Cangtian Mail Assistant
Effective 4 October 2026

Privacy Policy

This policy explains what Google user data Cangtian Mail Assistant accesses, why it needs that access, how the data is handled, and how you can withdraw access at any time.

1. Summary

Cangtian Mail Assistant ("the app") is a private, single-user tool that sorts Gmail messages by applying labels to them. It runs locally on one computer, for one Gmail account, belonging to the person who operates the app.

  • There is no server. The app has no backend, no database, and no cloud infrastructure.
  • Message content is processed in memory during a run and is not stored.
  • Google user data is never sold, shared, or disclosed to any third party.
  • Google user data is never used for advertising or to train machine-learning models.
  • Access can be revoked at any time, with immediate effect.

Google API Limited Use statement. App's use of information received from Gmail APIs will adhere to Google's Limited Use Requirements.

2. Who is responsible for your data

The app is developed, owned, and operated by a single individual (the "operator"), who is also the sole user of the app and the sole owner of the Gmail account it acts upon. The operator is the data controller for the purposes of this policy.

Because the app serves exactly one account — that of the operator — there are no other users, no user accounts, and no sign-up process.

3. Scope of this policy

This policy covers the processing of Google user data by the app when it connects to the Gmail API through Google OAuth 2.0. It does not cover any other website, product, or service.

The app is intended for personal, non-commercial use by its operator and is not offered to the public.

4. Google user data the app accesses

The app accesses only what is necessary to sort messages into labels. The categories of data and the reasons for each are set out below.

DataRead or writePurpose
Message metadata and a short text snippet from inbox messages received in the last seven days (sender, subject, timestamp, snippet) Read To decide which of the four categories a message belongs to
Label names and label identifiers Read To locate the four labels and confirm they exist before use
Message labels Write (add only) To apply the selected category label to a message thread
The Gmail address of the account being organised Read To confirm which account is authorised

The app does not access the body of messages beyond a short snippet used for classification, and it does not access attachments. It does not read any mailbox other than the inbox of the single authorised account.

The app does not send, reply to, forward, delete, or archive email. It does not remove labels, and it does not create, modify, or delete Gmail filters or account settings.

5. Google API scopes requested

The app requests the following Google OAuth scopes. The first two are sign-in identifiers used solely to identify the authorised account; the remaining three form the standard Gmail access set used by the client library.

ScopeWhat it permitsUsed by this app
openid
userinfo.email
Confirm the identity and email address of the signed-in Google Account Yes — to identify the single authorised account
gmail.modify Read message metadata and manage labels on messages. Does not permit permanent deletion of messages or threads. Yes — this is the app's core function
gmail.settings.basic See, edit, create, or change Gmail settings and filters No — included in the library's standard Gmail access set and never exercised
gmail.settings.sharing Manage delegated access and sharing settings for Gmail No — included in the library's standard Gmail access set and never exercised

The app never reads or modifies your Gmail settings, filters, or sharing configuration. It does not create, alter, or delete filters, auto-forwarding rules, or delegated-access settings, and it requests no Drive, Calendar, Contacts, Sheets, or Docs access.

The single capability the app exercises is the ability to read a short window of message metadata and to apply category labels. No other permission listed above results in any access to, or modification of, Google user data.

6. How the data is used

Data is used for one purpose only: to assign labels to messages so that the operator's inbox is organised by category. Specifically:

  1. The app queries the inbox for messages received in the last seven days.
  2. It evaluates each message against a fixed, deterministic rule set.
  3. It applies exactly one category label per message.
  4. It logs a short summary of the run (for example, how many messages were processed) to a text file on the operator's own computer.

The logged summary contains counts only. It does not contain message content, sender addresses, or subject lines.

7. Limited Use compliance

The app's use of Google user data is limited to the practices disclosed in this policy, in accordance with the Google API Services User Data Policy, including its Limited Use requirements. In particular:

  • Data is transferred to third parties only where necessary to provide or improve the app's single, user-facing feature — in practice, data is not transferred to any third party at all.
  • Data is not used for serving advertisements, and is not sold to third parties.
  • Data is not used to determine creditworthiness or for lending purposes.
  • No human reads Google user data, except as described in section 9.

8. Storage and retention

Message data

Message metadata and snippets are held in memory only, for the duration of a run. They are discarded when the run ends. No copy of message content is written to disk.

OAuth credentials

To avoid repeated sign-in prompts, the app stores Google OAuth credentials — an access token and a refresh token — locally on the operator's own computer, in the application's configuration directory. These credentials are protected by the operating system's user account controls on that computer. They are not stored on any server, because the app has no server.

Retention periods

  • Message metadata and snippets: not retained (in-memory only).
  • Run summaries (counts only): retained on the operator's computer until manually deleted.
  • OAuth credentials: retained until access is revoked, at which point the app deletes them.

Deletion

Revoking the app's access from the Google Account permissions page invalidates the stored credentials immediately, rendering them unusable. To request deletion of any remaining local files, contact the operator using the address in section 15.

9. Sharing and disclosure

Google user data is not sold, rented, traded, or otherwise transferred to any third party. No data is disclosed to advertisers, data brokers, analytics providers, or machine-learning training pipelines.

No data is disclosed to any third party except where required by law, and only to the extent legally required. Because the app has no server, no third-party infrastructure provider receives Google user data at any point.

10. Human access to Google user data

The app is operated by one person, who is also the owner of the account it processes. No other person has access to the data. No employee, contractor, or third party reviews Google user data, and no data is made available to anyone for any purpose.

11. Your rights and revocation

Revoking access

You may revoke the app's access to your Google Account at any time, with immediate effect, at myaccount.google.com/permissions. Once access is revoked, the app can no longer read or modify anything, and the stored credentials stop working.

Access, correction and deletion

Because the app retains no message content, there is no stored personal data to access or correct. To request deletion of the limited local files described in section 8, or to ask any question about how Google user data is handled, write to the address in section 15.

Removing labels

Labels applied by the app can be removed by the user at any time directly within Gmail. The app does not prevent or reverse manual changes.

12. Security

  • All communication with Google APIs takes place over HTTPS.
  • OAuth credentials are held in the operating system's user-protected application data directory and are never committed to source control or shared.
  • The app requests the narrowest scope that supports its single feature, and holds no server-side copy of any data.
  • Access tokens are short-lived and are refreshed automatically by the standard Google OAuth mechanism.

No system can be guaranteed to be perfectly secure. However, because the app stores no message content and transmits nothing to any third party, the exposure surface is limited to the credentials held locally on one computer.

13. Children's privacy

The app is not directed to children and is not available to the public. It is used solely by its adult operator for their own mailbox. No data relating to children is knowingly collected or processed.

14. International transfers

The app runs on a single computer in the operator's country of residence. Google user data is transmitted to Google's API endpoints in the course of normal operation, subject to Google's own privacy terms. No Google user data is transferred to any other country or jurisdiction by the app itself, because no other party ever receives it.

15. Changes to this policy

This policy may be updated if the app's behaviour or the applicable rules change. Any update will be published on this page with a revised effective date. Material changes will also be reflected in the app's OAuth consent screen configuration where required.

This policy was last updated on 4 October 2026.

16. Contact

Questions, requests, or complaints about this policy or about the handling of Google user data should be sent to:

cangtian606@gmail.com

This is the same address registered as the support contact on the app's OAuth consent screen.