Trust & Transparency

Privacy Policy

We are committed to protecting your privacy and ensuring you have complete control over your personal information and connected services.

Last Updated: September 10, 2026Effective Date: September 10, 2026

Google API Services User Data Policy & Limited Use Disclosure

ConnectWhole's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models. Google data is strictly used to provide personalized email sending and outreach management explicitly requested by you.

1. Introduction

ConnectWhole ("we," "our," or "us") operates the ConnectWhole platform, available at https://connectwhole-frontend-1070428613852.asia-south1.run.app and associated subdomains. This Privacy Policy details the types of information we collect, how we handle and protect it, and the choices available to you regarding your data.

2. Information We Collect

We collect information to provide, personalize, and improve our outreach automation platform:

Account Information

Your name, email address, password hash (encrypted via bcrypt), and profile preferences provided during registration.

Resumes & Documents

Resumes, cover letters, and documents uploaded by you for email attachments. Stored privately and securely in isolated Google Cloud Storage buckets.

Google Account Data

When you connect a Gmail account via Google OAuth 2.0, we obtain OAuth tokens and your authorized email address. We never see or store your Google account password.

Outreach & Interaction Data

Recipient email addresses, email subjects, sending timestamps, email open signals, and reply status necessary to power analytics.

3. How We Use Google User Data

ConnectWhole requests specific Google OAuth scopes strictly to fulfill user-initiated actions:

  • `https://www.googleapis.com/auth/gmail.send`: Used exclusively to send emails on your behalf from your connected Gmail address when you click "Send" in ConnectWhole.
  • `https://www.googleapis.com/auth/gmail.readonly` or user profile scopes: Used to display your sender address and monitor replies to your outreach campaigns.

Our Guarantees Regarding Google Data:

No selling or renting of Google user data
No advertising or behavioral targeting
No training of public or third-party AI models
AES-256 token encryption at rest

4. AI Email Generation (Google Gemini)

When you use our AI writing assistant, your prompt and context (such as recipient role or company name) are sent to the Google Gemini API to generate the email draft. We do not use your proprietary emails to train foundational AI models.

5. Data Security & Storage

We employ enterprise-grade security protocols hosted on Google Cloud Platform:

  • Encryption in Transit: All web traffic is strictly encrypted using HTTPS / TLS 1.3.
  • Encryption at Rest: Database records and files in Cloud Storage are encrypted using Google-managed encryption keys.
  • OAuth Token Security: Sensitive Google OAuth refresh tokens are encrypted in the database using Fernet / AES symmetric encryption.
  • Multi-Tenant Isolation: Data access is strictly segmented by authenticated user IDs.

6. Revoking Access & Data Deletion

You maintain full control of your connected accounts and stored data:

  • Disconnect Gmail in ConnectWhole: Navigate to Email Accounts in your dashboard and click Disconnect to instantly purge all stored OAuth tokens.
  • Revoke via Google Account: You can independently revoke ConnectWhole's permissions at any time via Google Account Permissions.
  • Complete Account Deletion: You may request complete erasure of your account, contact history, and uploaded resumes by contacting our privacy team.

7. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our compliance with Google API policies, please reach out to us: