1. Scope and identity
This Privacy Policy applies to the public DiplomaticOne website and to DiplomaticOne software, including Email Router. DiplomaticOne provides office-management tools for diplomatic missions, embassies, international offices and similar organizations. The organization deploying DiplomaticOne decides which users, mailboxes, recipients, routing rules and workflows are configured.
For privacy and OAuth questions, the current contact address is DiplomaticOneD1@gmail.com.
2. Website data
If a visitor submits the website contact form, DiplomaticOne may receive information the visitor chooses to provide, such as name, email address, organization, position, telephone number, country, enquiry type, package interest, preferred reply method and message. The current website uses Formspree to deliver contact-form submissions. This information is used to respond to enquiries, arrange demonstrations, prepare proposals and provide requested information.
The website does not use Gmail data for website analytics, advertising or marketing. Standard hosting and security infrastructure may process ordinary technical data such as IP address, browser type, timestamps and request logs.
3. What Email Router does
Email Router is a local-first desktop application. It connects only to a mailbox that an authorized user or administrator chooses to configure. It can inspect incoming correspondence, classify it against office-defined categories and rules, surface uncertain items for Human Review, identify calendar information, maintain local operational history, and send or forward messages when the configured workflow requires it.
Depending on the mail provider and the enabled features, Email Router may process message headers and metadata, sender and recipient addresses, subject lines, message bodies, message identifiers and threads, labels/read state, dates, attachments needed for supported document-processing features, routing decisions, recipients selected by office rules, and calendar information extracted from correspondence.
Routine processing is performed on the user's workstation or local environment. DiplomaticOne does not operate a central service that routinely receives a copy of every connected mailbox message.
4. Google / Gmail user data accessed
When a user connects Gmail or Google Workspace, Email Router uses Google OAuth and currently requests the restricted scope https://www.googleapis.com/auth/gmail.modify. This scope is used because the application needs a single authorization that can support the user-facing Email Router workflow: reading authorized inbox messages for processing, sending authorized forwards or messages, and updating message state such as removing the UNREAD label after successful processing.
For unread inbox messages selected for processing, Email Router may retrieve the raw email needed to obtain sender, recipients, subject, date, body text, message and thread identifiers, and supported attachment content. It may also read the connected Gmail account address to identify the mailbox the user authorized. Email Router does not scan unrelated Google products such as Google Drive, Google Photos or Google Calendar through this Gmail authorization.
DiplomaticOne's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How Google user data is used
Google user data is used only to provide or improve user-facing Email Router features that the connected user or organization has chosen to use. Specifically, Gmail data may be used to: determine whether an unread message matches an office-defined routing category; display a message for Human Review when the routing decision is uncertain; extract a date or event for the application's local calendar features; prepare and send an authorized forward; record local routing metadata and a short derived operational summary; retry a failed send; and update the original Gmail message's read state after successful processing.
The test/authorization function is intentionally privacy-minimized: it validates authorization and mailbox access without sending a test email, and its connection test does not need to read a message body.
Where a user configures recipients or forwarding rules, the relevant message content may be sent through Gmail to those user-selected or organization-selected recipients. That transmission is part of the user-facing routing feature requested by the organization.
6. Local storage and retention
Email Router stores operational data under the local user profile on the workstation. Different data has different retention because it serves different user-facing functions:
- OAuth authorization tokens: stored locally for the connected mailbox so the user does not need to sign in for every scan. They remain until the authorization is revoked, the mailbox/local token cache is removed, or application data is cleared.
- Routing history: stores lightweight routing metadata and a short derived summary locally. Normal history records are retained for up to 31 days by default; records tied to a future deadline may remain until that deadline is no longer future-facing.
- Human Review: messages requiring a person to decide may be kept locally in the Human Review queue. This may include message text and non-binary attachment metadata needed for review. Raw attachment bytes are not persisted in that queue by the standard persistence mechanism. Review items remain until processed/removed, subject to the application's queue controls.
- Failed forwards: information needed to retry an unresolved send may remain locally until the send succeeds or the item is cleared. Raw MIME and attachment bytes are not persistently stored in the failed-forward queue; the queue is capped for operational safety.
- Calendar extracts, processed-message identifiers and local routing settings: may remain locally until removed through the application's controls, data cleanup, or authorized workstation administration.
Transient message content used for classification can exist in memory during processing even when it is not written to a persistent queue. Retention can also be affected by an organization's own backup, endpoint-management or retention practices outside DiplomaticOne.
8. Uses DiplomaticOne does not make of Google user data
Google user data accessed by Email Router is not:
- sold, rented or licensed to data brokers or advertising networks;
- used for targeted advertising, advertising profiles or personalized marketing;
- used to determine creditworthiness, lending eligibility, insurance eligibility or similar high-impact financial decisions;
- used to build unrelated user profiles;
- used to train, fine-tune or improve general-purpose or generalized artificial-intelligence or machine-learning models;
- made available to humans for routine reading other than the connected organization's own authorized users, or exceptional support explicitly authorized by that organization.
Any future material change to these practices would require an updated privacy disclosure and, where applicable, renewed user consent and Google verification before the changed use is deployed.
9. Credentials and OAuth tokens
Google OAuth allows Email Router to operate without storing the user's normal Google password. Each authorized Gmail mailbox receives its own local OAuth token/cache. In the current Windows implementation, OAuth token-cache content is protected for the current Windows user using Windows Data Protection API (DPAPI). Public OAuth client configuration may be distributed with Email Router, but user access tokens and refresh tokens are created separately for each authorization and are not included in the product distribution package.
For providers that require password-based IMAP/SMTP authentication, Email Router is designed to use Windows Credential Manager rather than storing mailbox passwords in its normal mailbox configuration file.
10. User controls, revocation and deletion
A user can stop Gmail access by removing or disabling the Gmail mailbox in Email Router and/or by revoking DiplomaticOne's Google Account access from the user's Google Account security controls. Revoking Google access prevents new API access using the revoked authorization.
Because Email Router is local-first, revoking OAuth at Google does not automatically erase local operational records already stored on the workstation. An authorized user or administrator can remove the mailbox/token cache and clear or delete local application data using the application's maintenance controls, uninstallation/data cleanup, or authorized workstation administration. Requests for assistance with deletion can be sent to DiplomaticOneD1@gmail.com.
11. Security
DiplomaticOne uses a local-first architecture intended to reduce unnecessary central collection of operational information. OAuth token caches are protected with operating-system facilities on supported Windows deployments. Security also depends on the organization's endpoint controls, operating-system security, mail-provider configuration, user permissions, backup practices and physical access to the workstation.
No system can guarantee absolute security. Organizations should keep systems updated, restrict workstation access, use provider-supported authentication, promptly revoke accounts that are no longer required, and configure routing recipients carefully.
12. Third-party services
DiplomaticOne may interoperate with Google Workspace/Gmail, Microsoft 365/Outlook, Infomaniak and other mail providers selected by the organization. Those providers process data under their own terms and privacy practices. The public website currently uses Formspree for contact-form delivery and Google Fonts for typography. These website services are separate from the Gmail mailbox content processed locally by Email Router.
13. Changes to this policy
This policy may be updated as DiplomaticOne features, provider integrations or legal requirements change. The effective/last-updated date at the top identifies the current version. Material changes affecting Google user data access, use, storage or sharing will be reflected here before or when those changes take effect and, where required, will be subject to renewed authorization or verification.
14. Contact
Questions about privacy, Google OAuth access, data deletion, security or support can be sent to DiplomaticOneD1@gmail.com. Please do not send mailbox passwords, OAuth tokens or unnecessary sensitive message content by email.