Privacy Policy
This policy explains what data Trymo Mail-to-Drive ("the Service") accesses, why, and how it is handled. It applies to every Google Account that authorises the Service.
1. Who is responsible
Plaftik operates the Service and is the controller for the purposes of this policy. Contact: biro@plaftik.com
2. Google user data we access
Only after you explicitly grant permission through Google's OAuth consent screen, and only via Google's official APIs:
- Gmail — the content, headers, metadata and attachments of messages in the authorised mailbox, and the ability to apply labels to mark messages as processed.
- Google Drive — the ability to create folders and upload files in the authorised Drive account, and to read file and folder names in order to avoid duplicates.
We request the narrowest scopes that allow this to function. We do not request or use access to contacts, calendar, photos, location or any other Google service.
3. Why we access it
Solely to perform the automation you have asked for: identifying relevant incoming messages, extracting attachments and filing them in Drive. We do not use your data for any other purpose, and we do not use it to build profiles, train machine learning models, or generate advertising.
4. Limited Use disclosure
Trymo Mail-to-Drive's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; we do not sell it; and we do not allow humans to read it except with your explicit permission, where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.
5. Storage and retention
- Message content and attachments are processed in transit and are not stored beyond the duration of the automated run.
- Attachments are written to your own Google Drive account. We keep no copy.
- OAuth tokens are stored encrypted on our n8n instance for as long as authorisation remains active, and are deleted when access is revoked or the engagement ends.
- Technical execution logs (timestamps, message identifiers, success or failure) are retained for up to 30 days for troubleshooting, then deleted automatically.
6. Sharing
We do not sell, rent or share your Google user data. No third party receives it. Our infrastructure providers (hosting and DNS) may process data incidentally in transit but have no access to message content.
7. Security
All connections use TLS. OAuth credentials are held encrypted and are accessible only to Plaftik personnel administering the instance. Access to the n8n instance is restricted and authenticated.
8. Your rights and control
- Revoke access at any time at myaccount.google.com/permissions. The Service stops immediately and its tokens become invalid.
- Request confirmation of what is processed, correction, deletion, restriction, or a copy of your data, by writing to biro@plaftik.com.
- Where the GDPR applies you may lodge a complaint with your national supervisory authority.
9. Children
The Service is a business tool and is not directed at or intended for anyone under 16.
10. Changes
Material changes will be published on this page with an updated date, and notified to authorised account owners by email.
11. Contact
Plaftik · biro@plaftik.com