Legal
Privacy Policy
This policy explains how Nassarlabs ("Nassarlabs", "we", "us") handles personal data in two places: the website at nassarlabs.com, and the automation tools we build and operate that connect to Google services (the "Tools"). It also contains the disclosures Google requires from applications that access Google user data.
1. Who we are
Nassarlabs is an agentic automation lab. We build and run internal automation for our own operations and for the businesses we work with. You can reach us at nassarmh93@gmail.com.
2. The website
The website is a static, informational site. It has no user accounts, no forms, and no comment features.
- Cookies and analytics. We do not set cookies and we do not run analytics or advertising trackers on the site.
- Server logs. Our web server records the usual technical details of each request (IP address, browser type, requested page, time). We use these logs only for security and troubleshooting, and they are deleted automatically after 14 days.
- Fonts. The site loads web fonts from Google Fonts. Your browser requests those files from Google directly, which means Google receives your IP address. Google describes its handling of that data in the Google Privacy Policy.
- Email. If you email us, we keep the correspondence for as long as needed to respond and to keep a record of the conversation.
3. The Tools and Google user data
The Tools are internal automations that Nassarlabs operates. They are not offered to the general public. A Google account can only be connected to a Tool by Nassarlabs or by the business the Tool is run for, and only after that account's owner grants access through Google's consent screen.
3.1 What the Tools access
Depending on the Tool and the permissions granted, the Tools use the Gmail API to:
- search for and read email messages and their attachments in the connected mailbox, and organise messages by applying or changing labels (Google scope
gmail.modify); - read basic settings of the connected mailbox (Google scope
gmail.settings.basic).
The Tools do not send email on your behalf, do not access your contacts or calendar, and do not access any other Google service unless this policy is updated to say so.
3.2 Why the Tools access it
The Tools read messages from senders that the connected business has designated, such as suppliers sending invoices or staff forwarding documents to a shared mailbox. From those messages and attachments they extract structured business information, for example the vendor, invoice number, dates, amounts and the store or location an invoice belongs to, and turn it into to-do summaries and spreadsheets for the business's own staff. That is the only purpose for which Google user data is used.
3.3 How Google user data is used and shared
- We use Google user data only to provide the features described above to the business that connected the mailbox.
- We do not sell Google user data, we do not use it for advertising, and we do not use it to build profiles of people.
- To read attachments and extract the information described above, message content and attachments may be processed by Claude, an AI model operated by Anthropic. Anthropic processes that data under the Anthropic Privacy Policy.
- The extracted summaries and spreadsheets are delivered to the connected business's own internal channels, such as a staff messaging group. They are seen by that business's staff, which is the purpose of the Tools.
- Beyond the processing above, we do not transfer Google user data to anyone else, except where the law requires it.
3.4 Storage, security and retention
- Where. Google access tokens, downloaded attachments and extracted results are stored on servers operated by Nassarlabs, in dedicated service accounts with restricted file permissions. Data moves between our servers and Google, Anthropic and messaging providers over encrypted connections.
- Access. Only Nassarlabs operators with administrative access to those servers can reach the raw data, and they do so only to run, secure and troubleshoot the Tools.
- Retention. Access tokens are kept for as long as the mailbox stays connected and are deleted when access is revoked. Downloaded invoices and the extracted results are business records of the connected business and are kept for as long as that business needs them for its accounting and record-keeping. Everything else, such as run logs, is deleted routinely.
3.5 Your choices
- You can withdraw a Tool's access to your Google account at any time from your Google Account's third-party access page. The Tool stops accessing the mailbox immediately and its stored token becomes unusable.
- You can ask us to delete tokens, attachments and extracted data we hold for your mailbox by emailing nassarmh93@gmail.com. We will do so, except for records the connected business is required to keep for legal or accounting reasons.
Limited Use disclosure. Nassarlabs' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Children
Neither the website nor the Tools are directed at children, and we do not knowingly collect personal data from anyone under 16.
5. Changes to this policy
If we change how we handle personal data, we will update this page and change the effective date at the top. Material changes to how the Tools use Google user data will be reflected here before they take effect.
6. Contact
Questions or requests about this policy: nassarmh93@gmail.com.