Overview
iotoWeb (“we”, “us”) provides an AI assistant platform. This policy explains what data we
access, why, and how we protect it — including data from services you choose to connect, such
as Google (Gmail, Calendar, Drive).
Data we access
- Account data you provide (username, email) to create and secure your account.
- Content you send to the assistant (your messages and prompts) so it can respond.
- Connected-service data, only if you explicitly connect a service via its
official consent screen. For Google this may include reading your Gmail messages, Calendar
events, and Drive file metadata (all read-only).
- Usage metrics (token counts, timestamps) for billing and reliability.
How we use connected data
We use data from connected services solely to provide features you request — for example,
summarizing your inbox, surfacing your schedule, or drafting replies for your review. We access
this data on demand to fulfill your requests. We do not sell it, use it for
advertising, or use it to train generalized AI models.
Google API Services — Limited Use
iotoWeb’s use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve features that are prominent in the
user-facing interface and that the user has requested.
- We do not transfer Google user data to third parties except as necessary to provide or
improve those features, to comply with applicable law, or as part of a merger with adequate
consent.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless we have the user’s affirmative
agreement for specific messages, it is necessary for security or to comply with the law, or
the data is aggregated and anonymized for internal operations.
- We do not use Google user data to train or improve generalized/foundation AI or ML models.
Storage & retention
We minimize what we store. We fetch connected-service content on demand and do not retain
full email or file bodies beyond what is needed to complete the immediate request. OAuth tokens
are stored encrypted at rest and are used only to access the services you
connected. You can disconnect a service at any time, which deletes its stored tokens.
Your controls
- Connect or disconnect any data source at any time from your agent settings.
- Revoke iotoWeb’s access directly at
Google Account permissions.
- Request deletion of your account and associated data by contacting us.
Security
We use encryption in transit (TLS) and at rest for sensitive credentials, access controls,
and audit logging. No method of transmission or storage is 100% secure, but we work to protect
your data using industry-standard measures.