Version 1.0 · Effective 2026-09-12
Privacy Policy
What we collect
We collect your verified Google identity (name, email and provider identifier), account and profile preferences, subscription identifiers and invoice records, project inquiries, support messages, policy acceptances and security evidence. Where a trusted hosting ingress supplies it, signup and security IP information is encrypted; a keyed hash supports exact-match security searches. We do not collect Google or Facebook passwords or full card numbers.
Why we process information
We process information to authenticate you, deliver requested design and digital-management features, bill subscriptions, answer support requests, prevent abuse and meet applicable legal obligations. Marketing permission is optional and separate. The applicable legal bases, controller identity, business address and jurisdiction-specific rights must be finalized by the business before publication.
Google sign-in and Gmail
Google sign-in requests identity scopes only. Connect Gmail is a separate authorization that requests read-only Gmail access for search, selected-thread summaries and drafts. We retrieve only the messages needed for the current request and do not persist raw inbox messages. Sending email is not enabled. Gmail content is never sold, used for advertising, credit scoring, or training or improving a general AI model.
Google Limited Use
BuiltWithinChrist’s use of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace user data and developer policy, including the Limited Use requirements. Transfers are limited to providing prominent user-requested features with consent, security, legal compliance, or a merger or asset transfer with required prior explicit consent. We do not permit administrators to browse customer email. Exceptional human access requires a documented policy-permitted basis such as affirmative consent to specific data, security investigation or legal obligation.
Facebook and Meta
We request access only to authorized Pages through official APIs. Page identifiers, authorized permissions, encrypted credentials, analytics snapshots and action records support the features you activate. Inbox contents are retrieved for your own account, not exposed in normal admin views. Features requiring Meta approval remain unavailable until approved. We do not scrape profiles or private data.
AI processing and outside services
OpenAI processes prompts and the selected account context only when you request an AI feature and authorize account-context use. Google and Meta receive the requests necessary for their integrations. Stripe processes billing. The deployment’s hosting and PostgreSQL providers store application records. The final provider and subprocessor list, locations and transfer safeguards must be confirmed before launch. OpenAI API data is not used for training by default; our requests disable application-state storage. OpenAI may retain abuse-monitoring data for up to 30 days unless different approved contractual controls apply. We do not claim zero retention.
Storage and retention
OAuth credentials are encrypted with authenticated encryption. Account records are retained while your account is active. Saved chat history is encrypted and retained for your chosen 7, 30 or 90 day period. Raw Gmail and Messenger messages are processed transiently. Analytics snapshots are retained for 90 days. Security evidence is retained for 90 days, then purged; expired authorization attempts are also purged. Project inquiries and closed support records are retained for up to 365 days. Immutable non-content audit events and consent evidence are retained while the account is active and for the business’s documented legal-retention period after deletion; the production retention schedule must be approved before launch. Backups must have a documented expiry, restore-and-redelete procedure and access controls.
Your controls
Connected Accounts provides reconnect, disconnect and deletion controls. Disconnection immediately prevents further app retrieval; stored tokens are deleted and provider revocation is attempted. Deleting integration-derived data also removes saved AI conversations that could contain that data. Download My Data exports application records, not a bulk export of your Gmail mailbox. Delete Account stops automations, disables sessions and queues billing cancellation, revocation and personal-data erasure. Marketing choices can be changed without affecting service access.
Rights and contact
Contact us through the Contact page for access, correction, deletion, objection, withdrawal or other rights available in your jurisdiction. You may also have a right to complain to a regulator. We respond under applicable law. Security measures reduce risk but do not guarantee that incidents cannot occur. Material policy changes require a new version and, where appropriate, renewed consent.
BuiltWithinChrist · builtwithinchrist.com