Privacy Policy
Northmark Automation · northmark.ai · Effective 21 September 2026
The short version: Northmark Automation is a single-operator tool that acts on its operator's own Google Workspace account, on his own machine. It has no other users, no server, and no third party to share anything with. Nothing is sold, and nothing is used to train machine-learning models.
Who we are
Northmark Automation is a personal command-line tool operated by Matthew Miller. It is not a commercial product and is not offered to anyone else. You can reach us at privacy@northmark.ai.
Whose data this is about
The operator's own. The tool authorizes against one Google account and acts only within it. There is no second user whose data could be collected, and no mechanism for anyone else to authorize the app.
What it accesses, and why
The tool requests the Google Workspace permissions below. Each is used only to do the work described on the home page.
- Gmail — read (
gmail.readonly). To read message metadata and content in order to decide what is stale. - Gmail — modify (
gmail.modify). To archive threads and apply labels. This scope cannot permanently delete mail; full-mailbox access (mail.google.com) is deliberately not requested, and an automated check fails if it is ever granted. - Calendar — read only
(
calendar.events.readonly). To read upcoming entries for the daily briefing. The tool cannot create, change or cancel events. - Sheets (
spreadsheets). To read and update spreadsheets the operator already owns, as part of scheduled reporting. - Basic profile and email address (
openid,userinfo.email,userinfo.profile). To identify which account the stored credential belongs to.
That is the complete list. The tool does not request Drive, Docs, Slides, Tasks, Contacts, or any Google Cloud scope, and it holds no write access to Calendar.
Where data goes
Nowhere. The tool runs locally and talks only to Google's own APIs. There is no Northmark server, no database, and no analytics. Data read from Google is used in the moment and not retained, except where the operator's own scheduled jobs write output into files he owns — in his own Google Drive, or on his own machine.
Credentials
The OAuth refresh token is stored encrypted on the operator's machine (AES-256-GCM, with the key held in the operating system keyring). It is never transmitted anywhere other than Google's token endpoint.
What we never do
- No selling or sharing of data — there is no one to share it with.
- No advertising, no ad networks, no tracking.
- No use of Google user data to develop, improve, or train generalized machine-learning models.
- No human reads Google user data, other than the operator reading his own.
Limited Use
Northmark Automation's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
No copy of Google user data is retained by the tool itself. Authorization can be revoked at any time from the operator's Google Account permissions page, which immediately invalidates the stored credential.
Changes
If this policy changes in a meaningful way, we will update this page and the effective date above.