CaseMail Google Workspace API Privacy & Limited Use Policy
How CaseMail accesses, uses, stores, transfers, and protects Google Workspace and Gmail user data.
Contents
- 1. Scope of This Policy
- 2. Google Data CaseMail May Access
- 3. How CaseMail Uses Google User Data
- 4. User-Directed Storage and Evidence Preservation
- 5. Limited Use Compliance
- 6. No Advertising, Data Brokerage, or Credit Uses
- 7. AI and Machine Learning
- 8. Human Access
- 9. Transfers and Service Providers
- 10. Security
- 11. Revoking Access and Privacy Requests
- 12. Related Policies
- 13. Changes to This Policy
- 14. Contact
1. Scope of This Policy
This Google Workspace API Privacy & Limited Use Policy supplements the CaseMail Privacy Policy and applies when a user connects a Google account or when CaseMail receives Google user data through Google Workspace APIs, including Gmail APIs. VerTrius Corp, doing business as CaseMail, operates CaseMail.
This page is intended to explain, in a direct and Google-specific manner, how CaseMail accesses, uses, stores, discloses, and protects Google user data. If this policy conflicts with a more protective requirement of an applicable Google developer policy, the applicable Google requirement controls our handling of Google user data.
2. Google Data CaseMail May Access
CaseMail requests only Google OAuth scopes reasonably necessary for the CaseMail features the user chooses to enable. Depending on the scopes authorized, CaseMail may access Google account identifiers and Gmail data such as message bodies, attachments, participants, metadata, headers, labels, settings, and related information.
The Google OAuth consent screen identifies the permissions requested for the applicable CaseMail feature. CaseMail does not receive a user's Google password through OAuth.
3. How CaseMail Uses Google User Data
CaseMail uses Google user data only to provide or improve user-facing CaseMail features that the user has requested or authorized. Those features may include verifying a connected email account, displaying or allowing a user to select email correspondence, capturing and certifying selected email threads, messages and attachments, creating cryptographic fingerprints and certificate records, preserving user-selected correspondence in the Digital Evidence Archive, re-verifying certified correspondence, sharing evidence records at the user's direction, and providing other Certified Email functionality visible to the user.
Where an enabled feature requires sending, modifying, labeling, or otherwise acting on Gmail data, CaseMail uses the authorized permission only for the user-requested CaseMail feature and within the scope granted by the user.
4. User-Directed Storage and Evidence Preservation
CaseMail does not use Google Workspace API access to indiscriminately copy or build a permanent database of a user's entire Gmail account. CaseMail processes data needed for the feature the user selects.
When a user affirmatively selects correspondence for certification, evidence preservation, or Digital Evidence Archive storage, CaseMail may retain the selected message content, attachments, metadata, and CaseMail-generated evidence records for as long as necessary to provide that user-directed feature, subject to the CaseMail Privacy Policy, the user's plan or agreement, and applicable law.
Revoking Google OAuth access prevents future API access but does not necessarily delete certified correspondence or evidence records that the user previously directed CaseMail to create or preserve. Users may submit applicable deletion requests through the CaseMail Privacy Policy, subject to legal, contractual, evidentiary, security, and immutable-record exceptions.
5. Limited Use Compliance
CaseMail's use and transfer to any other app of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
CaseMail limits its use of Google user data to providing or improving the appropriate user-facing CaseMail features for which access was requested.
6. No Advertising, Data Brokerage, or Credit Uses
CaseMail does not sell Google user data. CaseMail does not transfer or use Google Workspace API data for advertising, retargeting, personalized advertising, data-broker activities, information-reseller activities, creditworthiness determinations, or lending decisions.
7. AI and Machine Learning
CaseMail does not transfer, sell, or use Google Workspace API user data to create, train, or improve generalized or non-personalized artificial intelligence or machine-learning models.
If CaseMail offers an AI-enabled user-facing feature that is permitted under Google policy, any Google user data used for that feature will be limited to the specific appropriate use case, permissions, and user experience authorized by the user and will remain subject to Google's Limited Use requirements.
8. Human Access
CaseMail does not permit personnel to read Google user data except in limited circumstances allowed by Google policy, such as when the user has provided explicit consent for access to specific data for support; when access is necessary for security or abuse investigation; when required to comply with applicable law; or when data has been aggregated and anonymized for permitted internal operations.
9. Transfers and Service Providers
CaseMail may transfer Google user data only as permitted by Google policy and applicable law, including to service providers when necessary to provide or improve the user-facing CaseMail feature and subject to appropriate protections; for security purposes; to comply with law; or in connection with a merger, acquisition, or sale of assets when Google's policy requirements, including any required user consent, are satisfied.
CaseMail does not permit service providers to use Google user data for their own advertising, data-broker, credit, or generalized AI-training purposes.
10. Security
CaseMail uses safeguards designed to protect Google user data, including access controls, encryption and secure transmission where appropriate, logging, monitoring, and restrictions on personnel and service-provider access.
Users are responsible for securing their CaseMail and Google accounts and should revoke access promptly if they believe an account has been compromised.
11. Revoking Access and Privacy Requests
Users can revoke CaseMail's Google OAuth access from their Google account permissions. Revocation may disable CaseMail features that depend on the connection.
Privacy questions and requests concerning Google user data may be submitted to privacy@vertrius.com. Requests are handled under the CaseMail Privacy Policy and applicable law.
13. Changes to This Policy
We will keep this Google-specific policy current with material changes to how CaseMail uses Google user data. If CaseMail materially changes the purposes for which Google user data is accessed or used, we will update the applicable disclosures and obtain any additional consent or Google verification required before implementing the change.
14. Contact
For questions about CaseMail's handling of Google user data, contact:
Email: privacy@vertrius.com
VerTrius Corp
16192 Coastal Highway
Lewes, DE 19958