Your mail stays yours.
This policy describes how Retail Assist Personal handles data when its owner chooses to connect a Google Account.
Google data accessed
Retail Assist requests only https://www.googleapis.com/auth/gmail.readonly. It uses that permission to list a bounded set of recent unread Target back-in-stock candidates and retrieve those candidates for local authenticity, product-link, and stock-intent checks.
The app does not send email or change, mark read, archive, label, move, or delete any Gmail message or setting.
Use and retention
- Full Gmail message content is processed transiently on the owner's Mac and is not retained.
- Retail Assist may retain locally derived evidence: a Gmail event identifier, Gmail timestamp, exact Target product link, scan count, match outcome, and availability-handoff history.
- The Google OAuth client material and refresh token are stored in macOS Keychain until the owner disconnects Gmail.
- Derived evidence remains in encrypted local application data until the owner deletes that data or restores a different backup.
Sharing and transfers
Retail Assist does not sell Google user data, use it for advertising, credit decisions, surveillance, or unrelated analytics, or allow another person to read message content. Gmail credentials and message bodies are not sent to the Retail Assist relay or any retailer.
The optional relay stores signed availability metadata from separately approved producers. The current local Gmail integration does not upload Gmail message content or OAuth credentials to that relay.
Security and deletion
Retail Assist uses Google's documented OAuth flow in the system browser, requests read-only access, stores credentials in macOS Keychain, encrypts sensitive local application data, and uses HTTPS for relay traffic.
Choosing Disconnect Gmail attempts to revoke the Google grant and removes the local Keychain credential. The owner can also revoke access from the Google Account connections page. Deleting Retail Assist's local application data and encrypted backups removes locally retained derived evidence.
Google API Limited Use
Retail Assist Personal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
For privacy or deletion assistance, use the support email displayed on Retail Assist Personal's Google OAuth consent screen.