Legal

Privacy Policy

Last updated: July 31, 2026

This Privacy Policy explains how 33touch (“33touch,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use our AI transaction-coordination application and related services (the “Service”). It includes specific details about how we access and handle data from Google services, including Gmail, because the Service can connect to your inbox to help manage real-estate transactions.

1. Information we collect

Account information

When you sign in with Google, we receive your name, email address, and profile picture (your Google account identifier) to create and secure your account.

Content you provide

Contracts and other documents you upload or paste into the Service, and any deal, contact, or note information you enter.

Google data (Gmail)

If you connect your inbox, we read certain Gmail data and — only when you explicitly approve an individual message — send email from your address on your behalf. See Section 2 for exactly what we access, send, and why.

Technical & usage data

Standard server logs (IP address, device/browser type, timestamps) and product usage events used to operate, secure, and improve the Service.

2. Google user data

To connect your inbox, the Service requests two Gmail scopes, together with basic identity scopes (openid, email, profile). You grant these in a single Google consent screen and can revoke them at any time.

ScopeWhat it allowsWhy we need it
https://www.googleapis.com/auth/gmail.readonlyRead messages, attachments, and metadata. It does not allow us to modify, label, or delete anything in your mailbox.To identify real-estate transaction email and extract deal details, dates, and documents.
https://www.googleapis.com/auth/gmail.sendSend mail as you. It grants no read, modify, or delete ability of its own.To send follow-up messages that you have reviewed and explicitly approved.

We request gmail.send rather than a broader scope such as gmail.compose or gmail.modify because it is the narrowest permission that supports approved sending.

What we read

Our access is designed to be minimal and purpose-limited. The pipeline works as follows:

What we send

The Service drafts follow-up email — for example, a nudge to a counterparty about a missing disclosure or an approaching deadline — and can send it from your Gmail address so it appears in the thread as coming from you.

You can exclude specific senders or domains from processing at any time, and disconnect Gmail entirely from within the Service.

Aggregated and anonymized data

We do not create aggregated or anonymized Google user data. We do not derive, generate, or maintain any aggregated, anonymized, de-identified, or statistical dataset from Gmail content or metadata — not for analytics, benchmarking, research, product development, or any other purpose. Every statement in this policy about Google user data therefore describes raw Google user data, which is the only form we access, use, transfer, store, or retain.

3. How we use information

How this applies to Google data. Google user data is used only for the first two purposes above — providing you the transaction-coordination and approved-sending features described in Section 2 — and, where you ask us to, to debug a problem you report. We do not use Google user data for product analytics, benchmarking, research, advertising, or AI/ML model training, and we do not aggregate or anonymize it for any purpose. The general “operate, maintain, debug, and improve” activities above draw on technical and usage data, not on the contents of your inbox.

4. Limited Use & AI commitments

Google Limited Use disclosure

33touch’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

5. How we share information

We do not sell your personal information. We share it only with service providers (subprocessors) that help us operate the Service, under contracts that require appropriate confidentiality and security:

ProviderPurpose
AnthropicAI processing — classifying messages and extracting transaction details. Data sent via the API is not used to train models.
DigitalOceanApplication hosting and managed database (where your account data and stored documents reside).
GoogleAuthentication, Gmail access, and delivery of messages you approve for sending, at your direction.

We do not share aggregated or anonymized Google user data with any party — as stated in Section 2, we do not create it.

The one other category of recipient is the people you choose to email: when you approve an outbound message, its contents go to the recipients shown to you on that draft, and to no one else.

We may also disclose information to comply with law, enforce our agreements, or protect the rights, safety, and security of users and the public. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; Google user data would be transferred only with your explicit prior consent, and we will notify you and give you the opportunity to delete your data before any such transfer.

6. Storage & security

Your data is stored on managed infrastructure operated by DigitalOcean in the United States. We protect it with the following safeguards:

Incident response. We maintain procedures to detect, investigate, and remediate security incidents. If a breach affects your personal information, we will notify you and the applicable regulators as required by law and without undue delay.

No method of transmission or storage is perfectly secure, but we work to protect your data and to limit what we collect in the first place.

7. Retention & deletion

We keep data only as long as we need it to provide the Service to you. Specific retention periods:

DataRetention
Gmail access and refresh tokensUntil you disconnect Gmail or revoke access at Google, at which point they are deleted immediately.
Gmail message content and attachments filed to a dealFor as long as your account is active, so the documents stay available in your deal records.
Extracted transaction details (parties, key dates, document types)For as long as your account is active.
Copies of messages you approved and sentFor as long as your account is active, as your record of outbound activity on a deal.
Non-content records for ignored messages (a message identifier and an “ignored” status)For as long as your account is active; used only to avoid re-processing the same message. No sender, subject, or body is kept.
Account informationFor as long as your account is active.
Server logs and product usage eventsUp to 90 days.

Disconnecting Gmail

You can disconnect Gmail at any time from within the Service. This immediately deletes our stored Google tokens and stops all further inbox access and all ability to send on your behalf. Deal records and documents already created from your inbox are kept so you do not lose your work; you can delete them individually in the Service, or request deletion of all of them using the process below. You can also revoke our access directly at myaccount.google.com/permissions.

Deleting your data or account

You can request deletion of your Google data, or of your entire account, by emailing [email protected]. We will confirm the request and complete it within 30 days. Deletion removes your account information, extracted deal records, stored documents and attachments, sent-message copies, and any remaining Google tokens from our live systems. Residual copies in encrypted backups are purged on our normal backup rotation within 90 days of your request and are not accessed in the meantime.

We retain data beyond these periods only where the law requires it, and only for as long as that obligation lasts.

8. Your rights & choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Residents of the EEA/UK (under the GDPR) and California (under the CCPA/CPRA) have specific rights; we honor these requests and do not discriminate against you for exercising them. To make a request, contact us at the address below.

9. Children

The Service is intended for professional use by adults and is not directed to anyone under 18. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date, and we will provide additional notice for material changes.

11. Contact us

Questions or requests about this policy or your data? Contact us at [email protected].