Google data privacy

Gmail privacy disclosure

Last reviewed: August 28, 2026

What access the portal requests

The Gmail connection asks Google for exactly four permissions:

  • openid and email to identify the connected Google account;
  • https://www.googleapis.com/auth/gmail.readonly to read messages, threads, headers, attachments, labels, and mailbox settings; and
  • https://www.googleapis.com/auth/gmail.send to send an owner-approved new message or reply.

Google's read permission technically covers the connected mailbox. It is not limited by Google to rental email. The portal displays only conversations matched to a known resident, former resident, applicant, or inquiry address; manually linked by an owner; carrying the selected Gmail label; or sent through the portal to an approved contact.

What is stored

The system stores the connected Google account identifier and mailbox address, an encrypted refresh credential, the selected Gmail label identifier and name, Gmail thread/message/attachment identifiers needed for the feature, links to people and properties, each owner's portal read/follow-up state, send status, and content-free audit records naming the actor, action, time, record identifiers, and outcome.

Complete message bodies and attachment bytes are retrieved from Gmail only when needed and are not durably stored in D1, logs, analytics, audit records, browser storage, or development fixtures. Draft text remains only in the active browser view until a confirmed send or navigation away.

Who can use the mailbox

Every approved, active owner who passes the required owner sign-in and multi-factor checks can read included conversations and send through the connected account. Only the designated primary owner can connect, replace, relabel, reconnect, revoke, or disconnect it. Residents and applicants never receive owner-mailbox access.

How content is handled

Full message reads can receive provider-inline MIME bytes and filenames. That inline data is rendered only for the active request and is not durably stored. The separate attachment endpoint only fetches descriptor-based downloads after an owner chooses the matching attachment.

  • Remote images are blocked and are not loaded by the portal, preventing automatic contact with a sender's tracking server.
  • Incoming attachments are fetched from Gmail only after an owner asks to download one, checked against the included message, limited to the supported size, and returned with download-safe browser headers. They are not previewed or retained by the portal.
  • Application logs, analytics, monitoring, errors, and audits must exclude message bodies, attachment bytes, credentials, authorization codes, raw Google responses, and full mailbox queries.

No sale, advertising, credit use, or AI training

Google data is used only for the visible owner communications feature. It is not sold or transferred to advertising platforms or data brokers, used for advertising or credit decisions, or used to create, train, or improve an artificial-intelligence or machine-learning model.

Use of information received from Google Workspace APIs will adhere to the Google Workspace User Data and Developer Policy, including its Limited Use requirements.

Disconnect, revoke, and request deletion

The primary owner can disconnect Gmail in Communications. Disconnecting immediately disables portal Gmail operations, removes the locally stored encrypted credential, attempts to revoke the Google grant, and reports when Google revocation cannot be confirmed. A Google account holder can also revoke the grant in the Google Account connections settings.

Non-content audits and person/property links remain after disconnect so the organization can document actions and safely reconnect. Use the contact page to request deletion of Gmail-derived organization records. The request will be reviewed against legal, security, and operational retention duties; eligible data will be deleted or de-identified, and any required retained record will be explained.

Email is not authority for sensitive changes

An email address match does not prove who sent a message. Email alone is never enough authority to change banking or payment instructions, lease or contract terms, rent, property access, or resident-account ownership. Those requests require an approved independent verification workflow.

Google policy references