Vectorfy Gmail Dot Bridge
Privacy policy
App-specific information for the Vectorfy Gmail Dot Bridge.
About this policy
This policy describes Vectorfy Gmail Dot Bridge, operated by Vectorfy. It covers this metadata and notification bridge, rather than the separate Vectorfy Ops application. Contact [email protected] with questions about the bridge.
Google data accessed and used
The bridge requests https://www.googleapis.com/auth/gmail.metadata. It checks the selected Gmail account identity and accesses mailbox history, message and thread identifiers, labels, message timestamps and the From header. These are used to detect eligible arrivals, recover missed notifications and suppress mail sent by the owner. The INBOX watch filter does not limit the metadata permission to INBOX. The bridge does not fetch message bodies or attachments and does not provide Gmail sending, message deletion or settings operations.
Stored information
Cloudflare hosts the bridge using Workers, D1, Queues, Workflows, Durable Objects and separate OAuth KV stores. Durable records include message identifiers, arrival and eligibility state, history and watch cursors, receipt and job records, event-delivery state and consumer checkpoints. OAuth refresh grants and subscription credentials are encrypted by the application; its client credentials and encryption keys are held in scoped Worker Secrets. This does not mean all metadata records are encrypted by the application.
Data recipients
Google Gmail and Pub/Sub support mailbox access and change notifications. Cloudflare processes bridge data as its hosting provider. The authorised OpenAI connection receives a signed mail-arrival event containing a mailbox binding and message ID, together with an event identifier, event name and timestamp. The event does not contain the From header, message body or attachments. The separate Gmail integration used by that connection may read email content under its own authorisation; this bridge policy does not describe all processing by that integration or by ChatGPT.
Retention and deletion
Durable bridge records currently have no automatic purge. The 90-day recovery eligibility window is not a deletion schedule. Acknowledging a batch advances a checkpoint; it does not erase stored records or Gmail messages. Enrollment state is short-lived and consumed after callback handling, with expired-state cleanup during new enrollment. An expired callback lease does not delete all mailbox records.
Disconnecting and requesting help
You can revoke the Google grant in your Google Account third-party connections settings to prevent continued API access under that grant. Revocation does not automatically delete existing bridge records or copies already received by other services. Unsubscribing from bridge events removes that subscription and stops its pending deliveries, rather than erasing all mailbox data. The bridge has no self-service all-data deletion page. Contact [email protected] to discuss disconnection or removal of stored bridge data.