Privacy Policy
Last updated: June 26, 2026
This Privacy Policy explains how The Computer Work Company, Inc. ("we," "us," or "our") collects, uses, stores, and protects information when users connect Google Workspace accounts to our service.
Information We Collect
We collect account and workspace information only when a user connects an account, signs in, or directs the service to perform an action.
Account information may include name, email address, profile image, account identifier, organization or workspace metadata, authentication status, and connected-account identifiers.
Google Workspace information may include:
- Gmail: message IDs, thread IDs, labels, headers, recipients, senders, subject lines, timestamps, message bodies, attachments, draft content, and mailbox state needed to search, read, draft, send, label, archive, trash, or otherwise modify messages at the user's direction.
- Google Drive: file and folder IDs, names, metadata, permissions visible to the user, file contents, exported file contents, comments, and file changes needed to search, read, create, update, organize, copy, export, download, or manage files at the user's direction.
- Google Calendar: calendar IDs, event IDs, attendees, titles, descriptions, locations, conference details, reminders, free/busy information, timestamps, and event metadata needed to read availability and create, update, respond to, or delete events at the user's direction.
- Google Docs: document IDs, text, structure, tables, comments, paragraph ranges, and edits needed to read or update documents at the user's direction.
- Google Sheets: spreadsheet IDs, sheet metadata, cell values, formulas, comments, and range updates needed to read, search, duplicate, create, or update spreadsheets at the user's direction.
- Google Slides: presentation IDs, slide IDs, speaker notes or text content, thumbnails, tables, comments, and presentation edits needed to read, create, copy, or update presentations at the user's direction.
We may also collect operational information such as device/browser metadata, request metadata, IP address, approximate location derived from IP address, connection status, error status, audit events, product analytics events, masked session recordings, turn/status/timing metadata, error reports, support/debug submissions, and security logs.
How We Use Information
We use information to:
- authenticate users and maintain connected accounts;
- run user-directed workflows and agent actions;
- search, read, summarize, draft, send, create, update, organize, or delete Google Workspace content when requested by the user;
- show connected accounts, connection status, and account metadata;
- understand approximate user location for security, diagnostics, abuse prevention, localization, and product analytics;
- troubleshoot, secure, monitor, and improve the service;
- comply with law, security requirements, and our agreements.
We do not use Google Workspace data for advertising. We do not sell Google Workspace data. We do not use Google Workspace data to train generalized AI or machine learning models unrelated to the user's requested workflow.
Google API Services User Data Policy
Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace data is used only to provide or improve user-facing features that are prominent in the service. We do not transfer Google Workspace data except as needed to provide the service, comply with law, protect security, or with the user's direction or consent.
AI Processing
When a user asks the service to analyze, summarize, draft, transform, or act on Google Workspace content, relevant content may be sent to AI model providers or infrastructure processors solely to complete that user-directed request. We require processors to handle data under contractual confidentiality, security, and use restrictions. We do not permit processors to use Google Workspace data for advertising or unrelated model training.
Product Analytics, Session Recordings, Debug Traces, And Local Privacy Controls
We use product analytics and diagnostic tools to understand service reliability, errors, and product usage. These tools may collect account identifiers, email address, device/application metadata, page or action events, error reports, request metadata, IP address, approximate location derived from IP address, and usage metadata.
We may use masked session recordings to troubleshoot product behavior and improve the service. Session recordings are configured to mask visible text as *****, so Google Workspace content, prompts, and other user-visible text should not be readable in recordings. Session recordings may still show non-text interaction metadata such as clicks, navigation, timing, layout, and masked input activity.
The desktop application may store user-visible workflow outputs, thread records, memory files, browser profile records, uploads, exports, and other application data locally on the user's device or in the user's configured local data directory. Where available, users may configure local memory behavior, including whether local memory is read into prompts or written after work, and may choose whether to start user-directed indexing of local or connected sources.
Local privacy controls do not disable user-directed processing needed to operate requested features, including sign-in, account and organization services, connected-account APIs, AI model providers, payment or account services, product telemetry, masked session recordings, error reporting, or debug traces and bug reports that a user or operator affirmatively submits for support. Product telemetry may include account identifiers, device/application metadata, page or action events, error information, request metadata, turn identifiers, timing, model, token-usage, and status metadata where enabled.
Users or operators may also submit debug traces or bug reports for support or security troubleshooting. Debug traces and bug reports are stored through private support and diagnostic infrastructure, currently including Cloudflare R2 through our trace-ingest workflow, with access limited to authorized personnel. We retain debug traces only as long as needed to investigate the related support or security issue, unless a longer period is required for legal, security, or compliance reasons.
Subprocessors And Infrastructure Providers
We use the following providers to operate the service, connect user-authorized Google Workspace accounts, process user-directed workflows, monitor reliability, and handle support or security operations.
| Provider | Purpose | Data processed |
|---|---|---|
| Google Cloud Platform | Hosting, database, secret management, build/deployment, operational logging, diagnostic storage where applicable, and infrastructure security. | Account metadata, connection metadata, service logs, configuration, secrets, diagnostic records, operational records, and bug reports where applicable. |
| Google Workspace APIs | User-authorized source and destination for connected-account actions. | Gmail, Drive, Calendar, Docs, Sheets, Slides, and related Google account data that the user authorizes and directs the service to access. |
| Self-hosted Nango integration infrastructure | OAuth connection flow, token management, provider API proxying, and connection lifecycle management, operated by us on our infrastructure. | OAuth tokens, connection metadata, provider request metadata, and Google Workspace data transmitted for user-directed actions. |
| PostHog | Product telemetry, masked session recordings, error reporting, approximate location analytics, and operational diagnostics. | Account identifiers, email address, IP address, approximate location derived from IP address, device/application metadata, page/action events, masked session recordings, error reports, and usage metadata. |
| Cloudflare | Worker and R2 infrastructure for debug trace and bug report ingestion/storage, and release or support infrastructure where applicable. | Debug traces, bug reports, related operational/support records, and release/support metadata where applicable. |
| OpenAI | User-directed AI processing when selected or routed through a user-authorized ChatGPT/OpenAI path. | User prompts, AI responses, and selected Google Workspace content needed to complete the user's requested workflow. |
| Anthropic | User-directed AI processing when selected or routed through Anthropic APIs. | User prompts, AI responses, and selected Google Workspace content needed to complete the user's requested workflow. |
Google Workspace data is shared with these providers only as needed to provide, secure, troubleshoot, or support user-facing features; comply with law; or follow the user's direction.
OAuth Tokens And Connected Accounts
When users connect Google accounts, OAuth tokens are stored and managed by our OAuth/integration infrastructure and related processors. Tokens are used to access Google APIs only for user-authorized scopes and user-directed workflows. Users can disconnect connected accounts, which disables future access through the service. Users may also revoke access directly from their Google Account security settings.
Storage And Retention
We retain account, connection, workflow, audit, analytics, diagnostic, and operational records for as long as needed to provide the service, secure the service, comply with legal obligations, resolve disputes, and enforce agreements.
Google Workspace content is processed for user-directed workflows and is not intentionally retained on our servers as workflow output, except where included in user- or operator-submitted debug traces, bug reports, support records, security records, or other records described in this Privacy Policy. User-visible outputs are stored locally on the user's computer where applicable. We may retain limited operational, security, diagnostic, analytics, and audit metadata needed to run and secure the service.
Default retention targets:
- OAuth connection records and credentials: retained while the account remains connected and deleted or disabled when the user disconnects the account, subject to limited security, audit, backup, and provider deletion windows.
- Workflow logs, telemetry records, and metadata: retained for the period needed to operate, secure, troubleshoot, and improve the service. Local privacy controls may control local memory and indexing behavior where those settings are available.
- User-visible workflow outputs: stored on the user's computer and controlled/deleted by the user locally.
- Session recordings and product analytics: retained only for operational, diagnostic, security, and product-improvement purposes according to our analytics retention settings.
- Security logs: retained for security, abuse prevention, incident response, and audit purposes.
- Debug traces and bug reports: retained only as long as needed to investigate the related support or security issue, unless a longer period is required for legal, security, or compliance reasons.
- Backups: retained according to backup and disaster recovery practices.
Sharing
We may share information with:
- infrastructure providers that host, secure, monitor, or process the service;
- OAuth and integration providers used to connect Google Workspace;
- AI/model providers used for user-directed features;
- support and security vendors;
- professional advisors;
- authorities when required by law or necessary to protect rights, users, or security;
- third parties in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections.
We do not sell personal information or Google Workspace data.
Security
We use administrative, technical, and organizational safeguards designed to protect user data, including encryption in transit, access controls, least-privilege production access, secrets management, logging, monitoring, and vulnerability management. No system is perfectly secure, but we work to prevent unauthorized access, disclosure, alteration, or destruction of user data.
User Controls
Users may:
- connect or disconnect Google accounts;
- configure local privacy controls where available, including local memory and user-directed indexing controls;
- revoke OAuth access in their Google Account settings;
- delete workflows, outputs, or account data where supported;
- request access, correction, deletion, or export of personal information by contacting us.
We may need to retain limited records where required for security, legal compliance, dispute resolution, or backup integrity.
Children
The service is not intended for children under 13 or the minimum age required by applicable law. We do not knowingly collect personal information from children.
International Transfers
Information may be processed in the United States and other countries where we or our subprocessors operate. We use appropriate safeguards for international transfers where required by law.
Changes
We may update this Privacy Policy from time to time. If changes are material, we will provide notice as required by law or through the service.
Contact Us
Questions or requests may be sent to privacy@thecomputerworkcompany.com.
