Privacy & Data Architecture
EmberFocus is being built around one boundary: Google Workspace remains the authoritative home for Workspace content.
What EmberFocus accesses
Only information authorized through Google and needed to render the feature you are using. Gmail access is separate from sign-in and begins read-only.
What stays inside Google
Email bodies, subjects, senders, recipients, attachments, summaries, Calendar content, Contacts content, and Workspace document content remain Google-hosted.
What EmberFocus stores
The current foundation stores app authentication only. It does not contain an email-content database. Future workflow state should use Gmail labels or other Google-native storage wherever possible.
OAuth permissions
Basic Google sign-in requests identity information only. Gmail permissions are requested separately and progressively, starting with the narrowest read access needed.
AI use
No AI provider receives email content. Optional AI enrichment is not part of this MVP and requires explicit future authorization and disclosure.
Telemetry and logs
The application must not log OAuth tokens, subjects, addresses, recipients, attachment names, email bodies, or thread summaries. No email-content analytics are enabled.
Disconnecting access
Users can sign out of EmberFocus and revoke its Google access from their Google Account security settings. Revocation prevents future retrieval; Google remains the authoritative store.
Organization administration
A future organization administrator may manage deployment settings, enabled features, scopes, privacy settings, and versions—but cannot read employee email through EmberFocus.