (service providers)

We use a small number of vetted providers to run the app. They process data on our behalf:

  • Amazon Web Services (AWS), application hosting and the application database, in its Mumbai (India) region.
  • Google, for signing in, and for the optional export feature you start.
  • GitHub, where the app’s code is kept, built and deployed. The data described in Section 1 is not sent there.

The app was previously hosted on Vercel, with its database on Supabase. Until that earlier setup is retired, a copy of the data also remains there.

7. Security

You sign in with your SourceFuse Google account, and the app keeps no password. Google connection tokens are encrypted at rest; traffic is served over HTTPS; and what each person can open is decided by team membership and enforced on the server. The app’s own login to its database can open only the data L10 uses. Sensitive actions are recorded in an append-only audit log. Sign-in sessions expire 48 hours after you sign in and are not extended by activity (see the Cookie & Session Notice).

8. Retention

Account and meeting data is kept for as long as needed to run the app and meet SourceFuse’s internal recordkeeping needs. Audit records are kept as an append-only history. Google tokens are kept only while your account is linked and are deleted when you disconnect.

9. Your choices

  • The Google export feature is optional; you can decline to link Google and use the rest of the app as normal.
  • You can disconnect a linked Google account at any time.
  • For questions about, access to, or correction of your personal data, contact us (Section 10). Access is otherwise governed by SourceFuse’s internal policies.

10. Contact

Questions about this policy or your data: ashwani.diwedi@sourcefuse.com.

11. Changes

We may update this policy as the app changes. Material changes will be reflected here with a new “last updated” date at the top of the page.

Privacy PolicyTerms of ServiceAcceptable UseCookiesContact