BEN Z PERSONAL MAIL
Privacy Policy
Effective: August 30, 2026
Scope and purpose
Ben Z Personal Mail is a private, single-user Gmail triage assistant. It accesses Google user data only to identify messages that may need the account owner’s attention and to deliver a concise summary to that owner. The service is not offered to the public.
Google user data accessed
The app uses the Gmail read-only permission and may access:
- message and thread identifiers;
- sender address or domain, subject, received time, labels, and read state; and
- a short, sanitized excerpt from selected messages when needed to classify urgency or actionability.
The app does not request permission to send, delete, archive, label, modify, or mark email as read.
How data is used
Google user data is used only to:
- find new non-promotional Inbox messages since the last successful scan;
- classify messages as urgent, actionable, digest-worthy, or ignorable;
- redact and format a short owner-facing summary; and
- prevent duplicate summaries and support delivery acknowledgements.
Google user data is not used for advertising, creditworthiness, surveillance, sale, or any purpose unrelated to personal email triage.
Processing and sharing
Bounded and sanitized message metadata or excerpts may be processed by OpenAI through the owner’s private OpenClaw environment solely to generate classifications. A redacted summary is delivered to the account owner through Telegram. Infrastructure providers may process data only as needed to operate these services and subject to their applicable service terms.
Google user data is not sold, rented, shared for advertising, or transferred to data brokers. It is not disclosed to other people except when required by law or necessary to protect the security of the owner or service.
Storage and retention
- OAuth credentials are stored in a restricted private credential store until revoked or replaced.
- Operational state may retain message or thread identifiers, classifications, delivery status, and acknowledgement status to avoid duplicate alerts.
- Raw email bodies are not copied into the triage ledger.
- Temporary local prompt files are access-restricted and deleted after each classification run.
- Bounded operational session records may be retained for reliability and security troubleshooting and are removed when no longer needed for those purposes.
Security
The service applies least-privilege OAuth access, read-only runtime enforcement, restricted local file permissions, bounded scans, sanitized excerpts, redacted summaries, and fail-closed processing. No system can be guaranteed completely secure, but access and retained data are deliberately minimized.
Access, revocation, and deletion
The owner can revoke Google access at any time from Google Account connections. Revocation stops future Gmail access. To request deletion of stored operational data or ask a privacy question, email benjaphon.mail@gmail.com.
Google API Services User Data Policy
Ben Z Personal Mail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes to this policy
This policy will be updated before Google user data is used for a materially different purpose. The effective date above identifies the current version.