This Privacy Policy describes how Auto Email ("we", "us", or "our service") handles data accessed through Google OAuth APIs. Auto Email is an internal, non-public operational automation tool that creates scheduled reporting Gmail drafts for authorized store accounts.
1. Google OAuth Data Access & Scope
Auto Email requests access solely to the following Google OAuth scope:
https://www.googleapis.com/auth/gmail.compose(Create, draft, and send emails)
Purpose of Scope: This scope is strictly used by our automated job runner to construct pre-formatted operational report drafts within the designated store Gmail account.
Strict Scope Boundaries:
• No Inbox Reading: We do not request gmail.readonly or full mail access. We do not read, parse, or index incoming emails, inbox contents, or existing conversations.
• No Automatic Sending: Our automation creates email drafts only. Drafts remain in the store's drafts folder for operational review and manual dispatch.
2. Use and Retention of Google User Data
Google user data obtained through the Google API is handled under strict operational limits:
- Draft Creation Only: Information accessed through the API is used solely to generate the scheduled operational drafts.
- No Advertising or Profiling: We never use Google user data for advertising, marketing, analytics profiling, or commercial resale.
- No Sale of Data: We do not sell, rent, or trade Google user data or email contents to any third parties under any circumstances.
- No Third-Party Sharing: User data is never transferred or shared with external parties, except as required by the underlying cloud hosting provider (Google Cloud Platform) to run the automated workload.
3. Security and Storage of OAuth Credentials
When an authorized administrator authorizes a store account, OAuth tokens (access and refresh tokens) are generated.
- Tokens are stored securely in access-controlled, encrypted Google Cloud infrastructure (Google Cloud Firestore / Secret Manager).
- Tokens are accessed strictly by the automated service account responsible for executing scheduled draft jobs.
- Tokens are never exposed in client-side code, logs, or public repositories.
4. User Rights and Revoking Access
You have complete control over Auto Email's access to your Google Account. You may review or revoke access at any time:
- Visit your Google Account Third-Party Permissions page.
- Locate Auto Email in the list of authorized third-party applications.
- Click Remove Access. Upon revocation, the service will immediately lose the ability to generate drafts for your account.
5. Google API Limited Use Disclosure
Auto Email's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Contact Information
If you have questions regarding this Privacy Policy or our operational data handling, please contact the administrator:
Email: ferryrusly123@gmail.com (replace with official contact email)