NbotaiOS privacy notice
Clear use.
User control.
Effective July 29, 2026. This notice covers the NbotaiOS public website, contact flow, optional Google OAuth connection for Gmail, and the deployment-specific third-party connectors described below. A deployed NbotaiOS tenant may also have a separate agreement and environment-specific notice.
Information you submit
The contact form asks for name, work email, organization, request type, message, and consent. Do not submit credentials, private tenant content, regulated records, or confidential project files.
Operational information
The website host and delivery providers may process standard request information such as IP address, user agent, requested URL, timing, security signals, and errors to deliver, secure, and diagnose the site.
Google account data accessed
The Google connection is optional. NbotaiOS accesses Google account data only after a user chooses to connect Gmail and grants permission on Google's OAuth consent screen. NbotaiOS does not receive the user's Google password.
- Mailbox identity, including the connected email address and Gmail profile needed to identify the account.
- Message data needed to display and synchronize mail, including message identifiers, headers, senders, recipients, subjects, bodies, labels, folder state, drafts, and attachment information or content when requested.
- OAuth access and refresh tokens needed to keep the user-authorized connection working.
Google permission and purpose
https://www.googleapis.com/auth/gmail.modifylets NbotaiOS read, synchronize, display, organize, archive, mark, move, draft, and send Gmail messages for the connected mailbox.
NbotaiOS uses this data only to provide user-requested mail features, maintain the connected mailbox state, secure and troubleshoot those features, and comply with applicable law. Sending, replying, forwarding, and provider-changing actions occur only after a user chooses or separately approves the action. It is not used to build advertising profiles.
AI-assisted mail features
When a user explicitly requests a visible mail feature such as summarizing a message or thread, proposing a reply, triaging mail, or extracting action items, NbotaiOS may send the selected mail content and the user's instruction to an AI model enabled for that tenant. The result is returned to the requesting user inside the mail workflow. NbotaiOS does not use Google user data to train generalized or non-personalized AI models, and it does not permit an AI provider to use that data for unrelated model training or advertising.
Deployment-specific third-party connectors
Signing in to NbotaiOS does not connect a third-party provider. Each connection must be enabled separately for a deployment and authorized by the user or tenant administrator. Availability, supported actions, retention, and revocation depend on the provider configuration and the tenant's environment-specific agreement or notice.
- Microsoft / Outlook: after Microsoft OAuth approval, NbotaiOS may access the approved Microsoft profile and people data, Outlook messages, mailbox state, and attachments. Current mail permissions include
offline_access,User.Read,People.Read,Mail.ReadWrite,Mail.Send,Mail.ReadWrite.Shared, andMail.Send.Shared. The data is used to display, synchronize, organize, archive, draft, send, reply to, or forward mail inside the active tenant workflow. - Procore: on an authorized and configured deployment, NbotaiOS may import permitted company and project identifiers, submittal status, review and approval metadata, attachment metadata, and selected attachment content. The data is used to organize, scan, validate, and reconcile project documents locally.
- ConstructConnect: with an authorized account and configured tenant session, NbotaiOS may collect permitted project and opportunity details, events, contacts, bid packages, documents, and source responses. The data is used to track changes, classify bid packages, evaluate trade fit, prepare bid or no-bid recommendations, index documents, and summarize analytics.
Where connector credentials, OAuth tokens, or authorized session state are required, they are kept in owner-scoped tenant storage with restricted access. The public website does not receive connector credentials or private tenant records.
Local storage and security
OAuth tokens are stored in owner-scoped NbotaiOS tenant storage with private file permissions. Synced mail records and user-requested archives are stored inside that user's local or owner-managed NbotaiOS environment. Google API requests use encrypted HTTPS connections. Access is limited to the connected user, authorized tenant operations, and processes needed to provide the requested mail feature.
Sharing, sale, and Limited Use
NbotaiOS does not sell Google user data, use it for advertising, or transfer it for unrelated purposes. Google user data is shared only when necessary to provide or secure a user-requested feature, when the user initiates or consents to the transfer, or when required by law.
NbotaiOS's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention, deletion, and revocation
OAuth tokens are kept while the Gmail account remains connected. Removing the mail account in NbotaiOS deletes the locally stored OAuth tokens and stops future Google access. A user can also revoke access from their Google Account connections. Synced messages or archives already stored in the owner's NbotaiOS environment remain under that owner's retention controls until they are deleted; disconnecting Google does not silently delete owner-managed records.
How public-site information is used
- Respond to access, demo, deployment, support, privacy, or security requests.
- Operate, secure, troubleshoot, and improve the public website.
- Meet legal obligations and prevent misuse.
Providers and transfer
The public site is delivered through Cloudflare Pages. A configured contact-delivery provider processes form submissions only to deliver the request. Google and Microsoft process OAuth and mail API requests under their own terms. Procore and ConstructConnect process authorized project requests under their own terms when configured for a tenant. Provider configuration can change; contact us for the current list relevant to your request.
Retention and choices
Contact information should be retained only as long as needed for the request, relationship, security, or legal obligation. Use the contact form with request type “Support” to ask for access, correction, or deletion, subject to applicable law and necessary records.
Your privacy requests
Use the contact form with request type “Support” or email info@nbotaios.com to ask for access, correction, export, or deletion, subject to applicable law and necessary records.
Changes
Material updates will change the effective date and appear in the public release record.