This Privacy Policy explains how 33touch (“33touch,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use our AI transaction-coordination application and related services (the “Service”). It includes specific details about how we access and handle data from Google services, including Gmail, because the Service can connect to your inbox to help manage real-estate transactions.
Contents
1. Information we collect
Account information
When you sign in with Google, we receive your name, email address, and profile picture (your Google account identifier) to create and secure your account.
Content you provide
Contracts and other documents you upload or paste into the Service, and any deal, contact, or note information you enter.
Google data (Gmail)
If you connect your inbox, we read certain Gmail data and — only when you explicitly approve an individual message — send email from your address on your behalf. See Section 2 for exactly what we access, send, and why.
Technical & usage data
Standard server logs (IP address, device/browser type, timestamps) and product usage events used to operate, secure, and improve the Service.
2. Google user data
To connect your inbox, the Service requests two Gmail scopes, together with basic identity scopes (openid, email, profile). You grant these in a single Google consent screen and can revoke them at any time.
| Scope | What it allows | Why we need it |
|---|---|---|
https://www.googleapis.com/auth/gmail.readonly | Read messages, attachments, and metadata. It does not allow us to modify, label, or delete anything in your mailbox. | To identify real-estate transaction email and extract deal details, dates, and documents. |
https://www.googleapis.com/auth/gmail.send | Send mail as you. It grants no read, modify, or delete ability of its own. | To send follow-up messages that you have reviewed and explicitly approved. |
We request gmail.send rather than a broader scope such as gmail.compose or gmail.modify because it is the narrowest permission that supports approved sending.
What we read
Our access is designed to be minimal and purpose-limited. The pipeline works as follows:
- Triage on metadata first. We first review only message metadata (sender, subject, a short snippet, and attachment file names) to determine whether a message relates to a real-estate transaction.
- Full content only when relevant. We retrieve a message’s full body and attachments only after that triage classifies it as real-estate business (for example, a purchase contract, disclosure, inspection, loan, or title document).
- We extract and organize. For relevant messages, we extract transaction details (such as parties, key dates, and document types) to build and update your deal records, and we may store the original document so you can view it in the Service.
- Everything else is discarded. Messages that are not real-estate business — personal mail, newsletters, promotions, and the like — are not stored. We retain only a non-content record (a message identifier and an “ignored” status) for sync de-duplication; the sender, subject, and body of ignored mail are not kept.
What we send
The Service drafts follow-up email — for example, a nudge to a counterparty about a missing disclosure or an approaching deadline — and can send it from your Gmail address so it appears in the thread as coming from you.
- You approve every message. No email is ever sent from your account automatically or on a schedule. We show you each draft, with its recipients and full body, and send it only after you explicitly approve that specific message.
- Recipients and content. Recipients are drawn from the transaction contacts in your deal records. Drafts are generated from those deal records and from the transaction email we have already processed under
gmail.readonly. - What we keep. We store a copy of each message you approve and send, along with its recipients and timestamp, so you have a record of outbound activity on a deal. Google also places a copy in your Gmail Sent folder, which is governed by your own Google account settings, not by us.
- What we cannot do. The
gmail.sendscope cannot read, modify, label, archive, or delete anything in your mailbox. We never send email to recipients you have not seen, and we never send on behalf of one user from another user’s account.
You can exclude specific senders or domains from processing at any time, and disconnect Gmail entirely from within the Service.
Aggregated and anonymized data
We do not create aggregated or anonymized Google user data. We do not derive, generate, or maintain any aggregated, anonymized, de-identified, or statistical dataset from Gmail content or metadata — not for analytics, benchmarking, research, product development, or any other purpose. Every statement in this policy about Google user data therefore describes raw Google user data, which is the only form we access, use, transfer, store, or retain.
3. How we use information
- Provide the Service: detect transactions, extract parties and deadlines, file documents to the correct deal, and surface upcoming dates.
- Draft follow-up email and, once you explicitly approve an individual message, send it from your Gmail address on your behalf.
- Authenticate you and keep your account and data secure.
- Operate, maintain, debug, and improve the Service.
- Communicate with you about the Service, including service-related notices.
- Comply with legal obligations and enforce our terms.
How this applies to Google data. Google user data is used only for the first two purposes above — providing you the transaction-coordination and approved-sending features described in Section 2 — and, where you ask us to, to debug a problem you report. We do not use Google user data for product analytics, benchmarking, research, advertising, or AI/ML model training, and we do not aggregate or anonymize it for any purpose. The general “operate, maintain, debug, and improve” activities above draw on technical and usage data, not on the contents of your inbox.
4. Limited Use & AI commitments
Google Limited Use disclosure
33touch’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We do not sell Google user data, and we do not use it for advertising.
- We do not use Google user data to train generalized or non-personalized AI/ML models. We use Google data only to provide and improve user-facing features within the Service for you.
- We do not allow humans to read your Gmail data except: (a) with your explicit consent (for example, to troubleshoot at your request); (b) where necessary for security purposes such as investigating abuse; or (c) to comply with applicable law. Google’s Limited Use requirements also permit human review of aggregated and anonymized data; that exception does not apply to us, because we do not create such data.
- To extract transaction details, relevant message content is processed by our AI provider (Anthropic) via its enterprise API. Data sent to the Anthropic API is not used to train Anthropic’s models. See Section 5.
5. How we share information
We do not sell your personal information. We share it only with service providers (subprocessors) that help us operate the Service, under contracts that require appropriate confidentiality and security:
| Provider | Purpose |
|---|---|
| Anthropic | AI processing — classifying messages and extracting transaction details. Data sent via the API is not used to train models. |
| DigitalOcean | Application hosting and managed database (where your account data and stored documents reside). |
| Authentication, Gmail access, and delivery of messages you approve for sending, at your direction. |
We do not share aggregated or anonymized Google user data with any party — as stated in Section 2, we do not create it.
The one other category of recipient is the people you choose to email: when you approve an outbound message, its contents go to the recipients shown to you on that draft, and to no one else.
We may also disclose information to comply with law, enforce our agreements, or protect the rights, safety, and security of users and the public. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; Google user data would be transferred only with your explicit prior consent, and we will notify you and give you the opportunity to delete your data before any such transfer.
6. Storage & security
Your data is stored on managed infrastructure operated by DigitalOcean in the United States. We protect it with the following safeguards:
- Encryption in transit. All traffic between you, the Service, Google, and our subprocessors is encrypted with TLS 1.2 or higher.
- Encryption at rest. Our application database and its backups are encrypted at rest with AES-256. This covers your account data, extracted deal records, Gmail message content and attachments stored against a deal, and copies of messages you have approved and sent.
- Credential protection. Gmail access and refresh tokens receive an additional layer of application-level encryption (AES-256-GCM) before they are written to the database, so they are never stored in plaintext.
- Access control. Access to production systems and data is limited to authorized personnel who need it to operate the Service, protected by multi-factor authentication, and granted on a least-privilege basis.
- Send-path controls. Because we hold permission to send mail as you, outbound sending requires your per-message approval and is bound to your own account; there is no path by which the Service sends from your address without that approval.
- Data minimization. As described in Section 2, we avoid retrieving or storing Gmail data that is not relevant to a real-estate transaction, which limits our exposure in the first place.
- Subprocessor diligence. The providers listed in Section 5 are bound by contract to maintain appropriate confidentiality and security safeguards.
Incident response. We maintain procedures to detect, investigate, and remediate security incidents. If a breach affects your personal information, we will notify you and the applicable regulators as required by law and without undue delay.
No method of transmission or storage is perfectly secure, but we work to protect your data and to limit what we collect in the first place.
7. Retention & deletion
We keep data only as long as we need it to provide the Service to you. Specific retention periods:
| Data | Retention |
|---|---|
| Gmail access and refresh tokens | Until you disconnect Gmail or revoke access at Google, at which point they are deleted immediately. |
| Gmail message content and attachments filed to a deal | For as long as your account is active, so the documents stay available in your deal records. |
| Extracted transaction details (parties, key dates, document types) | For as long as your account is active. |
| Copies of messages you approved and sent | For as long as your account is active, as your record of outbound activity on a deal. |
| Non-content records for ignored messages (a message identifier and an “ignored” status) | For as long as your account is active; used only to avoid re-processing the same message. No sender, subject, or body is kept. |
| Account information | For as long as your account is active. |
| Server logs and product usage events | Up to 90 days. |
Disconnecting Gmail
You can disconnect Gmail at any time from within the Service. This immediately deletes our stored Google tokens and stops all further inbox access and all ability to send on your behalf. Deal records and documents already created from your inbox are kept so you do not lose your work; you can delete them individually in the Service, or request deletion of all of them using the process below. You can also revoke our access directly at myaccount.google.com/permissions.
Deleting your data or account
You can request deletion of your Google data, or of your entire account, by emailing [email protected]. We will confirm the request and complete it within 30 days. Deletion removes your account information, extracted deal records, stored documents and attachments, sent-message copies, and any remaining Google tokens from our live systems. Residual copies in encrypted backups are purged on our normal backup rotation within 90 days of your request and are not accessed in the meantime.
We retain data beyond these periods only where the law requires it, and only for as long as that obligation lasts.
8. Your rights & choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Residents of the EEA/UK (under the GDPR) and California (under the CCPA/CPRA) have specific rights; we honor these requests and do not discriminate against you for exercising them. To make a request, contact us at the address below.
9. Children
The Service is intended for professional use by adults and is not directed to anyone under 18. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date, and we will provide additional notice for material changes.
11. Contact us
Questions or requests about this policy or your data? Contact us at [email protected].