Conversation Workbench privacy policy
Effective: 10 September 2026.
Operator and purpose
Conversation Workbench is operated by James Wood for personal email archiving, search, and research. Questions about this application or its data practices can be sent to james@vrg.asia.
Google account access
The application uses Google OAuth to request the https://www.googleapis.com/auth/gmail.readonly permission for accounts explicitly authorized by the owner. It reads message identifiers, thread identifiers, headers (including sender, recipients, subject and dates), labels, bodies, original MIME messages and attachments, and mailbox synchronization information. It may include messages in Spam and Trash. It does not request permission to send, modify, or delete Gmail messages.
Use and storage
Email is downloaded to storage controlled by the operator. Original messages and attachments are retained as MIME files. Message metadata and extracted body text are stored in a local SQLite database and full-text index. Copies may be included in the operator's device backups. OAuth credentials are encrypted using Windows protection tied to the operator's Windows account. The archive itself is not encrypted by the application; its protection depends on the operator's device access controls and storage configuration.
AI clients and disclosure
The local MCP server exposes read-only search and message retrieval to clients the operator connects. When used with a cloud AI client, the selected queries and returned email content may be transmitted to and processed by that AI provider under the operator's account settings and the provider's terms. The public information website does not host the email archive or OAuth tokens. The application does not sell Google user data, use it for advertising, or contain a workflow for training a general-purpose AI model on the archive.
Retention, revocation and deletion
Archived messages are retained until the operator removes the local archive and any retained backup copies. Deleting a message in Gmail does not delete its archived copy. Revoking the application's access in Google Account third-party connection settings prevents future authorized imports but does not erase existing local copies. Contact the operator about deletion of retained data; backup deletion is managed separately from the live archive.
Google API data policy
Conversation Workbench's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
Website visitors
These information pages do not need Google sign-in or request mailbox access. The pages contain no application-added analytics, tracking scripts, or forms. The hosting provider may process ordinary connection information, such as IP addresses and request logs, to deliver and secure the website.
Changes
This notice will be updated when the application's data practices change.