Privacy policy

Effective date: 2026-09-30.

This policy describes Roman Frołow's personal gmailctl setup, not the upstream project, Google's own services, or every feature of the email-assistant repository.

Data accessed and purpose

The local tool uses Google APIs to read labels and Gmail filter/basic-settings data and to reconcile filter definitions chosen by the owner. Scope access is limited to gmail.labels and gmail.settings.basic. This OAuth client does not request Gmail message-body access or message-sending access. Filter definitions can nevertheless contain private email addresses, search criteria, subject phrases, label names and forwarding-related settings from existing filters.

Storage and retention

Rule definitions, existing-filter snapshots and backups are stored locally on the owner's device in a git repository. OAuth client credentials and tokens are stored separately from git. Local copies remain until the owner deletes them; revoking OAuth access does not remove local backups. Gmail's settings and filter data remain with Google and are changed only through authorized operations. This informational website does not host filter exports, credentials or tokens, and does not provide a server-side Gmail database.

Use and disclosure

Data is used to carry out the owner's requested email-filter management, not for advertising, sale, profiling or general-purpose model training. The local client exchanges the necessary data with Google to perform API operations.

If the owner chooses to use an AI assistant to inspect or operate this setup, selected filter definitions or command output may be included in that assistant's session and processed by the chosen provider. Such use must be explicitly authorized for the task and comply with Google's Limited Use requirements; credentials and tokens must not be included. This policy does not claim that an AI provider's storage or training practices are controlled by this local tool. Private exports must not be published or sent to independent reviewers without owner approval. Any legally required disclosure is limited to the applicable requirement.

This setup's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Website and account control

The website is informational and has no OAuth login form or application-level analytics. Its hosting server may keep ordinary request/access logs, including IP addresses and request metadata. The hosting server rotates its nginx logs daily and retains 14 rotated logs under its current configuration.

The owner can revoke the application's access through Google Account permissions and remove local credentials and retained files separately. Contact for questions: rofrol@gmail.com. Any material change in actual consumers, scopes, storage or sharing requires updating the disclosures before that use begins.