Privacy policy
In short
- KX Workspace Gateway is a private app that Rishabh Madaan runs for the owner's own use. Nobody else can sign up.
- It lets AI assistants that the owner connects work with the owner's own Google accounts (Gmail, Google Calendar, Google Drive, Google Docs and Google Sheets), and only within the permissions the owner gives each assistant.
- It keeps no copy of anyone's mail, files or calendar, apart from short-lived downloads an assistant asks for (section 4). It keeps a record of which assistant used which account, without the content.
- Google data goes only between the owner's server and Google, and to the AI assistants the owner connects. It is never sold or used for ads, and the app itself never uses it to train AI models.
1. Who runs this app
KX Workspace Gateway is run by Rishabh Madaan (the "owner"). It is a private, personal-use installation of Workspace Gateway, free open-source software that the owner runs on a machine the owner controls. The app runs on a computer the owner runs at home, reachable only through the owner's private Tailscale network.
The only person who uses it is the owner. The only Google accounts it connects to are accounts the owner has linked by signing in to each one. There is no public sign-up, and no one else's account can be added without signing in to that account.
The Workspace Gateway software sends nothing to the people who wrote it: no usage data, no telemetry and no Google data.
2. What the app can access
When the owner links a Google account, Google asks the owner to approve the permissions below. The app uses them only when an AI assistant that the owner has allowed asks it to do something.
- Basic account details: the account's email address and name, so the app knows which account was linked.
- Gmail: read and search mail, organise it with labels, write drafts, send mail, and change basic mail settings such as filters.
- Google Calendar: read calendars and events, and create, change and delete events.
- Google Drive: read and search files, and create, change, share and delete files.
- Google Docs: read, create and edit documents, and find them through Drive.
- Google Sheets: read, create and edit spreadsheets, and find them through Drive.
Mail, events and files can contain information about other people, such as senders, guests and collaborators. That information is handled exactly as described in this policy.
Signing in to the app's own dashboard, or connecting an AI assistant by signing in, uses only the owner's Google email address, to check that the person signing in is the owner.
3. How access is limited
An AI assistant connects in one of two ways: with a key the owner creates on the dashboard, or by the owner signing in from the assistant with the owner's own Google account. Either way, every assistant has its own permissions, set by the owner on the dashboard.
- A new assistant has no access until the owner grants some.
- Access is granted per account and per service. For example, an assistant can be allowed Gmail on one account and nothing on another. The owner can also choose "all accounts", which includes accounts linked later.
- A service grant covers that service's reading and writing. An assistant allowed Gmail on an account can both read and send mail from it. There is no separate read-only setting.
- The owner can change an assistant's access, turn an account off, or revoke an assistant at any time. A revoked assistant is refused from then on.
4. What is stored, and what is not
Stored on the owner's server
- Linked accounts: each account's email address, whether it is turned on, its status, the permissions Google granted, when it was last checked, and the sign-in tokens Google issues so the app can act without asking again.
- The app's own credentials: the owner's Google app credentials and the app's own keys.
- Assistants: each assistant's name, a scrambled (hashed) copy of its key or an encrypted record of its sign-in, its permissions, and when it was created, last used or revoked.
- Activity records: for each request, the time, which assistant, which account, which action (for example "search mail"), and whether it worked, was refused or failed. Dashboard sign-ins are recorded too; a refused sign-in is recorded with the email address that tried. Activity records never include the content: no message text, file contents, event details or document text.
- Dashboard sign-ins: a scrambled token for the owner's dashboard session, which expires after 12 hours.
- Error logs from the part of the app that talks to Google, limited to warnings and errors. A log line can name an account or an item, such as a file name, but the logs are not a copy of mail or files.
Never stored
The app keeps no copy of anyone's mailbox, Drive, calendar, documents or spreadsheets. When an assistant asks for something, the app fetches it from Google and passes it to that assistant. It is not kept afterwards.
One exception: temporary files
When an assistant asks to download a Drive file or a Gmail attachment, the app saves that file on the owner's server so the assistant can collect it. The file expires after one hour and is deleted from the disk the next time the app saves or serves a temporary file, so an expired file can stay on the disk until then. Only the assistant that asked for it, or the owner on the dashboard, can collect it. These files are never included in backups.
5. Where data goes
- Between the owner's server and Google, to carry out what an assistant asked for.
- To the AI assistants the owner connects, and only within their permissions. These assistants are separate products, such as Claude Code or Codex. They send what they receive to their providers' AI services, which handle it under their own terms and privacy policies. The owner chooses which assistants to connect.
- Over a private network. The owner's devices reach the server over Tailscale's encrypted private network. Tailscale helps the devices find each other and may pass encrypted traffic along, but it cannot read that traffic.
Google data is not shared with anyone else. The app has no analytics and no tracking.
These public pages are hosted on Cloudflare Pages (the hosting provider may process ordinary connection data such as IP addresses when these pages are visited). They use no cookies, no scripts and no analytics.
6. Backups
The app can make encrypted backups of its stored data (section 4, without the temporary files and logs), so it can be restored on another machine. A backup includes the linked accounts' sign-in tokens, which is why it is encrypted. It cannot be opened without a separate recovery key. It never contains copies of mail, files or calendars, because the app does not keep them.
The backups are encrypted snapshots kept on the owner's server and copied to the owner's own laptop; the recovery key is kept separately in the owner's password manager.
7. How long data is kept, and deleting it
- Linked accounts and their tokens are kept until the owner removes the account on the dashboard. Remove deletes the server's copy of the tokens, but Google still counts the app as allowed, and older backups still hold a working copy. Revoke also asks Google to cancel the app's access, which makes every copy useless.
- Any account holder can cancel the app's access at Google directly, at myaccount.google.com/connections. After that, the stored tokens no longer work, including any copies in backups.
- Assistants stop working the moment the owner revokes them on the dashboard. Their record stays, marked as revoked.
- Activity records and error logs are kept on the server and are not deleted automatically. Removing an account does not remove its past records. They are deleted when the owner deletes the app's data.
- Backups are kept until the owner deletes them, in each place a copy is kept.
- Removing the app completely means stopping it, deleting its data folder and backups, and cancelling its access at Google.
8. Google's user data policy
KX Workspace Gateway's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain words: Google data is used only to do what the owner's assistants are asked to do, for the owner.
9. What this app never does
- It never sells Google data, or any other data.
- It never uses Google data for advertising.
- It never uses Google data to develop, improve or train AI or machine learning models.
- It never lets anyone other than the owner read Google data, except where the law requires it.
10. Security
The app is reachable only from the owner's own devices on a private network, and connections to it are encrypted. Only the owner's Google account can open its dashboard. Assistants' keys are stored scrambled. Google's sign-in tokens are kept in a private folder on the server, and backups are encrypted. No system is perfectly secure, but the app is built to expose as little as possible.
11. Children
This app is used only by its owner. It is not meant for children, and no child can sign up for it.
12. Changes to this policy
If this policy changes, the new version will be posted on this page with a new effective date.
Earlier version: a privacy policy published on 9 September 2026 described an earlier setup of this app. This policy replaces it.
13. Contact
Questions about this policy or about this app's use of Google data: Rishabh Madaan, [email protected].