AIM · NGX Insights

Privacy Policy

This policy explains how AIM handles information when Google OAuth is used for operational email alerts.

1. Information AIM uses

AIM is configured to request only the Google OAuth scope needed to send email:

https://www.googleapis.com/auth/gmail.send

With this scope, AIM can send operational alert messages using the Gmail account that the user explicitly authorizes.

2. What AIM does not request

3. How Google authorization data is used

Google OAuth credentials are used only to obtain access tokens needed to send AIM operational alerts. The refresh token is stored as a protected application secret and is not exposed through public routes. AIM may retain limited operational evidence such as alert timestamps, delivery status and provider message identifiers for audit and troubleshooting purposes.

4. Data sharing

AIM does not share Google user data with advertisers or sell it to third parties. Google authorization data is used only for the user-facing operational alert functionality described above, except where disclosure is required by law or necessary to protect the security and integrity of the service.

5. Data retention and revocation

A user can revoke AIM's Google authorization from the security/permissions section of the user's Google Account. Once authorization is revoked, AIM can no longer use that authorization to obtain Gmail access tokens. Operational audit records may be retained for security, compliance and troubleshooting purposes.

6. Google API Services User Data Policy

AIM's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.

7. Security

AIM applies access controls, secret bindings, fail-closed execution logic and audit records intended to limit unauthorized access to credentials and operational functions.

8. Contact

For privacy questions, contact the developer using the support email displayed on the Google OAuth consent screen for AIM.