Privacy Policy

Operator and purpose

Prospect Gmail Metadata is operated by John Lelis for his private CRM workflow. The only authorized mailbox is john.lelis@evocon.com. The integration is not offered for public registration.

Google access and data used

Access requires the mailbox owner's Google authorization. The only Gmail permission requested is gmail.metadata (https://www.googleapis.com/auth/gmail.metadata).

The integration reads the authorized mailbox identity, routing and reply-related headers, sender and recipient addresses, message and thread identifiers, operational labels, and timestamps needed to match identities, record email activity, and distinguish reply evidence from recognized automated messages. Email subjects, bodies, snippets and attachment contents are not requested or stored by the integration. The integration does not access or store the mailbox password.

The integration cannot send email or modify, move or delete Gmail messages with this permission. It does not import the full historical mailbox. Normal processing uses a saved position to handle newly observed mail. A separately requested, bounded metadata lookup may check earlier correspondence for an eligible Contact without importing message content or historical activity into the CRM.

Private CRM use and service providers

Necessary contact identity and activity facts are synchronized with John's private Attio CRM workflow. Personally sent outbound email can establish intent to create or link a corporate Contact or Company, subject to deterministic identity and conflict checks. Apollo may receive an exact contact email or company identifier to resolve factual identity and employer information, and may receive the resulting CRM representation through the separately controlled synchronization workflow. Email bodies and attachments are not transferred to these services.

The processing service runs privately on Railway. OAuth credentials are stored in private Railway configuration; authorized administration also uses private local setup files. Credentials and operational data are never included in these public pages.

Google user data is not sold, used for advertising or transferred to data brokers. It is used to provide and maintain this private integration. Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Retention and control

Processing evidence supports reconciliation and idempotency: repeating an event must not create duplicate activity or records. The integration retains the message identifiers, contact identity, timestamps, processing evidence and synchronization state needed for reliable operation and duplicate prevention. Related CRM records and operational records remain stored until deliberately removed through administration; no automatic deletion schedule is currently implemented.

John can revoke authorization through his Google Account's third-party connections settings. Revocation prevents future Gmail access but does not automatically erase previously created CRM records or synchronization records. Questions or requests concerning stored integration data can be sent to john@lelis.gr.

Public website

These three information pages contain no login, forms, advertising or analytics scripts and expose no mailbox or CRM data. Cloudflare provides static hosting and network delivery and may process ordinary web-request information, such as IP addresses, for delivery and security. Visiting these pages does not authorize Gmail access.

Changes and contact

This policy will be updated if the integration's data practices change. New Gmail permissions or additional mailboxes require separate authorization.

Contact: John Lelis — john@lelis.gr

Home · Terms of Service