Privacy Policy
How ByteBack collects, uses, protects, disconnects, and deletes your data — including Google/Gmail data authorized through OAuth.
Last updated: July 10, 2026
Gmail data is used only for user-facing inbox, classification, CRM, and task features.
Disconnect one mailbox or all connected Google accounts from Account & Data settings.
Permanently delete your account and associated workspace data from settings.
What ByteBack does
ByteBack is an enterprise AI-powered Unified Inbox and Customer Communication Platform. It enables organizations to connect multiple email accounts from Gmail, Google Workspace, Microsoft 365, Outlook, and other supported providers into one intelligent inbox. The platform helps users manage customer communications, generate AI-powered summaries, organize conversations, create CRM records, assign follow-up tasks, and improve response times.
This Privacy Policy explains what information ByteBack ("we", "us", "our") collects, how we use it, and the choices you have. By using the Service you agree to this policy.
1. Information we collect
Account data
When you sign up we collect your name, email address, workspace name, and authentication identifiers. Passwords are hashed by our authentication provider and are never accessible to us in plaintext.
Connected email accounts
When you connect a Gmail, Google Workspace, Outlook, Microsoft 365, IMAP, or other supported email service provider to ByteBack, we access:
- Message metadata (sender, recipient, subject, date, thread id, labels)
- Message bodies (plain text and HTML) required to power inbox and AI features
- Your email address and basic profile from the OAuth provider
We request the minimum OAuth scopes required for the features you enable. Additional scopes (such as send or modify) are requested only if you enable features that need them, and always with an explicit user consent screen.
Usage data
We collect standard product analytics (pages visited, features used, errors) to improve the Service. We do not sell this data.
2. How we use your data
- To provide the unified inbox and analyze customer conversations to provide AI-powered summaries, categorization, CRM timelines, and productivity features
- To create follow-up tasks and send you notifications
- To secure your account and detect abuse
- To provide customer support
We do not train AI models on your email content. AI inference is performed by authorized AI processing providers operating under zero-retention agreements — your data is not stored or used for training by these providers.
3. Google Workspace data
ByteBack accesses Gmail and Google Workspace data only after explicit user authorization via Google OAuth, to provide the following user-facing features: Unified Inbox, AI-powered summaries and categorization of customer conversations, CRM timeline generation, follow-up reminders, and email management features.
Specifically, we access:
- What: message metadata (sender, recipient, subject, date, thread id, labels) and message bodies (plain text and HTML) from mailboxes you connect.
- Why: to display incoming messages in the unified inbox, analyze customer conversations with AI, generate CRM contacts and timelines, and create follow-up tasks and reminders.
- Which features use it: Unified Inbox, AI Summaries & Categorization, CRM & Timeline, Tasks & Follow-ups, Analytics (mailbox health, response time, inbox activity, and productivity metrics), Notifications.
AI processing
Email content may be processed to generate AI summaries, categorization, and productivity features (such as suggested next actions and follow-up drafts).
Google Workspace data is never used to train generalized AI models. AI inference is performed by authorized AI processing providers operating under zero-retention agreements — your data is not stored or used for training by these providers.
Google Limited Use statement
The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google Workspace data to provide user-facing features in the ByteBack app (unified inbox, AI summaries and categorization, CRM, tasks, analytics).
- We do not transfer Google Workspace data to third parties except as required to provide the Service, comply with law, or with your explicit consent.
- We do not use Google Workspace data for serving advertisements.
- We do not allow humans to read Google Workspace data unless you explicitly grant permission for support, we need to for security or to comply with the law, or the data is aggregated and anonymized for internal operations.
Google OAuth scope justification
Each scope we request from Google is used only for the following purpose:
https://www.googleapis.com/auth/gmail.readonly— read incoming messages in the connected mailbox so ByteBack can display them in the unified inbox, analyze customer conversations, and create CRM contacts and follow-up tasks.https://www.googleapis.com/auth/gmail.sendandhttps://www.googleapis.com/auth/gmail.modify— requested only if you enable reply, compose, or mailbox-action features. Depending on the permissions explicitly granted by the user, ByteBack may allow composing, sending, replying to emails, and performing mailbox actions such as marking messages as read or applying labels. These actions occur only after direct user initiation.https://www.googleapis.com/auth/userinfo.email— identify which Google account the user connected, so we can label the mailbox in the app and prevent duplicate connections.https://www.googleapis.com/auth/userinfo.profile— display the connected account's name in the ByteBack UI.openid— standard OpenID Connect sign-in for identifying the Google user.
4. Data storage and security
- All data is encrypted in transit (TLS 1.2+) and at rest.
- OAuth refresh tokens are stored encrypted (AES-256-GCM) in an isolated secrets vault.
- Row-level security enforces strict workspace isolation.
- Hosted on hardened cloud infrastructure with regular security review.
5. Data retention
- Synced emails: messages fetched from connected mailboxes are retained for as long as the mailbox remains connected and your ByteBack workspace is active, so classification, CRM timelines, and search continue to work.
- On mailbox disconnect: messages synced from that mailbox are purged from our primary database within 30 days of disconnect.
- On account deletion: all workspace data — emails, contacts, tasks, notes, pipeline, notifications, AI embeddings — is deleted immediately from the primary database.
- Backups: encrypted backups are retained for up to 30 days for disaster recovery, after which deleted data is fully purged from backups as they roll off.
- Account & billing records: minimal account records (name, email, invoices) may be retained as required by applicable tax and accounting law.
6. Data deletion
You have full control over your data at any time:
- Disconnect Google: revoke a single mailbox or all connected Google accounts from Settings → Account & Data. ByteBack calls Google's OAuth revoke endpoint, deletes the stored refresh token, and stops all Gmail syncing.
- Delete synced emails: disconnecting a mailbox purges the messages synced from it within 30 days.
- Delete account: permanently delete your entire ByteBack account and all workspace data from Settings → Account & Data → Delete my account.
- Request deletion: if you cannot access the app, email info@byteback.co.in and we will action the request within 30 days.
Disconnect a Google / Gmail account
You can disconnect any connected mailbox at any time from Settings → Account & Data → Disconnect all Google accounts, or individually from Email Sources. When you disconnect, ByteBack immediately calls Google's OAuth revoke endpoint (https://oauth2.googleapis.com/revoke), deletes the stored refresh token from our database, stops all Gmail syncing, and purges any messages synced from that mailbox within 30 days. You can also revoke ByteBack directly from your Google Account at myaccount.google.com/permissions.
Delete your entire ByteBack account
Go to Settings → Account & Data → Delete my account, type DELETE to confirm, and press Permanently delete. This immediately and irreversibly:
- Revokes every connected Google OAuth token
- Deletes all OAuth connection records
- Deletes every workspace you own and all data inside it — emails, contacts, tasks, notes, pipeline, notifications, AI embeddings
- Removes your membership from any shared workspaces
- Deletes your login (auth user) and signs you out everywhere
Backups are purged within 30 days. If you cannot access the app, email info@byteback.co.in and we will action the request within 30 days.
7. Sharing your data
We share data only with subprocessors that help us operate the Service:
- Cloud hosting and database provider
- Google (Gmail API) — only for accounts you connect
- AI inference provider (LLM inference, zero retention)
- Transactional email provider for notifications
We do not sell your personal data. We may disclose data if required by law or to protect the rights, safety, and property of ByteBack, our users, or the public.
8. Your rights
Subject to applicable law (including GDPR and CCPA), you have the right to access, correct, export, or delete your personal data. Contact info@byteback.co.in to exercise these rights.
9. Children
The Service is not directed to individuals under 16 and we do not knowingly collect data from them.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app or by email at least 7 days before they take effect.
11. Contact
Questions? Contact us at info@byteback.co.in.