If you choose to connect a Gmail or Google Workspace mailbox, Zenloth requests read-only Gmail access and basic Google account identity information only for the email import feature.
Data accessed: Google account email address, provider account identifier, OAuth access and refresh tokens, Gmail message identifiers, sender, subject, received date, and the body/content of bank notification emails that match our supported sender rules.
Data created from Gmail: parsed transaction details such as amount, currency, transaction date, merchant/payee, reference number, source message identifier, import status, and related transaction records.
Data use: we use this data to verify your mailbox, read bank notification emails, import and categorize transactions, prevent duplicate imports, show sync status, reconnect your mailbox, troubleshoot the email import feature, and protect the service.
Data we do not change: Zenloth does not send, modify, archive, delete, label, or permanently delete messages in your Gmail account.
Data protection: OAuth tokens and provider credentials are stored encrypted at rest, and Google data is transmitted using secure protocols.
Data sharing: we do not sell, rent, or transfer Google user data to advertising platforms, data brokers, information resellers, or parties that use it for credit-worthiness, lending, retargeting, personalized advertising, or interest-based advertising.
Service providers: Google user data may be processed by infrastructure and service providers only as needed to operate, secure, maintain, or improve the user-facing Zenloth features described in this policy, subject to confidentiality and security obligations.
AI/ML restrictions: Zenloth does not use raw or derived Google Workspace API data to develop, improve, or train generalized or non-personalized AI/ML models. We do not transfer raw or derived Gmail data to third-party AI/ML services for those services to train their models.
Limited Use statement: Zenloth's use and transfer of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Retention and deletion: Zenloth processes matching message bodies transiently and stores only a content-free source marker for deduplication after parsing; raw Gmail bodies are not retained in the ingestion record. Disconnecting a mailbox requests revocation of the Google OAuth grant, removes the stored connection credentials, stops future Gmail access, and deletes source identifiers, per-message metadata, and intermediate import candidates from Zenloth. If you choose to keep imported transactions, the resulting transaction records remain available for your budgets and reports; you can instead choose to delete those transactions during mailbox deletion.
Account deletion: deleting your account purges user-owned profile, financial, Gmail-derived, mailbox-credential, and AI conversation records. Privacy-minimized product-health telemetry, aggregate statistics, limited records required for security, billing, or legal obligations, and a non-identifying deletion record may remain. Solely to prevent repeated one-time trial abuse, Zenloth also retains a non-reversible, environment-specific cryptographic marker derived from the normalized email address. The marker contains neither the email address nor a user, Google, or provider account identifier and is deleted no later than 24 months after account deletion.