Privacy Policy

Scope and contact

This policy describes the Workforce Gmail mailbox integration operated through the support contact superiormobile7@gmail.com. It covers Google data accessed by that integration and associated workflow records. Contact that address with privacy questions, requests to disconnect an account, or requests to delete retained Workforce data.

Data accessed and purposes

With the account owner's Google authorization and an authorized operator request, Workforce reads selected Gmail messages and threads. Data can include message and thread identifiers, sender and recipient addresses, subject lines, timestamps, labels, and message body text. The integration reads this information to reconcile threads, summarize and classify messages, identify urgency and possible deadlines, and prepare grounded reply drafts.

The OAuth configuration requests Gmail modify and compose permissions. These permissions can authorize broader Gmail actions than this release enables. Workforce applies separate application authority checks: M0 allows review; M1 adds reply-draft preparation; M2 adds approved reversible organization. The present release disables sending and does not implement permanent deletion. OAuth permission alone does not authorize unrestricted action.

Processing and service providers

Selected message content, including body text and header metadata, is sent to Cloudflare Workers AI for classification, summaries, and draft generation. Cloudflare Workers and Workflows run the mailbox job. Cloudflare R2 stores audit evidence. Cloudflare therefore processes Google-derived data to deliver these disclosed features. Google processes account authorization and Gmail API requests under its own applicable terms and privacy practices.

The mailbox implementation uses Cloudflare-hosted AI models. This policy does not claim that model inference is performed solely on the user's device. Workforce does not use Gmail data to train a general-purpose AI model. This statement describes Workforce's permitted use; it is not a claim of independently audited service-provider behavior.

Storage and retention

OAuth client credentials and the refresh token are maintained as server-side secrets. They are not published in this website or source repository. Workflow state supports retries and continuity. R2 evidence can retain message/thread identifiers, classifications, summaries, reasons, model identity, draft identifiers, organization results, timestamps, and integrity metadata. Summaries and reasons may contain information derived from email content. Workflow state can also retain data used during execution, including selected message content and generated drafts.

Retention is managed by the operator. The reviewed mailbox implementation does not implement an automatic deletion deadline for its R2 evidence. This policy therefore does not promise a fixed automatic expiry. Request deletion through the contact above. The operator will identify and remove applicable retained Workforce records, subject to necessary legal or security obligations, and explain any records that cannot be removed. Disconnecting Google access does not itself delete existing Workforce records or Gmail drafts and labels.

Sharing, access, and Limited Use

Workforce's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Google-derived data is used to provide the disclosed mailbox features. Workforce does not sell Google data, use it for advertising, or use it to determine creditworthiness. Access by an operator to specific mailbox content requires the account owner's affirmative authorization, except where access is necessary for security investigation or applicable law. Service-provider processing is limited to delivery of these features and permitted security or legal purposes. Any new use requiring consent will be disclosed before that use begins.

Google policy: https://developers.google.com/terms/api-services-user-data-policy

Security and your controls

Workforce uses authenticated operator access, server-side secrets, application authority checks, and execution evidence to constrain mailbox activity. No system can guarantee absolute security. Do not authorize access to an account unless you understand the disclosed processing.

You can revoke Workforce access in your Google Account's third-party connections settings. Revocation prevents future authorized Gmail access using the revoked grant; it does not undo previously created drafts or mailbox organization. Contact superiormobile7@gmail.com to disconnect the integration and request deletion of retained Workforce records. Do not include passwords, refresh tokens, client secrets, or full sensitive email contents in a support message.

Policy changes

This page will record updates with a new effective date. Material changes to Google-data use will be disclosed, and additional consent will be obtained when required before the changed use begins.