Information We Access
Email AI Agent is a personal email automation application designed to monitor incoming messages, classify their priority, and trigger notifications based on user-defined importance criteria.
The application accesses Gmail data only after the user explicitly grants permission through Google OAuth authorization. The application does not collect, read, or intercept any Google account information without this direct, interactive consent.
Categories of Gmail Data Accessed:
Email Metadata
Sender email address, recipient email addresses, subject line, timestamp/date received, message identifiers, and email headers when required by the configured workflow.
Email Message Content
Message body snippets or full email text when necessary to analyze the context, category, urgency, actionability, or importance score of incoming communications.
Data access is restricted strictly to the scopes requested during the Google OAuth consent flow and used only within the execution boundaries of the automation workflow.
How Gmail Data Is Used
Gmail information accessed by Email AI Agent is used exclusively for the personal email sorting, classification, prioritization, and notification features configured and requested by the user.
Permitted Operational Purposes:
- Email Monitoring: Monitoring the inbox for newly arrived messages.
- Classification & Categorization: Parsing email content and metadata to determine priority, subject matter, urgency, and action items.
- Alert Notification Triggers: Dispatching notifications (such as alert messages) to the user when an email satisfies the user-defined importance criteria.
- Workflow Operation: Maintaining and executing the automation pipeline as directly instructed by the user.
Strict Prohibitions — What Gmail Data Is NOT Used For:
Automated Processing
Email information may be processed by automated programmatic rules, workflow evaluation engines, or machine-learning models to determine message importance, categorization, and priority.
How Automated Processing Operates:
- Incoming message headers and content are evaluated against predefined urgency criteria (such as keywords, sender status, time sensitivity, and request context).
- Machine-learning or natural-language evaluation is utilized strictly for contextual triage and relevance scoring.
- No automated decisions are made that have legal or significant binding effects on users outside the scope of delivering the configured notification alerts.
Data Storage and Retention
The application follows strict data minimization principles. Email AI Agent is architected not to permanently store complete email content or maintain an enduring inbox database.
Temporary Processing Only
Email data is held temporarily in volatile memory or transient workflow execution state solely during the execution cycle required to classify the message and dispatch the alert.
Automatic Data Removal
Once the workflow run finishes execution, temporary variables and in-memory email representations are automatically discarded. No long-term archive of email bodies is maintained.
Operational logs that record execution status (e.g., workflow success/error status and timestamps) contain minimal technical metadata and are purged according to standard server retention cycles.
Third-Party Services and Infrastructure
In order to execute automation logic, classify message content, and deliver notifications, the application utilizes dedicated infrastructure and service components. We are fully transparent about where data is processed:
Automation Engine Infrastructure
The automation workflows run on a secure, dedicated automation environment (self-hosted or cloud-hosted). This environment connects securely to the Gmail API using OAuth 2.0 credentials and processes messages according to the user's specific workflow configuration.
Machine-Learning / Classification Services
If the automation workflow utilizes an external machine-learning API or LLM provider for email evaluation, only the specific text required to determine classification and importance is transmitted to that service. Such data is transmitted over encrypted channels and is processed solely for generating the classification response, without being used to train generalized commercial models.
Notification Delivery Gateways
When an email triggers an alert, concise notification summaries (such as sender name and brief message summary) are relayed through the user-configured notification channel (such as a messaging API) to deliver real-time alerts.
Data Sharing
We do not sell, rent, lease, or trade personal data or Gmail information to any third party.
Gmail data is never shared with third parties for commercial advertising, marketing, profiling, or data brokerage purposes. Data is only processed by technical infrastructure and services strictly required to execute the user's automation and notification requests as described in Section 5.
Security Measures
We implement robust technical and organizational security measures to protect Google user data against unauthorized access, loss, alteration, or misuse:
OAuth 2.0 Authentication
Direct Google token exchange; user passwords are never seen or stored.
Encrypted Transmission
All data in transit is protected using HTTPS/TLS 1.2+ encryption.
Credential Protection
OAuth access tokens and API secrets are stored in protected environment vaults.
Principle of Least Privilege
Access is restricted strictly to the minimal scopes required for operation.
User Control and Revoking Access
Users retain continuous, complete control over the application's permissions. You may inspect or immediately revoke access to your Google account at any time through Google Account security settings.
Step-by-Step Revocation Guide:
- Navigate to your Google Account permissions page: Google Security - Third-party apps with account access
- Find Email AI Agent in the list of authorized third-party applications.
- Click on the application and select Remove Access (or "Delete all connections").
Upon revocation, Google immediately invalidates all active access tokens, and the application will be unable to access any Gmail data until re-authorized by the user.
Data Deletion Requests
Because Email AI Agent functions as an automated processing workflow without a permanent user database, Gmail message content is not intentionally stored or retained after processing concludes.
If you wish to request the manual verification or deletion of any technical logs, cached metadata, or connection configurations associated with your workflow, you may contact the administrator at the email address provided in Section 11.
Changes to this Privacy Policy
We may periodically update this Privacy Policy to reflect changes in our technology, operational practices, legal obligations, or Google API policy requirements.
Any updates will be published directly on this page, and the Effective date at the top of this document will be updated accordingly. We encourage users to review this policy periodically to remain informed about how their data is handled.
Contact Information
If you have questions, feedback, inquiries, or privacy-related requests regarding this Privacy Policy or the operation of Email AI Agent, please contact the developer: