Privacy

How CivicFolio handles Google Workspace data.

This notice explains the data CivicFolio uses when an administrator connects an approved Google account.

Connection and use

An administrator starts the Google consent flow. CivicFolio requests Gmail read-only access and Google Drive access to review source information, add review metadata to Inbox, and complete an exact Drive action after confirmation.

CivicFolio cannot send Gmail. CivicFolio's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Data CivicFolio stores

For Gmail, CivicFolio stores message metadata such as sender address, subject, received date, Gmail link, and attachment name, type, and size. It does not store message bodies, snippets, or attachment bytes.

For Drive, CivicFolio stores file metadata such as name, type, link, modified date, parent context, and a content hash when required for review. It does not keep a second copy of a Drive file.

CivicFolio stores Google access and refresh credentials encrypted in its PostgreSQL database. It also stores short-lived consent state and reviewed Drive action metadata and provider readback.

Access, sharing, and security

Google Workspace records are limited to the administrator who owns the connected account. CivicFolio uses these records only to operate the connected workflow and to preserve its review trail.

CivicFolio does not sell Google user data. It does not transfer Google user data except to service providers that operate or secure CivicFolio, at the administrator's direction, or when security or law requires it.

CivicFolio uses administrator access checks, per-connection database access rules, browser-bound OAuth state with Proof Key for Code Exchange, and encrypted credential storage. These controls reduce access risk but do not remove all risk.

Retention and deletion

Disconnect asks Google to revoke the grant and deletes CivicFolio's encrypted credential envelope. Disconnect prevents new Google reads and Drive actions. If Google cannot revoke access, CivicFolio reports the failure. Disconnect does not automatically remove existing Inbox metadata or completed operation readback.

CivicFolio does not publish a fixed retention period or a self-service per-record deletion control in this release. To request deletion of Google Workspace records, contact CivicFolio with the connected account and organization. CivicFolio will verify the request and explain any record that it must retain for security, legal, or operational reasons.

Privacy contact

For a privacy question or a deletion request, email contact@civicfolio.com.