Google API Services User Data Policy & Limited Use Disclosure
ConnectWhole's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models. Google data is strictly used to provide personalized email sending and outreach management explicitly requested by you.
1. Introduction
ConnectWhole ("we," "our," or "us") operates the ConnectWhole platform, available at https://connectwhole-frontend-1070428613852.asia-south1.run.app and associated subdomains. This Privacy Policy details the types of information we collect, how we handle and protect it, and the choices available to you regarding your data.
2. Information We Collect
We collect information to provide, personalize, and improve our outreach automation platform:
Account Information
Your name, email address, password hash (encrypted via bcrypt), and profile preferences provided during registration.
Resumes & Documents
Resumes, cover letters, and documents uploaded by you for email attachments. Stored privately and securely in isolated Google Cloud Storage buckets.
Google Account Data
When you connect a Gmail account via Google OAuth 2.0, we obtain OAuth tokens and your authorized email address. We never see or store your Google account password.
Outreach & Interaction Data
Recipient email addresses, email subjects, sending timestamps, email open signals, and reply status necessary to power analytics.
3. How We Use Google User Data
ConnectWhole requests specific Google OAuth scopes strictly to fulfill user-initiated actions:
- `https://www.googleapis.com/auth/gmail.send`: Used exclusively to send emails on your behalf from your connected Gmail address when you click "Send" in ConnectWhole.
- `https://www.googleapis.com/auth/gmail.readonly` or user profile scopes: Used to display your sender address and monitor replies to your outreach campaigns.
Our Guarantees Regarding Google Data:
4. AI Email Generation (Google Gemini)
When you use our AI writing assistant, your prompt and context (such as recipient role or company name) are sent to the Google Gemini API to generate the email draft. We do not use your proprietary emails to train foundational AI models.
5. Data Security & Storage
We employ enterprise-grade security protocols hosted on Google Cloud Platform:
- Encryption in Transit: All web traffic is strictly encrypted using HTTPS / TLS 1.3.
- Encryption at Rest: Database records and files in Cloud Storage are encrypted using Google-managed encryption keys.
- OAuth Token Security: Sensitive Google OAuth refresh tokens are encrypted in the database using Fernet / AES symmetric encryption.
- Multi-Tenant Isolation: Data access is strictly segmented by authenticated user IDs.
6. Revoking Access & Data Deletion
You maintain full control of your connected accounts and stored data:
- Disconnect Gmail in ConnectWhole: Navigate to Email Accounts in your dashboard and click Disconnect to instantly purge all stored OAuth tokens.
- Revoke via Google Account: You can independently revoke ConnectWhole's permissions at any time via Google Account Permissions.
- Complete Account Deletion: You may request complete erasure of your account, contact history, and uploaded resumes by contacting our privacy team.
7. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our compliance with Google API policies, please reach out to us:
ConnectWhole Privacy & Compliance
Email: support@connectwhole.com
Application: https://connectwhole-frontend-1070428613852.asia-south1.run.app