Privacy policy
This policy describes how Access Gateway (the "gateway"), a private tool operated by its owner, Maksim (maksim@kubot.ee), handles data from Google accounts and other mailboxes that the operator links to it.
Whose data
The gateway serves only mailboxes belonging to the operator and explicitly linked by him. Each Google account is linked through Google's own consent screen, signed in as that exact account. Mail from other people is processed only as part of the operator's own correspondence in those mailboxes.
Google user data accessed
For each linked Google account the gateway requests the Gmail scope https://www.googleapis.com/auth/gmail.modify and the basic openid and email scopes (to confirm which account was linked). It uses this access only to:
- search and read messages, threads and attachments;
- create and update drafts in that account;
- list and create labels, and apply or remove labels on messages and threads;
- delete only test drafts and test labels that the gateway itself created.
The gateway does not send email. Sending is blocked by policy and could happen only through a separate, explicit confirmation step by the operator, which is not enabled.
How data is used and where it goes
- Data is retrieved only when the operator's AI assistant (Claude, by Anthropic) makes a request in the operator's own session, and the result is returned to that session. This is the only transfer of the data, and it happens at the operator's direction.
- Email content is processed in memory to answer the request and is not stored by the gateway.
- Data is not sold, not used for advertising, not used to train AI models by the gateway, and not shared with any other third party.
- No person other than the operator reads the data, except where required by law.
Credentials and storage
- OAuth refresh tokens and other access credentials are stored in Google Cloud Secret Manager (region europe-north1), readable only by the gateway's own service identity. They are never shown in any output.
- Operational logs contain only technical metadata (operation name, mailbox, outcome, timing), never message content, search terms, addresses or credentials.
Retention and revocation
Credentials are kept until the operator removes them or revokes access. Access can be revoked at any time in the Google Account under Security → Third-party apps with account access; the gateway then loses access immediately.
Google API Services User Data Policy
Access Gateway's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes and contact
Changes to this policy are published on this page. Questions: maksim@kubot.ee.
Last updated 2026-10-07. Contact: maksim@kubot.ee