Privacy Policy
Mail-Document-Extraction
Effective date: 5 September 2026
1. Scope
This policy applies to the privately operated Mail-Document-Extraction OAuth application and its two separate components: the Email Extraction Tool and the Document Extraction Tool.
2. Data accessed
Depending on the authorised operation, the application may access Gmail message content and metadata, Google Drive files and metadata, Google Sheets data used by the extraction tools, Google Docs content used by the document workflow, Apps Script project or runtime functions required by the existing tools, and the signed-in Google account email address.
3. Purpose of access
Google user data is accessed only to execute the operator-authorised corpus extraction workflow, preserve source provenance, maintain operational ledgers and status, produce structured extraction artefacts, and generate governed corpus outputs.
4. Data handling
- The Email Extraction Tool and Document Extraction Tool remain technically separate applications with a controlled handoff.
- Email outputs preserve message and thread identifiers, dates, sender and recipient data, subjects, body text, label metadata, and deterministic source provenance as required by the workflow.
- Email attachments remain separate source artefacts for the Document Extraction Tool unless a separately approved change alters that model.
- Generated extraction artefacts and corpus outputs are stored only in the operator-controlled Google and working environment used for this project.
5. Sharing, sale and advertising
The OAuth application does not sell Google user data and does not use Google user data for advertising, profiling, or unrelated commercial targeting. Access is limited to the authorised extraction purpose.
Any later operator-controlled use of generated corpus files in external analysis services is a separate, deliberate action by the operator and is not an automatic function of this OAuth application.
6. Retention and deletion
Source and extracted artefacts are retained according to the operator's governed corpus and audit requirements. Because provenance and auditability are core workflow requirements, deletion is controlled rather than automatic. The operator can remove generated artefacts and revoke the application's Google account access when required.
7. Security
OAuth credentials and tokens are treated as restricted configuration material. They must not be published in source artefacts, public pages, shared continuity records, or the extraction corpus.
8. OAuth scopes
The current authorised scope set is limited to the established Email and Document scope union:
https://www.googleapis.com/auth/script.scriptapphttps://mail.google.com/https://www.googleapis.com/auth/drivehttps://www.googleapis.com/auth/spreadsheetshttps://www.googleapis.com/auth/drive.apps.readonlyhttps://www.googleapis.com/auth/script.external_requesthttps://www.googleapis.com/auth/documentshttps://www.googleapis.com/auth/script.container.uihttps://www.googleapis.com/auth/userinfo.email
No additional scopes are authorised by this policy.
9. Contact
Privacy questions should be directed to the operator using the support contact shown on the Google OAuth consent screen for Mail-Document-Extraction.