Marcus Mail Tidy privacy policy

Last updated: 24 September 2026.

This policy describes the current personal Gmail workflow under the Designed4Human name. Contact: research@designed4human.com. It applies to this application's handling of Google account and Gmail data.

Information accessed and purpose

Google account identity is used to verify that each connection belongs to the intended account. With the owner's consent, the tool can read Gmail messages and labels. Routine assessments use message identifiers, sender addresses, subjects, dates, label/read status and account or Inbox counts. Message content may be read when the owner requests it or when needed for an authorised review. Attachment download is disabled in the current workflow.

This information is used to organise the owner's email, produce review summaries and propose rules. The current Gmail connection does not send or modify email. It does not use Google user data for advertising, sale or credit decisions.

Processing and sharing

The Gmail connector runs locally and communicates with Google to authenticate and read authorised information. Selected message metadata, summaries and, when needed for an authorised review, message content may be provided to OpenAI's Codex service for AI-assisted analysis. The application therefore must not be described as processing all email data exclusively offline. The AI service's handling of submitted data is governed by the owner's service terms and settings. Model-improvement training is turned off for the OpenAI account used for this workflow.

Selected documentation and review reports may be copied to the owner's Obsidian folder in OneDrive. Depending on report content, these copies may include sender addresses or subject examples. Raw mailbox ledgers and OAuth credentials are not intentionally included in those documentation mirrors. Google, OpenAI and Microsoft services involved in this workflow process data under their applicable terms and settings.

Marcus Mail Tidy's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not to be used through this application to train general-purpose AI models. Access is limited to providing and maintaining the owner's requested email-management features.

Storage, retention and security

OAuth authorisation records are stored in encrypted local connector storage, separately for each connected Gmail account. Google passwords are not stored by Mail Tidy. Local assessment records and rules are stored in the project workspace; selected documentation may also be stored in OneDrive as described above. These data records are not claimed to share the token store's encryption protection.

No automatic deletion schedule is currently configured for local reports or assessment records. They remain until the owner removes them. The owner should protect the computer, backups and cloud account access and retain only records needed for the workflow.

Choices, revocation and deletion

The owner can stop the local connectors and revoke the app's access in Google Account third-party connections. Revoking access stops future authorised reads but does not itself delete existing local reports, cached files or OneDrive copies. To remove those records, the owner must delete the relevant local and mirrored files and manage any backups or provider retention separately. Questions and deletion requests can be directed to the contact above.

Changes

Update these disclosures before adding users, new service providers, broader data access, automatic processing or Gmail write features. Show the current policy link from the homepage and OAuth consent configuration.