OWNER CONNECTIONS
Privacy policy
Effective description: 28 September 2026. This policy covers Dr Gummy Owner Connections, the internal account-connection and report-delivery application operated for Dr Gummy's authorized owner.
Information and permissions
Google sign-in is used to check the selected account's verified email and stable account identity. The report connection requests openid, email identity and gmail.send. It uses them to send owner-authorized reports from manager@dr-gummy.com to the configured owner recipient, currently drgummy6@gmail.com.
The separate mailbox connection requests openid, email identity and gmail.readonly. Its access checks read the Gmail profile and a bounded listing of message identifiers. At the signed-in owner's request, the mailbox preview retrieves at most five recent messages' sender, subject and date headers plus a short snippet of up to 240 characters. It displays them only in that owner's authenticated console. The feature does not fetch full message bodies or attachments and does not persist message content. These checks do not return message bodies in connection evidence. The mailbox grant does not send, edit or delete messages.
How information is used
Google identity data binds a connection to the authorized Dr Gummy account. Gmail data supports the owner's enabled report-delivery and mailbox-access features. Permission status, task bindings, timestamps, hashes and delivery receipts support security, troubleshooting and audit. Google consent alone is not recorded as successful email delivery.
Gmail user data is not sold, used for personalized advertising, transferred to advertising platforms, or used to train generalized AI or machine-learning models. Mailbox data is not an input to the hosted code-generation lane.
Storage, access and sharing
OAuth refresh credentials are stored in dedicated Google Cloud Secret Manager resources using encryption at rest and protected transport. The report and mailbox grants use separate resources. The authorized Dr Gummy cloud runtime has narrowly scoped access and uses an explicit credential version after readback verification. Credentials are not placed in the owner page, operational task records or diagnostic logs.
Google processes authentication and Gmail API requests; Google Cloud hosts the authorized application and protected storage. Reports are shared with the configured owner recipient as part of the enabled delivery feature. Connection evidence contains fixed account details, scopes, status, timestamps and credential references; it does not retain access tokens, authorization codes, mailbox message identifiers or message bodies. The report-delivery ledger retains provider message receipts to prevent duplicate sending.
Retention and removal
The owner controls whether a connection remains enabled. Operational audit records and report receipts are retained for traceability. This deployment does not promise an automatic 30-day deletion schedule. Revoking Google access stops the grant's future authorized use but does not automatically erase previously retained application records or reports already delivered.
You can review or revoke the application's Google access on your Google Account connections page. Contact manager@dr-gummy.com to request removal of application-held credentials or data, or to ask which retained audit records apply to your request. Data removal is handled by the operator; the current console does not claim an automatic deletion workflow.
Google Limited Use
Dr Gummy will comply with the Google API Services User Data Policy, including its Limited Use requirements. Google data is restricted to the disclosed user-facing features and necessary security operations. Additional uses or permissions require an updated disclosure and the appropriate user consent.
Policy updates and contact
Material changes to the data accessed, its purpose or sharing will be disclosed before the changed feature is used. Questions and requests: manager@dr-gummy.com. Publishing this policy does not indicate that Google has approved or verified the application.