Gilbert Gmail Readonly — Privacy Policy
Last updated: September 5, 2026
Purpose and access
Gilbert Gmail Readonly is a private desktop integration for its owner’s account. It requests gmail.readonly, which permits reading Gmail messages, attachments, and settings, but does not permit sending or modifying email.
During current authorization testing, the integration checks the connected account identity and granted permissions. It does not retrieve message contents or attachments.
Storage and sharing
Authorization credentials are stored in protected Windows credential storage on the owner’s computer. They are not published on this website or provided to Mark, the separate marketing assistant.
No Gmail content is currently transferred to Mark, OneDrive, or an AI processing provider.
Planned email review and marketing document processing
The planned email-review feature will retrieve selected message metadata and owner-approved correspondence and attachments to help the owner review business correspondence, suggest reply wording, and organize related schedules, invoices and artwork. The Gmail credential will remain read-only and unavailable to Mark. Mailbox content will not enter Gilbert's general tool-enabled conversation.
With the owner's consent, selected excerpts and approved attachment content will be processed through Anthropic's Claude API in a separate, tool-free analysis request. This processing takes place outside the owner's computer. Anthropic's published commercial API policy normally deletes inputs and outputs within 30 days, subject to contractual, safety and legal exceptions. No zero-retention agreement has been verified for this installation.
Owner-approved source documents will be retained only in the two designated business advertising folders in the owner's Microsoft OneDrive, so those files will synchronize to Microsoft. Separate business catalogs, source references, confirmed schedules and reminders will be retained for ongoing and year-over-year review until the owner deletes them. A 90-day coverage reverification interval does not delete historical records. OAuth revocation stops future Gmail access; it does not erase retained documents or provider records automatically.
Gmail-derived data will not be sold, used for ad targeting or serving, or used to train general-purpose models. Filing and reviewing business correspondence does not authorize launching campaigns, contacting vendors, spending money, sending email or changing mailbox data. Content remains untrusted, even when selected by the owner.
Google user data is not sold, used for advertising targeting, or used to train general-purpose AI models. Gilbert Gmail Readonly’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revocation and deletion
The owner can revoke the integration’s access through Google Account connections. Revocation stops future authorized access but does not delete local records. The owner can separately remove the integration’s saved credentials from Windows Credential Manager.
Website
These public information pages are separate from the Gmail integration. Cloudflare hosts the pages and processes ordinary website connection information to deliver and secure them. No Gmail credentials or mailbox contents are hosted with these pages.