Privacy Policy
Last updated: 2026-10-06
ATLASS OS is a business operating system for trades and field-service companies, built in Alberta, Canada. This policy explains what information we handle, why, who can see it, how long we keep it and how to have it removed. Section 4 explains, in full, what happens to your Gmail data if a business connects its own mailbox.
1. Who this covers
This policy covers the ATLASS OS website and application at app.atlass-os.com, and the satellite apps and phone line that connect to the same account.
ATLASS OS is used by businesses. When a business puts its own customers' information into ATLASS OS, that business decides what to enter and why, and we process it on the business's behalf to provide the service. If you are a customer of one of our customers, ask that business first about your information; you can also write to us at the address in section 10.
2. Information we handle
- Account information: your name, your work email address, a one-way hash of your password (we never store your password in readable form) and your role in your business.
- Business records that you or your team enter or import: customers, contacts, jobs, documents, accounting entries, photos and notes.
- Billing information: card details are handled by our payment processor and are not stored by us; we keep the subscription status.
- Activity records: a log of who changed what and when, so a business can audit its own books, and server logs that keep the service secure and working. Our rules forbid writing passwords, access tokens or message contents into logs.
- Information from Google, only if the owner or an administrator of a business chooses to connect Gmail. Section 4 describes it in full.
3. How we use information
We use information to provide and run ATLASS OS for the business that entered it, to keep the service secure, to give support when you ask for it, to meet our legal obligations and to improve the features you can see and use in the product.
We do not sell personal information. We do not use customer data for advertising.
4. Google user data and Gmail
This section applies only when the owner or an administrator of a business chooses Connect Gmail under Settings, Email, and approves Google's own consent screen. Nothing in it happens to a mailbox that has not been connected this way.
4.1 What we ask Google for
ATLASS OS asks Google for the following permissions, shown to you word for word on Google's consent screen. Google's own description of each is quoted below.
https://www.googleapis.com/auth/gmail.readonlyGoogle describes it as: “View your email messages and settings.” We use it for: Reading incoming mail so it can be filed to the right customer.https://www.googleapis.com/auth/gmail.modifyGoogle describes it as: “Read, compose, and send emails from your Gmail account. This scope does not allow immediate, permanent deletion.” We use it for: Labelling the mail it has taken in, moving a message you choose out of Spam, and sending your own documents from your own address.
We ask for nothing else from your Google account. In particular we do not ask to permanently delete mail, to see your contacts, calendar or files, or for your profile.
4.2 What we use it for
We use the access only to provide these features, each of which is visible in ATLASS OS when you use it:
- Filing your incoming mail: each message appears in the business's inbox and on the timeline of the matching customer or contact. Once automatic import is enabled for your business (today, on request), new mail is imported about every two minutes from the moment it is switched on. You can also run a history import over a date range you choose, or with no dates at all to work through the whole mailbox.
- Labelling: we create two labels in your mailbox and tag each message we import with one of them, so you can see in Gmail what ATLASS OS has taken in.
- Spam Recovery: when you ask, we list the sender, subject and date of messages in your Spam folder, mark the ones that match a known customer, contact or vendor, and move a message to your Inbox only when you press Recover.
- Sending: where your business has switched on sending through Gmail (today, on request), every email ATLASS OS sends on the business's behalf goes out from your Gmail address. That covers invoices, estimates and other documents; payment reminders; marketing and follow-up campaigns and outreach; team invitations; notifications to you (new leads, text-message attachments, call summaries and voicemails); bank-reconciliation reports; and the verification and notice emails sent to people you share documents with. It includes emails sent on a schedule your business configured, such as follow-up sequences and reminders. With sending switched off, none of these use your mailbox.
- Checking the connection: we ask Google which mailbox a sign-in opens, so a sign-in for one mailbox can never be saved as another.
The automatic import skips Spam, Trash, Promotions and Social mail and follows the allow and deny rules the owner sets by sender or domain; a message a rule excludes is read only long enough to apply the rule and is then discarded without being stored. A history import you start applies no sender rules and does not skip Promotions or Social mail; Gmail itself leaves Spam and Trash out of the list it returns.
4.3 What we store
- From the automatic import, for each message: the sender, the subject, the date, Google's message and thread identifiers, and a short excerpt of the plain text (up to the first 1,000 characters). It does not store the recipients or the HTML.
- From a history import you start, for each message: the sender and recipients, the subject, the date, Google's identifiers, the label identifiers, the names and types of any attachments, and the full text and HTML of the message. Attachments themselves are never downloaded.
- For each message we send from your address: the recipient, your address and Google's message identifier, in the business's audit log. The subject and body are deliberately not copied there.
- Your Google sign-in credentials (an access token and a refresh token), the mailbox address, the permissions granted and their expiry. The tokens are encrypted before they are stored.
- Everything above is stored under the one business account that connected the mailbox, and every read and write of it is limited to that business.
4.4 How we protect it
Google sign-in credentials are encrypted with AES-256-GCM before they are stored, and the service refuses to read or write them if the encryption key is missing. Traffic between your browser, our service and Google is encrypted in transit. Each business's records are kept separate from every other business's records, and changes to connections are written to an append-only audit log that never contains a token.
4.6 Artificial intelligence
Mail brought in from Gmail becomes part of your business's inbox and customer timeline, so the AI features of ATLASS OS can read it when a person asks them to. There are three ways, and only these three, in which text that came from Gmail reaches an AI provider or an AI client:
- The in-app assistant. When a user of your business asks the assistant a question whose answer needs your activity records or customer timeline, the assistant reads those records and sends what it read to our AI model providers (the companies whose models run the assistant) so the model can write the answer. For mail that came from Gmail this can include the subject, a short stored excerpt (up to the first 1,000 characters of the plain text) and, for mail brought in by a history import, the whole stored record: sender, recipients, subject, date, the full text and the HTML.
- A connected AI client. If a user of your business connects an AI client to their ATLASS OS account and that client asks for the business's inbox, it receives the inbox messages, including the stored excerpt of mail that came from Gmail. That transfer goes to the client your business chose, at the request of your user.
- Background classification. A separate background pass can send a record's subject or excerpt to our AI model provider to tag the people and topics it mentions, but it works only on records queued for it, and the Gmail importers do not queue the records they write.
These transfers happen to provide the answer a user asked for inside the product, and not otherwise: the automatic import, the history import, the labelling, Spam Recovery and sending do not send mail to an AI provider. We do not use Google user data to develop, improve or train artificial intelligence or machine-learning models, and we do not authorize our AI providers to use it to train theirs. These transfers are part of the user-facing features of ATLASS OS and are subject to the Limited Use requirements in 4.9.
4.7 Who can read your messages
ATLASS OS staff do not read the content of your Gmail messages. We will do so only if you ask us for support on a specific message and agree, where it is necessary to investigate abuse or a security problem, or where the law requires it.
4.8 How long we keep it, and how to delete it
- Imported message records are kept for as long as the business's ATLASS OS account is active, because they are part of the business's customer history.
- You can withdraw our access at any time at Google Account permissions (see the link below). From that moment we can no longer read or send; stored credentials become useless to us and Google refuses them.
- You can ask us to disconnect your mailbox. We then delete the stored credentials.
- You can ask us to delete the copies of your mail that we hold. We will do so within 30 days of a request from the business's owner or an administrator, and confirm when it is done.
- To make either request, write to the address in section 10 and say which mailbox and business you mean.
Withdraw access any time: Google Account permissions
4.9 Google API Services User Data Policy
ATLASS OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means: we use Google user data only to provide or improve the user-facing Gmail features described in 4.2; we transfer it to others only as 4.5 allows, which includes the AI transfers in 4.6 made at a user's request; we do not let people read it except as 4.7 allows; and we do not use it for advertising or to train generalized AI models.
6. Security
Each business's data is kept apart from every other business's data. Access inside a business is limited by role. Sensitive values such as sign-in credentials are encrypted before they are stored, and changes to important records are written to an audit log that cannot be edited afterwards. No system is perfectly secure; if we learn of a breach that affects your information we will tell the affected business promptly.
7. How long we keep information
We keep a business's records while its account is active and for as long as the law requires a business to keep its books. Owners can export a full backup of their business's data at any time.
8. Your choices and rights
You can ask us what personal information we hold about you, ask us to correct it, ask us to delete it, and withdraw a consent you gave. For information a business holds about its customers, we will pass your request to that business and help it respond. Write to the address in section 10.
9. Children
ATLASS OS is business software and is not directed to children.
10. Changes, and how to reach us
When we change this policy we post the new version here and update the date at the top. If a change affects how we use Google user data, we will tell connected businesses before it applies.
Questions, privacy requests and deletion requests: