Privacy Policy — DJEP Gmail Webmail

Applies to oauth.djep.app (OAuth connection relay) and google-api.djep.app (Gmail-style webmail UI)

Last updated:

Google API Services User Data Policy — Limited Use

Summary

  • We request only the Gmail scopes needed for the features you use (reading messages and sending email). Our production app requests openid, email, profile, and https://mail.google.com/.
  • We do not sell or share your Gmail content with third parties for advertising.
  • We do not store your Gmail messages or attachments on our servers.
  • We store your Google OAuth tokens securely so you can use the app, and you can revoke access at any time.
  • You can delete your data (tokens) by disconnecting in the app (if available) or contacting us, and you can revoke access from your Google Account at any time.

What Gmail data we access (and why)

When you connect Gmail, we request a minimal set of OAuth scopes. Exact scopes appear on Google’s consent screen and reflect the code shown below. We currently use standard identity scopes and a Gmail scope that provides full mailbox access so the webmail features function correctly.

Scope Why we need it
openid, email, profile Identify your Google account and show the correct mailbox.
https://mail.google.com/ Full Gmail access required for a complete webmail experience (read/display messages, compose/send, apply labels, mark read/unread, move messages, and other mailbox actions that you initiate in the UI). We do not perform destructive actions (e.g., permanent delete) without your explicit action, and we do not run automated batch processing of your mailbox.
Restricted scope notice: https://mail.google.com/ is a Gmail restricted scope under Google’s policies. We comply with the Google API Services User Data Policy (including Limited Use) and undergo Google’s verification process as required.

Gmail data we access (read-only unless you take an action like Send/Reply/Label): labels/folders, message lists, message metadata (IDs, headers, from/to/subject), message bodies (plain & HTML), inline images and attachments (when opened), and thread relationships.

When you send or reply from DJEP, we use the content you create (recipients, subject, body, attachments) solely to deliver the message through Gmail.

We do not access your Gmail settings (signatures, filters, forwarding, delegates) and we do not engage in automated analysis of message content beyond what is required to display and send your email.


How we use the data


What we store (and what we don’t)

We store

We do not store

Retention


Security

Note: The system is designed so Gmail content is not persisted on our servers—reducing risk. Attachments you choose to download go directly to your device.


Your choices & controls

Revoke app access (Google account controls)

  1. Open Google Account → Security → Third‑party apps with account access.
  2. Select the DJEP app (the exact app name shown on the consent screen).
  3. Click Remove Access.

Disconnect & delete tokens (DJEP controls)

Data portability

Your Gmail data remains in Gmail. Because we do not store message content, there is no additional export to provide beyond what Google already offers.


Sharing & transfers


International data transfers

All DJEP services for this integration are hosted and processed in the United States. If you access the service from outside the U.S. (for example, the UK or Australia), your information will be transferred to and stored in the United States.

For UK/EU users: where applicable, we implement appropriate safeguards for transfers to the U.S. consistent with applicable law (e.g., EU Standard Contractual Clauses/UK IDTA or their successors). Gmail message content itself remains with Google unless and until you view it in the UI.


Children’s privacy

DJEP is not directed to children under 13 (or the relevant age in your jurisdiction). Do not use the Gmail integration if you are under the minimum age.


Cookies and local storage

We use essential session cookies/local storage for authentication and to remember state in the webmail UI. We do not use Gmail data for advertising or cross‑site tracking.


Compliance with Google’s policies (Limited Use)


Data controller, legal bases & rights (UK/EU)


Changes to this policy

We may update this policy as our services evolve or to remain compliant. If changes are material, we will notify you (e.g., in‑app notice or email) and update the “Last updated” date above.


Contact

DJ Event Planner
PO BOX 191
Spirit Lake, IA 51360
USA
Email: privacy@djeventplanner.com