Privacy Policy
Last updated: April 27, 2025
Overview
Dharma Automations ("Dharma", "we", "us") provides an AI-powered Gmail add-on and web dashboard that helps you draft email replies, manage labels, and handle scheduling. This policy explains what data we collect, how we use it, and your rights.
Data We Collect
- Gmail content — message subjects, bodies, and sender metadata, accessed solely to generate draft replies and detect scheduling requests on your behalf.
- Google Calendar data — upcoming events and availability, used to suggest meeting times.
- Account identifiers — your Google account email address, used to authenticate you and associate your preferences.
- Preferences — tone settings, scheduling preferences, and writing-style profiles you configure in the dashboard.
How We Use Your Data
We use your data exclusively to provide the Dharma service:
- Generating AI-assisted email drafts using your selected tone and writing style
- Detecting and responding to scheduling requests in your inbox
- Applying Gmail labels and filters you configure
- Storing your preferences so settings persist across sessions
Third-Party Services
Dharma uses the following third-party services to operate:
- Anthropic (Claude API)— email content is sent to Anthropic's API to generate draft replies. Anthropic's privacy policy governs their handling of this data.
- Google APIs — we access Gmail and Google Calendar through official Google APIs under your explicit OAuth authorization.
- Vercel — our infrastructure provider for hosting and serverless functions.
Data Retention
We do not persistently store the content of your emails. Email content is processed transiently to generate responses and is not written to our databases. Your preferences and account information are retained until you delete your account.
Google API Scopes
Dharma requests the following Google OAuth scopes:
- Read Gmail messages and metadata
- Compose and send email drafts on your behalf
- Read Google Calendar events
Security
All data is transmitted over HTTPS. We use industry-standard security practices to protect your information. OAuth tokens are stored securely and never exposed client-side.
Your Rights
You may request deletion of your account and associated data at any time by contacting us. Upon request we will delete your stored preferences and account record within 30 days.
Contact
For privacy questions or data deletion requests, contact us at finley@qsbsrollover.com.