Hacala StudioAccount automation

Hacala Studio Account Automation

Privacy policy

Last updated August 24, 2026

1. What this policy covers

This policy covers Hacala Studio Account Automation, a private productivity tool operated by Hacala Studio in British Columbia, Canada. The tool connects only to Google accounts whose owner has explicitly authorized access. It is not offered as a public service.

This policy also covers information submitted through forms on roberthacala.com.

2. Google user data accessed

The automation may access the following data through the Gmail API:

  • Message metadata, including sender, recipients, subject, date, labels, message ID, and snippet.
  • Message bodies and attachments when needed to identify, summarize, send, or forward a message requested by the account owner.
  • Mailbox state, including whether a message is unread.
  • OAuth authorization information, including the Google account address and access or refresh tokens.

The automation does not receive or store the Google account password. It does not request access to Google Drive, Calendar, Contacts, or other Google products unless this policy and the authorization request are updated first.

3. How Google user data is used

Google user data is used only to provide the functions requested by the account owner:

  • Check incoming mail against specific account, security, payment, newsletter, and action rules.
  • Create private alerts, summaries, and digests for the account owner.
  • Forward selected receipts to a designated accounting mailbox.
  • Send operational messages when requested.
  • Mark processed messages as read and prevent duplicate alerts or forwarding.
  • Maintain, secure, and troubleshoot the automation.

Google user data is not used for advertising, profiling for advertising, credit decisions, or training general-purpose AI models.

4. Sharing and transfers

Google user data is not sold, rented, or shared with data brokers or advertising platforms.

Data may be transferred only as needed to provide the functions above:

  • To the accounting mailbox or private notification channels designated by the account owner.
  • To infrastructure and processing providers used to operate the automation, including Google APIs, private hosting, messaging delivery, and text summarization services.
  • When required by law, or when necessary to investigate abuse or protect the security of the service.

Providers receive only the information needed for their role. They are not authorized by Hacala Studio to use Google user data for advertising or to train general-purpose AI models.

5. Storage and retention

OAuth credentials and tokens are stored in an access-restricted private server environment. Tokens are kept while the account remains connected and are deleted when access is revoked or the automation is retired.

The automation keeps limited operational records such as message IDs, sender, subject, date, category, and processing status. These records help prevent duplicate alerts or forwarding and support troubleshooting. They are retained only while operationally useful.

Full email content is processed only when required for a function. It is not copied into a permanent message database. A selected receipt may be forwarded, including as an attached email file, to the account owner's designated accounting mailbox. Copies already delivered to a recipient may be retained under that recipient's legal or accounting obligations.

6. Website form information

When someone submits a form on roberthacala.com, Hacala Studio receives the information they choose to provide, such as name, email address, business or website, project details, questionnaire responses, and uploaded materials. Basic technical information such as IP address and submission time may be processed for spam prevention and rate limiting.

Form information is used to review and respond to the inquiry. It may be delivered through email and a private notification service. Draft form responses may be stored in the visitor's browser until submitted or cleared.

7. Security

Hacala Studio uses HTTPS, OAuth authorization, restricted credentials, access controls, and least-necessary access practices to protect information. No transmission or storage method can be guaranteed completely secure, but reasonable safeguards are maintained for the nature of the data handled.

8. Your choices

Google access can be reviewed or revoked at any time from Google Account permissions. Revoking access stops future API access but does not remove messages or records already delivered to authorized recipients.

To ask a privacy question or request deletion of retained information, email mynebularobot@gmail.com. Requests may require identity verification before data is disclosed or deleted.

9. Google API Limited Use

Hacala Studio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10. Changes to this policy

This policy may be updated when the automation, its data practices, or applicable requirements change. The date at the top of this page will be revised when an update is published. Material changes affecting Google user data will be disclosed before the new use begins, and new consent will be requested when required.