Privacy policy

This policy describes how Access Gateway (the "gateway"), a private tool operated by its owner, Maksim (maksim@kubot.ee), handles data from Google accounts and other mailboxes that the operator links to it.

Whose data

The gateway serves only mailboxes belonging to the operator and explicitly linked by him. Each Google account is linked through Google's own consent screen, signed in as that exact account. Mail from other people is processed only as part of the operator's own correspondence in those mailboxes.

Google user data accessed

For each linked Google account the gateway requests the Gmail scope https://www.googleapis.com/auth/gmail.modify and the basic openid and email scopes (to confirm which account was linked). It uses this access only to:

The gateway does not send email. Sending is blocked by policy and could happen only through a separate, explicit confirmation step by the operator, which is not enabled.

How data is used and where it goes

Credentials and storage

Retention and revocation

Credentials are kept until the operator removes them or revokes access. Access can be revoked at any time in the Google Account under Security → Third-party apps with account access; the gateway then loses access immediately.

Google API Services User Data Policy

Access Gateway's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes and contact

Changes to this policy are published on this page. Questions: maksim@kubot.ee.

Last updated 2026-10-07. Contact: maksim@kubot.ee