1. Controller and scope
SoloKeeper acts as the controller for the personal data processed through the app in connection with account access, scheduling, client operations, inbox review, analytics, support, and public beta feedback.
This policy applies to data provided directly by users, data created while using the app, and Google account, Gmail, or Google Docs data processed after the user chooses to connect Google services.
2. Data we process
- Account data, such as name, email address, Google account identifier, and profile details returned during sign-in.
- Workspace data, such as calendar events, session details, client records, payment tracking, settings, and analytics inputs created inside SoloKeeper.
- Connected Gmail data, such as message metadata, message content, and attachment metadata, which is loaded directly from Gmail, displayed in the user's browser tab, and not sent to or stored by SoloKeeper's server.
- Connected Google Docs data, such as document metadata and document content from the specific templates a user chooses to sync.
- Technical and security data, such as IP-derived logs, request metadata, browser information, crash reports, and operational diagnostics.
- Support and feedback data submitted through forms, product feedback, or direct support communication.
3. Purposes and legal bases
- To provide the app and maintain your account, we process data as necessary for performing our service agreement or pre-contractual steps.
- To connect Google services, we process Google account, Gmail, and Google Docs data on the basis of your authorization and the app functionality you request.
- To protect the service, investigate incidents, prevent abuse, and improve reliability, we process data on the basis of legitimate interests in operating a secure product.
- To respond to support requests, public beta feedback, and legal obligations, we process data as necessary to communicate with users and comply with applicable law.
4. Google user data
When you sign in with Google, SoloKeeper receives basic account data needed to identify your account. When you explicitly connect Gmail, SoloKeeper requests Gmail access so the browser can read relevant client messages inside the inbox workflow, manage the SoloKeeper "Need reply" Gmail label, and move messages to or from the Gmail trash. The Gmail access token and message data are not sent to or stored by SoloKeeper's server; they remain in memory in the active browser tab. Attachments are not downloaded by SoloKeeper. User-triggered session notifications open as prefilled drafts for review and sending in Gmail. When you explicitly connect Google Docs, SoloKeeper uses per-file Google Drive access to read a template you select through Google Picker, extract placeholders, create an invoice copy in your Drive, and replace placeholders in that copy. SoloKeeper does not modify the source template.
SoloKeeper does not use Google user data for advertising, does not sell Google user data, and does not train generalized models on your Gmail or Google Docs content. Google data is used only for the user-facing features described in the app and on the dedicated Google data use page.
SoloKeeper's use of raw or derived data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Sharing and processors
SoloKeeper may use third-party processors for hosting, infrastructure, logging, error monitoring, authentication, and Google API access. These processors may handle personal data only on documented instructions and for service-delivery purposes.
We do not sell personal data. We share personal data only when necessary to provide the service, respond to lawful requests, or protect the service and its users.
6. Retention
Account and workspace data are retained while your account remains active and for a limited period afterward when necessary for backups, incident investigation, dispute handling, fraud prevention, and legal compliance. Technical logs and support records may be retained for shorter operational windows depending on their purpose.
7. International transfers
SoloKeeper and its processors may process data in countries outside the EEA. Where required, we rely on appropriate safeguards such as contractual protections and processor obligations designed to support GDPR-compliant handling of personal data.
8. Your GDPR rights
If the GDPR applies to your use of SoloKeeper, you may have rights of access, rectification, erasure, restriction, portability, objection, and the right to withdraw a consent-based authorization. You may also have the right to lodge a complaint with your local supervisory authority.
To exercise these rights, contact privacy@solokeeper.app .
9. Security and updates
SoloKeeper uses technical and organizational measures intended to protect personal data. Because the product is in public beta, these controls continue to evolve, and a separate security readiness task will be completed before broad production publication.
We may update this policy as the product or legal obligations change. Material changes should be reflected on this page before they take effect in production.