Privacy Policy
OpenClaw Gmail Reports
Last updated: August 26, 2026
Purpose
This is a personal, single-user application that emails scheduled Agentic AI security and governance reports to its owner. It is not offered to other users.
Data accessed
The application uses the Google OAuth scope
https://www.googleapis.com/auth/gmail.send. It receives an OAuth refresh token
and uses the owner's Gmail address as the fixed sender and recipient. It does not request
access to read, list, modify, or delete existing Gmail data.
How data is used
Google user data is used only to authenticate a Gmail API request and send a scheduled report to the fixed address. It is not used for advertising, profiling, analytics, or training AI models.
Storage and security
The OAuth client secret and refresh token are stored as Cloudflare Secrets. They are not placed in source control, public pages, report content, or application logs. Short-lived access tokens are requested only when a report is ready to send.
Sharing
Google user data is not sold, rented, or shared with third parties. Cloudflare provides the application hosting and secret-storage infrastructure, and Google provides the Gmail API. No other processor receives the OAuth credentials or Gmail data.
Retention and deletion
The refresh token is retained only while email delivery is enabled. Disabling the integration removes the corresponding Cloudflare Secrets. Sent messages remain subject to the owner's normal Gmail retention controls.
Revoking access
The owner can revoke the application's Google access at any time from Google Account permissions. Revocation prevents any further Gmail API delivery until access is explicitly granted again.
Google API Services User Data Policy
The use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Contact
Questions about this policy can be sent to suzuoki@gmail.com.