Privacy Policy
private-automation · Last updated: October 4, 2026
This Privacy Policy describes how private-automation ("the app") collects, uses and shares information when it accesses Google user data through Google APIs.
1. Who operates the app
The app is a private, server-side email-sending service operated by an individual for personal use. It has no public user accounts. The only Google account it accesses is the account of the owner who authorized it.
2. Google user data accessed
- Gmail send permission (OAuth scope
https://www.googleapis.com/auth/gmail.send): used solely to send email messages from the authorizing account. - An OAuth refresh token for that account, stored as an encrypted environment variable on the hosting platform (Vercel) and used only to obtain short-lived access tokens.
The app does not read, search, list, modify or delete existing email, labels, contacts, calendar or any other Google data.
3. How data is used
- Message data submitted to the app's API by the owner's own systems (recipients, subject, body, attachments) is converted into an email and passed directly to the Gmail API to be sent.
- Message content is processed in memory only for the duration of the request and is not stored by the app.
- The hosting platform may keep short-term operational logs (such as request time, status code and error messages) for troubleshooting.
4. Data sharing
Google user data is not sold, rented or shared with third parties, and is not used for advertising. Data is transmitted only to Google (to send the email) and processed on the hosting platform (Vercel) as required to run the service. All transmission uses HTTPS.
5. Google API Services User Data Policy
The app's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data retention and deletion
Email content is not retained by the app. Sent messages remain in the authorizing account's Gmail "Sent" folder under that account owner's control. Access can be revoked at any time at https://myaccount.google.com/permissions, after which the stored refresh token stops working; the owner also deletes it from the hosting configuration.
7. Security
The API is protected by a secret key, credentials are stored as encrypted environment variables, and the app does not access the server's file system or fetch remote content unless explicitly enabled by the owner.
8. Changes
Updates to this policy will be posted on this page with a new "Last updated" date.
9. Contact
Questions about this policy can be submitted via GitHub Issues.