Privacy Policy for Scott’s Inbox Assistant
Effective date: 2 September 2026
Scott’s Inbox Assistant is a private application operated and used solely by Scott Peters. This policy explains how the application accesses, uses, stores and shares information obtained from authorised Google accounts.
Information accessed
When authorised, the application may access:
The authorised account’s email address.
Email messages, threads, subjects, bodies, senders, recipients and timestamps.
Gmail labels and message status.
Draft messages.
Attachment names and related metadata.
The application does not request or store Google account passwords.
How information is used
Google account data is accessed only when Scott Peters instructs the application to perform a task. Those tasks may include:
Searching and reading email.
Analysing or summarising correspondence.
Comparing conversations across authorised accounts.
Creating email drafts.
Organising messages and labels.
Sending a specifically approved draft.
Google account data is not used for advertising, profiling, marketing or sale.
Processing by Codex and OpenAI
When Scott requests email analysis or another email-related task, the information necessary to complete that task is provided to OpenAI’s Codex service for processing.
Email content or excerpts may therefore appear in Scott’s Codex conversation history and may be retained according to his OpenAI account settings, data controls and OpenAI’s applicable policies.
OpenAI’s Privacy Policy is available at:
https://openai.com/policies/privacy-policy/
Storage and security
Google OAuth client credentials and refresh tokens are stored locally in macOS Keychain. Temporary access tokens are held in memory while required.
Scott’s Inbox Assistant does not maintain a separate server, email archive or database of Gmail message content.
Sending an email requires an explicit request followed by a separate confirmation on Scott’s Mac showing the sending account, recipients and subject.
Information sharing
Information is shared only with:
Google, as required for authentication and operation of the Gmail API.
OpenAI’s Codex service, when necessary to perform a task requested by Scott.
Information is not sold, rented or shared with advertisers.
Data retention and deletion
The local application does not independently retain copies of email messages after a task is completed. Information included in Codex conversations is governed by Scott’s OpenAI account settings.
Google access can be revoked at any time through:
https://myaccount.google.com/permissions
Scott may also remove the application’s credentials from macOS Keychain and uninstall the local Codex plugin.
Google API Services User Data Policy
The use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
https://developers.google.com/terms/api-services-user-data-policy
Changes to this policy
This policy may be updated if the application’s functionality or data practices change. The effective date above will be updated whenever material changes are made.
Contact
Questions about this privacy policy or the application’s use of Google data can be sent to:
Scott Peters
scott@madebyscottpeters.com