Privacy Policy

Last updated: May 19, 2026. This policy explains how Visibu collects, uses, stores, and deletes data when you use our product, including when you connect Google accounts and grant Gmail access.

1. What we do

Visibu helps construction business owners turn team email activity into a structured project timeline. Teams continue using Gmail as normal while Visibu reads connected mailboxes and organizes communication by project and phase so leadership can track operational progress.

2. What Gmail data we access

For personal Gmail connections, Visibu requests Google OAuth scopes that include Gmail read-only access plus basic identity scopes for account linking. For Google Workspace connections, admins authorize read-only mailbox access needed for timeline functionality.

  • Data read can include sender and recipient fields, subject lines, timestamps, snippets, and message content.
  • We use thread identifiers to group related messages in timeline views.
  • Attachment names and metadata may be processed for timeline context.
  • We do not use Gmail access to modify, delete, or move email messages.

3. How Gmail data is used

Gmail data is used to identify project-relevant communication, structure timeline records, power search and watch workflows, and provide operational summaries inside the product.

  • We do not use Gmail data for advertising.
  • We do not sell Gmail data.
  • We do not share raw Gmail content with third parties except processors needed to deliver the service.
  • Access to message content is primarily automated; human review is limited to approved support, security, or legal cases.

4. Storage and protection

We use technical and organizational safeguards designed to protect customer data. OAuth credentials and integration secrets are encrypted at rest. Data in transit is protected using HTTPS/TLS connections between clients, services, and APIs.

  • OAuth tokens are encrypted at rest and handled separately from application data.
  • Encryption keys are managed separately from primary data stores.
  • We are rolling out stronger key management and token-rotation controls.
  • Operational access is restricted to authorized systems and personnel.

5. Sharing and processors

We share data only with service providers that help us operate the product (for example, infrastructure, authentication, and AI processing vendors) and only as needed to provide requested features.

  • Google APIs are used to retrieve authorized Gmail data.
  • AI processors may receive email text temporarily to classify timeline events and generate insights.
  • Infrastructure providers process encrypted data and system telemetry for service operation.
  • We do not share Gmail data with data brokers or advertising networks.

6. Retention and deletion

Data is retained for as long as needed to deliver the service, comply with legal obligations, and keep system integrity.

  • Disconnecting Gmail in Visibu stops future mailbox reads for that integration.
  • When integrations are disconnected, associated access tokens are removed from active use.
  • You can request account-level deletion by contacting us.
  • We are implementing faster purge workflows, including primary and backup deletion targets.

7. Security and compliance commitments

We maintain ongoing security controls for authentication, access monitoring, and abuse prevention. We are implementing additional controls including expanded key rotation, stronger retention automation, and incident response playbooks with user notification processes.

8. Google API Services User Data disclosure

Visibu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google API data is used only to provide and improve user-facing product features described in this policy.

9. Changes to this policy

We may update this policy as product and legal requirements evolve. Material updates will be reflected on this page with a revised date.

10. Contact

For privacy and data requests, contact: milo@visibu.app.