n8n Gmail TriagePrivate mail automation

Privacy Policy

Last updated 8 September 2026

This policy covers the application registered with Google as n8n Gmail Triage, operated by Pavel Plotnikov as a private, single-operator automation.

1. Who runs this

Pavel Plotnikov, an individual, reachable at pplotnikov2005@gmail.com. He is the sole operator and the sole user. The software runs on servers he controls; no other party administers it.

2. Whose data is involved

Only the operator's own Google accounts are connected. The application has no registration, no customers, and no mechanism by which a third party could attach an account to it. Consequently the only Gmail data it ever touches belongs to the person who runs it — including whatever correspondents have sent to those addresses.

3. What is accessed

Attachments are not opened or downloaded. Contacts, Drive, Calendar and other Google services are not accessed; those APIs are not enabled for the project.

4. What is done with it

A message is fetched, its sender and text are submitted to a language model running on the operator's own infrastructure, the model returns one category, and the corresponding Gmail label is applied. Some categories additionally remove the message from the inbox — the ordinary Gmail "archive", which does not delete anything. That is the entire processing chain.

The classifier is a private endpoint on the operator's server. Message text is not sent to any commercial AI provider, is not used to train or fine-tune any model, and is not retained by the classifier after the response is produced.

5. Retention

Mail is not copied into a separate store. The automation holds message content only in memory for the seconds it takes to classify one message. Execution logs in n8n record identifiers, timestamps and the assigned category, and are pruned on a rolling basis; they are readable only by the operator over an authenticated connection.

Google OAuth tokens are stored encrypted in the n8n credential store on the operator's server and are used for no purpose other than the access described here.

6. Disclosure

None. Data is not sold, rented, licensed, shared, published, or transferred to any third party. There is no advertising, no analytics, no tracking, and no profiling of correspondents. The only circumstance in which data would leave the operator's control is a binding legal demand under applicable law.

7. Limited Use

The application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the labelling feature described above; it is not transferred to others except as required by law; it is not used for advertising; it is not used to develop, improve or train generalised AI or machine-learning models; and no human reads it other than the operator, whose own mail it is.

8. Security

Traffic to Google runs over TLS. The server is access-controlled, the n8n interface requires authentication and is served over HTTPS, and credentials are held encrypted at rest. No system is beyond compromise; in the event of a breach affecting Google user data, the operator would revoke all tokens immediately and notify Google.

9. Withdrawing access

Because the operator is the only account holder, access is revoked by removing the application at myaccount.google.com/permissions. Revocation invalidates the stored tokens at once and the automation stops. Stored tokens can additionally be deleted from the n8n credential store, and log entries purged, on request to the contact address.

10. Children

The application is not directed at children and is not available to anyone but its operator.

11. Changes

If this policy changes, the revised text replaces this page and the date above is updated. There are no other users to notify.

12. Contact

Questions about this policy: pplotnikov2005@gmail.com