Gmail privacy and Google user data policy

Effective version: 2 October 2026 · Service: Scoreapps AI Agent (AgentStudio)

The Gmail connector is undergoing verification and is not yet generally available. This policy also applies to authorized review and test accounts.

1. Who we are and scope

SCORE CAPITAL SL, Calle Ana Mariscal 5, 28223 Pozuelo de Alarcón, Madrid, Spain, operates Scoreapps. Contact: info@scoreapps.com. This policy supplements our general privacy policy and takes precedence for Google and Gmail data. General website marketing or analytics purposes do not apply to your Gmail data.

You choose whether to connect your Gmail account and which workflows to create. We process mailbox data to execute those instructions. When you process another person's information, you remain responsible for your authority to do so and for the recipients and actions you configure.

2. Data we access and why

We use these data only to provide the mailbox productivity features you request: searching and reading messages or attachments; drafting, sending and replying; adding or removing labels; and archiving. Connecting alone does not instruct us to read the entire mailbox or send messages.

We request openid, email and profile for identification, and https://www.googleapis.com/auth/gmail.modify for these combined read, send and organization functions. Read-only or send-only access cannot perform all of them. The connector does not offer permanent message deletion.

3. Workflows, AI and transfers

Workflows execute on Scoreapps servers, manually from your authenticated account or on a schedule you activate. A saved send or reply step can send mail automatically when the workflow runs. Use drafts if you want to review content before sending.

AI is optional. A Gmail-only workflow does not send message content to an AI provider. If you add an Ask Agent step, you must explicitly accept its data-transfer notice. The step sends the prompt and Gmail-derived information referenced by its configuration to the OpenAI API to generate the requested result. Its output may be used by subsequent Gmail steps and saved in the execution history. Do not include information that is unnecessary for the task.

For this initial Gmail release, OpenAI is the only supported AI provider. Web search, long-term agent memory and transfer steps to other connected services are disabled for Gmail workflows. We use a separately configured OpenAI connection with training-data sharing disabled and request store=false. OpenAI's standard API abuse-monitoring logs may retain content for up to 30 days, or longer where required for legal or safety reasons; this is not a promise of Zero Data Retention. See OpenAI API data controls.

Our infrastructure provider Hetzner hosts the service. Google processes mailbox operations; OpenAI processes explicitly enabled AI steps; recipients selected in send/reply steps receive the resulting emails. These are the service providers and recipients involved, not advertising partners. OpenAI processing can involve international transfers; we do not promise that all processing occurs in the European Union.

4. Limited Use and prohibited purposes

Scoreapps AI Agent's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data, use it for advertising, build advertising profiles, or use it to train or improve generalized AI or machine-learning models. We do not allow providers to train generalized models using Gmail data sent through this integration. AI processing is only for the specific user-requested productivity feature.

Our personnel do not routinely read mailbox content. Human access is limited to your affirmative agreement for specific support, necessary security investigations, legal obligations, or internal operations using aggregated and anonymized data as permitted by Google's policy. Access is restricted to the personnel who need it.

5. Storage, protection and retention

DataRetention and controls
OAuth tokensEncrypted at rest while connected. A successful disconnect revokes authorization and removes the local connector. If Google cannot confirm revocation, local use is disabled and encrypted tokens are retained only to allow a revocation retry.
Gmail execution inputs, results and AI outputEncrypted at rest. Available for up to 30 days from execution, unless erased sooner through Gmail data controls. Expired payloads are hidden immediately and an hourly task removes them from the active database. Operational run status and timestamps may remain without the message payload.
Saved workflowsConfiguration, prompts, search queries, recipient addresses and text you enter remain until you edit or delete the workflow or request account deletion. Do not paste confidential message content into workflow names or static configuration unless necessary. Deleting a workflow also clears its stored Gmail execution payloads.
Recovery copiesEncrypted payloads may remain in restricted recovery backups until those backups are replaced or removed. They are not used for ordinary product access. Restored payloads retain their original 30-day expiry; a restore must reapply outstanding deletion requests before returning data to use. Erasing active history does not instantly rewrite older backups.

Connections use HTTPS. Credentials and Gmail execution payloads are encrypted at rest; access to account controls and workflow history is checked against the account owner. We avoid logging message contents and do not display provider error bodies in Gmail run histories. No security measure guarantees absolute protection.

6. Your choices, disconnection and deletion

  1. Pause a workflow to stop future scheduled actions.
  2. Use Connectors → Gmail → Disconnect to stop local access and request Google token revocation. You can also remove Scoreapps AI Agent in Google Account → Third-party connections.
  3. Use Gmail data controls in AgentStudio to erase completed Gmail execution payloads. Running executions are not erased mid-run; stop or disconnect first, then erase when they finish. Disconnecting does not by itself erase previous history.
  4. Delete or edit saved workflows to remove their static configuration. For remaining account data, backup-related requests or assistance, contact info@scoreapps.com. We may verify account ownership before acting.

Deleting Scoreapps history does not delete messages, drafts or labels in Gmail, nor recall emails already sent. Manage those in Gmail. You may request access, correction, export, restriction, objection or deletion as applicable, withdraw consent, and complain to the Spanish Data Protection Agency.

7. Changes and contact

We will update this page when practices change. New purposes or additional transfers require an updated disclosure and consent where necessary before using your Google data that way. Questions or requests: info@scoreapps.com.

Política de datos de Gmail — Español

Responsable: SCORE CAPITAL SL, Calle Ana Mariscal 5, 28223 Pozuelo de Alarcón, Madrid. Contacto: info@scoreapps.com. Esta política específica prevalece para los datos de Google/Gmail sobre los fines generales de marketing de la web. El conector está en revisión y aún no está abierto al público.

Acceso y finalidad

La conexión es opcional y se autoriza en Google, sin entregar tu contraseña a Scoreapps. Guardamos la identificación de la cuenta, los tokens y tu aceptación del aviso. Tus pasos pueden consultar identificadores, remitentes, destinatarios, asunto, fechas, etiquetas, contenido y adjuntos; crear borradores, enviar o responder y organizar o archivar mensajes. El selector puede consultar metadatos. No ofrecemos borrado definitivo. Solicitamos identificación básica y gmail.modify, necesario para combinar lectura, envío y organización.

Automatización e IA

Los workflows se ejecutan en nuestros servidores por ejecución manual autenticada o programación activada por ti. Un paso de envío puede enviar automáticamente: usa borradores si quieres revisarlos. Un workflow solo de Gmail no transfiere correos a IA. Si añades Ask Agent, debes aceptar expresamente la transferencia de los datos referenciados en el paso a OpenAI API para generar el resultado solicitado. En esta primera versión, Gmail admite únicamente OpenAI, sin búsqueda web, memoria persistente ni pasos de transferencia a otros conectores.

Usamos una conexión específica con compartir datos para entrenamiento desactivado y store=false. Los registros de prevención de abusos de OpenAI pueden conservar contenido hasta 30 días, o más por motivos legales o de seguridad; no prometemos retención cero. Hetzner aloja el servicio; Google ejecuta las operaciones de correo y los destinatarios configurados reciben los mensajes enviados. OpenAI puede tratar datos fuera de la UE.

Uso limitado

El uso y la transferencia por Scoreapps AI Agent de información recibida de las API de Google se ajustarán a la política de datos de usuario de Google API Services, incluidos los requisitos de Uso Limitado. No vendemos estos datos, no los usamos para publicidad ni perfiles publicitarios y no los usamos ni permitimos usarlos para entrenar o mejorar modelos de IA de propósito general. El personal no lee habitualmente correos: el acceso humano se limita al soporte específico autorizado, seguridad, obligaciones legales o datos agregados y anonimizados en los supuestos permitidos por Google.

Conservación y protección

Los tokens y los datos de ejecución de Gmail se cifran en reposo. Los resultados, entradas y respuestas de IA se conservan accesibles un máximo de 30 días desde la ejecución; al caducar se ocultan y una tarea horaria los elimina de la base activa. Puedes borrarlos antes. Se pueden conservar estado y fechas sin el contenido. La configuración estática —prompts, consultas, destinatarios y texto introducido— permanece hasta editar o eliminar el workflow o solicitar la baja. No pegues contenido confidencial innecesario en nombres o configuración.

Pueden quedar copias cifradas en backups restringidos hasta su sustitución o eliminación. No son de uso ordinario. Al restaurar se conserva la caducidad original y deben reaplicarse las solicitudes de borrado antes de devolver datos al servicio. Borrar el historial activo no reescribe inmediatamente backups anteriores. Las conexiones usan HTTPS y los controles de acceso comprueban al propietario de la cuenta.

Control y borrado

Pausa los workflows para detener la programación. Desconectar desactiva el acceso local y solicita revocar el permiso en Google; si falla, el conector queda inactivo y retiene los tokens cifrados únicamente para reintentar la revocación. También puedes revocar desde las conexiones de tu cuenta Google. Desconectar no borra automáticamente historiales. En Gmail data controls puedes eliminar los datos de ejecuciones terminadas; espera a que concluyan las que estén en curso. Eliminar el workflow borra también sus datos de ejecución de Gmail.

Esto no elimina mensajes o borradores de tu buzón ni retira correos enviados. Puedes solicitar acceso, rectificación, exportación, limitación, oposición, supresión y retirada del consentimiento cuando corresponda, o reclamar ante la AEPD. Contacta con info@scoreapps.com para datos restantes, copias o asistencia; podremos verificar tu identidad. Actualizaremos el aviso y recabaremos el consentimiento necesario antes de nuevos usos o transferencias.