Privacy and data deletion
Effective 18 July 2026
What SignalDesk processes
SignalDesk processes account identity, application preferences, connected Google account identifiers and encrypted OAuth credentials. When you connect Google, it synchronises the Gmail messages, labels, attachment metadata, and Calendar availability needed to provide the inbox, task, reply, and scheduling features you request.
How the data is used
Data is used only to operate SignalDesk for your account: synchronising mail, extracting proposed actions, drafting replies, planning work, creating approved calendar events, delivering notifications, securing the service, and diagnosing failures. SignalDesk does not sell personal data or use it for advertising.
Google user data is handled only for these user-facing features and in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Storage, sharing, and retention
OAuth refresh tokens, cached message bodies, and extracted attachment text are encrypted at rest. Raw attachment files are not retained. Cached bodies and extracted text expire automatically, with a 14-day default. Action analysis uses a 90-day default window. Long-lived task, goal, message metadata, source evidence, and privacy-safe audit records are retained while the account is active or according to configured retention settings.
Data is sent to Google APIs to perform requested Gmail and Calendar operations, and to the configured AI provider only when an AI feature is run. Infrastructure and delivery providers process the minimum data required to host the service and send notifications or account-recovery email. SignalDesk does not give other customers access to your data.
Your choices
You can disconnect a Google account from Settings. Disconnecting stops future synchronisation and removes the stored refresh token; you can separately remove SignalDesk access from your Google Account to revoke Google-side authorisation. AI suggestions remain proposals, and sending email or creating a calendar event requires explicit approval.
Access and deletion requests
To request a copy, correction, or deletion of your SignalDesk account data, email [email protected] from your SignalDesk sign-in address. The deployment operator will verify the request, revoke active sessions, remove connected-account credentials and user-owned application records, and confirm completion. Backup copies age out under the deployment's backup retention schedule and are not restored except for disaster recovery.
Security and contact
SignalDesk uses tenant-scoped access controls, encrypted credentials and sensitive caches, approval gates for external actions, revocable sessions, optional authenticator-app two-factor authentication, and privacy-safe operational logs. Questions or suspected security issues can be sent to [email protected] .