WORKSUITE
Privacy policy
Last updated: September 16, 2026
Google account and Gmail data we access
With your authorization, WorkSuite uses https://www.googleapis.com/auth/gmail.readonly to access your Gmail email address and mailbox profile, message and thread identifiers, email subjects, sender and recipient addresses (From, To and Cc), message dates, labels, message snippets, and message bodies including plain-text and HTML content. Gmail API responses can include mailbox message/thread counts and history identifiers. Reading a message also receives its MIME structure and attachment metadata such as filename, content type and size; the current Gmail Chat tools do not download attachment files. We retrieve this data from your authorized account to identify the connected mailbox, search for relevant messages, read conversations and answer your requests.
Permissions, optional collection and AI processing
Gmail Chat search and reading use the gmail.readonly scope. The separately configured Gmail collection feature also requests openid, email and profile; Google may return your account identifier, email address and basic profile information, and the current integration uses the email address to identify the connected account. When you enable this collection, selected messages matching your settings can be imported as local documents and processed by your configured Hindsight service. In Chat, retrieved email headers, body excerpts and related metadata may be sent to your selected AI provider to produce summaries, answers or suggested tasks. Connecting Gmail alone does not enable this separate collection. These Gmail features do not send, modify or delete emails and do not request Google Drive, Calendar or Contacts data.
About this policy
This policy explains the WorkSuite website at clavisay.com and the desktop application. For privacy questions, contact the WorkSuite developer at fatyansong@gmail.com.
Website visits
This site has no sign-in form, advertising tags or application analytics scripts. Cloudflare hosts the site and may process request information such as IP address, browser information and access logs to deliver and protect it. Contacting us by email shares your email address and message with the recipient and email providers.
Accounts and information you choose
The desktop app can process account identifiers, profile information and permitted work content from services you connect. Gmail access includes message and thread content needed for read-only search and reading. Zoom access supports meeting information and cloud recording listings. Lark and local-source access depend on your configuration and permissions.
How Google data is used
Gmail data is used to provide user-facing productivity features, including finding and reading messages and, in the separately configured Intelligence v2 integration, selected email ingestion and context. WorkSuite does not send, modify or delete Gmail messages through its current Gmail integrations. WorkSuite’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Local storage and AI services
The desktop direct integrations store authorization credentials in encrypted local storage. Work content, indexes, conversations and derived records may also be retained locally. Local storage does not mean all processing stays on your device: evidence used in Chat can be sent to the model provider you configure. Intelligence v2 may send selected source content to your configured Hindsight service and its model provider. These processing paths depend on enabled features and source permissions; review those services’ applicable terms and policies before connecting sensitive information.
Sharing and purpose limitations
This website does not receive your Gmail or Zoom access tokens. WorkSuite uses connected data to deliver the features described here, not to sell Google user data or target advertising. Google API data must not be used to train generalized AI models. The compatibility and data-handling settings of user-configured model and memory services must be assessed before use; this site does not promise that every third-party service has identical retention or processing terms.
Retention, disconnection and deletion
Local records can remain until you remove the relevant source or saved data using available application controls or remove the application’s data directory. Disconnecting an integration must not be assumed to delete existing conversations, caches or remote derived memory. You can separately revoke Google access in your Google Account and Zoom access in Zoom’s app management. Data already sent to model or Hindsight services may require separate deletion with that service. Contact us for help identifying the appropriate removal steps.
Your choices and changes
Connect only accounts and sources you are entitled to use. Source permission controls determine eligible retrieval and analysis; browser consent controls provider access. You may contact the developer about access, correction or deletion assistance. We update this page when our published data practices change; its date identifies the current notice.
Google API Services User Data Policy ↗ · Cloudflare Privacy Policy ↗