EFFECTIVE AUGUST 29, 2026

Privacy Policy

This policy explains how the locally operated bitshell application accesses and handles Google user data.

Data accessed

When a user authorizes a Google account, bitshell may access:

bitshell does not need to download or store message bodies to perform its Sent-mail cleanup function.

How data is used

Google user data is used only to verify that an authorized account matches the account selected by the user and to perform mailbox maintenance explicitly started by the user. It is not used for advertising, profiling, surveillance, or sale.

Storage and protection

bitshell runs on the user's own Windows computer. Account-to-environment mappings and authorization status are stored in a local SQLite database. OAuth refresh tokens are encrypted with Windows Data Protection API and can be decrypted only in the same Windows user context. Tokens, passwords, and message contents are not written to application logs or returned to the browser dashboard.

Sharing and transfer

bitshell does not sell Google user data or share it with advertisers, data brokers, or unrelated third parties. Data is sent to Google only as necessary to use the Gmail API. The local operator is responsible for the security of the computer on which bitshell runs.

Retention and deletion

Local account bindings and encrypted credentials remain until the user disconnects or unbinds the account, or deletes the local database. Unbinding an environment removes its locally stored OAuth credential. A user may also revoke bitshell access at any time from the Google Account third-party connections page.

Google API Services User Data Policy

bitshell's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Contact

Privacy questions and deletion requests: qdman006@gmail.com.