Publication draft · operator details and legal review required
Privacy Policy
This notice explains how AI Email Automation accesses, uses, stores, and shares information when you use the Google Sheets add-on and its optional integrations.
Updated 24 September 2026
1. Scope and operator
This policy applies to the AI Email Automation Google Sheets add-on and its promotional website. The legal name, registration details, and privacy contact of the organization operating the service must be inserted before this draft is published for OAuth review. The Yala reference policy identifies a different product and is not the identity of this add-on by default.
The Google account holder who installs the add-on controls the spreadsheets and recipient lists used for campaigns. The sender is responsible for the lawfulness of those lists, message content, consent where required, and requests received from recipients.
2. Information we access
The add-on accesses the signed-in sender’s email address; the Google Sheets files and cells needed for contact lists, templates, campaigns, settings, queues, and reports; files created or selected for email attachments in Google Drive; and the data needed to send mail on the user’s behalf.
Gmail read-only access is used to detect replies and bounce notices for campaign follow-ups and reports. The implementation reads matching message metadata, such as sender and subject; it does not use Gmail access to send mail or export the mailbox. Google Analytics read-only access is used only if you connect a GA4 property.
The add-on also uses Apps Script permissions to show its interface, run scheduled campaign steps, and make requests to the selected external services. These are the purposes for the Google permissions requested during authorization.
3. Information you provide and where it is kept
Contact rows, email addresses, message templates, campaign definitions, settings, and send activity are kept in the Google spreadsheet under the user’s Google account, including supporting or hidden tabs. Attachments are kept in Google Drive. This product does not require a separate imported marketing audience for the basic workflow.
If you add an OpenAI API key, the add-on stores it in Apps Script document properties associated with the spreadsheet, not in a visible sheet cell. The key is used for your optional AI requests. Access to a shared spreadsheet and its associated resources should be managed through Google permissions.
4. How information is used
We use the information described above to prepare personalized email from your sheet, send messages you authorize through your Google account, run scheduled follow-ups, detect supported replies or bounces, and present reports. The add-on does not sell recipient data or use Google user data for advertising or credit scoring.
The add-on may send operational notices to the signed-in sender, such as test emails or a request to reauthorize a scheduled campaign. Website analytics, marketing cookies, and separate billing records are not described as active processing here; if introduced, this notice must be updated before those uses begin.
5. Optional AI and OpenAI
AI writing is optional and requires the user’s own OpenAI API key. When a user invokes AI, the prompt, current subject or message text, relevant editor context, and the names of available sheet columns are sent to OpenAI to produce the requested copy. The add-on does not automatically insert contact-row values or Gmail inbox bodies into those prompts; text a user manually includes in a prompt or template may still be sent.
If the user marks an attachment as AI context, the selected Drive file is uploaded to OpenAI and indexed in a vector store so the generation can use it. This is distinct from attaching a file to an outgoing email. OpenAI processes the submitted content under its own terms and the user’s API account. Removing context can remove the associated vector store; retention of uploaded files and provider-side records remains subject to OpenAI’s policies and should be reviewed by the user.
6. Optional Google Analytics 4 measurement
If a user connects a GA4 property, the add-on can use that property to estimate email opens and clicks. Measurement may use a tracking pixel, campaign parameters, and a hashed recipient identifier. A hash can still be linkable to a contact in the sender’s sheet and should not be treated as anonymous data.
The add-on reads the connected GA4 property to show available results; it does not claim that every open or click can be measured. Email clients and privacy protections can block or distort those signals. Users should consider recipient notices and applicable legal requirements before enabling measurement.
7. Sharing and third parties
Google processes data through Sheets, Gmail, Drive, Apps Script, and, if enabled, Analytics. OpenAI receives only the optional AI requests and selected AI-context files described above. Email recipients receive the messages and any attachments the sender chooses to send.
A Drive attachment can be made available to “anyone with the link” only when the user enables that sharing option. The sender should check the intended audience and sensitivity of a file before making it public. We do not sell Google user data or transfer it to data brokers or advertising platforms.
8. Google Workspace Limited Use
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Access, use, and transfer of this data are limited to the user-facing functionality described here, security, or legal obligations as permitted by that policy.
Google user data is not used to train or improve a general-purpose machine-learning or AI model. Human access to Google user data is restricted to the circumstances allowed by the Google Workspace policy, such as specific user consent, security, or legal requirements. This statement is a product commitment, not an independent certification.
9. Retention, deletion, and your choices
The sender can edit or delete contact rows, supporting data, attachments, and the spreadsheet through Google products; uninstall the add-on; and revoke its authorization from Google Account permissions. Revoking access stops future authorized operations, but does not automatically delete spreadsheet files, messages already sent, GA4 events, or data held by an optional third-party provider.
Retention of a connected GA4 property follows that property’s settings. Retention of OpenAI submissions and uploaded context files follows the provider’s applicable terms and deletion controls. The operator must document any separate website, billing, or support retention periods before launch.
10. Security
The add-on uses Google account permissions and keeps the optional OpenAI key in Apps Script document properties instead of a spreadsheet cell. Users should restrict spreadsheet sharing, protect their Google account, and review any public attachment links. No internet-connected service can promise absolute security.
A production policy must identify the responsible operator and its incident-response contact. This draft does not claim a security certification, a completed independent assessment, or guaranteed compliance with LGPD or GDPR.
11. Your privacy rights and contact
Depending on applicable law, people may request access, correction, deletion, restriction, portability, objection, or information about processing. Requests about recipient data stored in a sender’s spreadsheet should be directed to that sender first, because the sender controls the list. Requests concerning data processed directly by the service operator require a published privacy contact.
Before publication, add a monitored privacy/support email and the operator’s legal identity here. Users may also contact their competent data-protection authority where applicable. This draft is not a substitute for a legal assessment of the sender’s or operator’s obligations.
12. Children, changes, and external links
The service is intended for professional email workflows and is not designed for children. Links to Google, OpenAI, or other external services lead to their own policies and terms.
Material changes to the way Google user data is accessed or used should be disclosed here and, where required, presented to users for renewed consent before the new processing begins. The publication date above should be updated whenever this policy changes.