Privacy policy

How this deployment handles Google user data.

This service is a private, self-hosted deployment run by one operator for their own Gmail accounts. It has no other users, no shared backend, and no central operator. The authors of the underlying open-source project receive no data from it.

What is accessed

When the operator connects a Gmail account, this service asks Google for permission to read, compose, send, and organize mail in that account. Google shows the exact permissions on its own consent screen before anything is granted. No other Google product or data is requested, and this permission does not allow permanently erasing messages outright -- messages can only be moved to Trash.

How it is used

Message data is fetched from Gmail only in direct response to a request the operator makes in their AI assistant -- for example, searching a mailbox or opening a specific message. Results are returned to that assistant so it can answer. Nothing is fetched on a schedule, in the background, or for any purpose the operator did not ask for.

What is stored

This service stores the OAuth refresh token for each connected account, plus that account's alias and email address, in Google Secret Manager inside the operator's own Google Cloud project. That is the only persistent storage. Message content, subjects, senders, and attachments are never written to disk or to any database -- they pass through memory to answer one request and are then discarded.

Who it is shared with

Message data is sent only to the AI assistant the operator connected, at the moment they ask for it. It is not sold, rented, or shared with anyone else. It is not used for advertising, for building profiles, or to train any generalized artificial intelligence or machine learning model. There is no analytics, telemetry, or crash reporting in this service of any kind.

This application's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Logging

Operational logs record request timing, HTTP status codes, tool names, and account aliases so the operator can debug their own deployment. They never contain OAuth tokens, credentials, message bodies, subject lines, attachment content, or sender and recipient addresses.

Retention and deletion

Disconnecting an account from this service's admin page deletes its stored token. The operator can also revoke this application's access to any Google Account at any time from Google Account permissions, which immediately and permanently ends this service's access to that mailbox. Deleting the underlying Google Cloud project destroys all stored data.

Changes

Because each deployment is independent and private, any change to this policy takes effect for that deployment when its operator updates and redeploys the service.