πŸ“„ Legal document

Privacy Policy

πŸ—“ Effective date: March 17, 2026 πŸ”„ Last updated: March 17, 2026 πŸ“‹ Version 1.0

1Data Controller

The controller of your personal data is:

Test Plus Tomasz Radzewicz
ul. mjr. Hubala 11/2, 15-174 BiaΕ‚ystok, Poland
VAT ID (NIP): 542-197-51-09
Email: kontakt@publishflow.pl

Supervisory authority: UrzΔ…d Ochrony Danych Osobowych (UODO – Polish Data Protection Authority), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl

Data Protection Officer (DPO): Not applicable – at the current scale of processing, there is no obligation to appoint a DPO under GDPR Art. 37.

2Scope of this Privacy Policy

This policy describes how we process personal data in connection with:

  • PublishFlow Gmail Add-on – a Google Workspace Add-on available on Google Workspace Marketplace
  • Website publishflow.pl

This policy is directed to individuals (journalists, editors, content creators) using PublishFlow on their own behalf or for their organization.

3How PublishFlow Works – Non-Proxy Architecture (BYOK)

πŸ”’ Core Privacy Principle
PublishFlow does not operate a backend server that stores the content of your emails. Your email data never reaches PublishFlow's servers.

PublishFlow operates on a Non-Proxy (no intermediary) and BYOK (Bring Your Own Key) model. This means:

πŸ“§ Gmail
"News" label
β†’
βš™οΈ Google Apps Script
in-session processing
β†’
πŸ€– Anthropic API
your own API key
β†’
πŸ“Š Google Sheets
your spreadsheet
Email content is processed only within the Google Apps Script execution session and is never stored on PublishFlow servers.

Your Anthropic API key is stored exclusively in PropertiesService.getUserProperties() – a Google-managed encrypted storage that PublishFlow's developer cannot access.

Processing results (article title, lead, tags, category) are saved to a Google Sheets spreadsheet on your own Google account – remaining entirely under your control.

4Data We Process

A. Google Account Data (identity)

  • Google account email address – purpose: license identification, display in the add-on interface
  • Name / profile picture (from Google Profile) – purpose: UI personalization

B. Gmail Data (email content)

πŸ“­ No email content stored
Email content is never stored on any PublishFlow server. Processing occurs only during the Google Apps Script execution session (in-memory). After the session ends, all email data is gone.
  • Email content from the "News" label (subject, body, sender) – sent to Anthropic API only upon your explicit action (clicking "Process Emails")
  • Attachments (PDF, DOCX, TXT, HTML) – processed temporarily in-session; a temporary Drive copy is deleted immediately after text extraction
  • Message metadata (thread ID, date, Gmail labels) – used only to manage the retry system (Retry-1/2/3, Processed, Processing-Failed labels)

C. User Configuration Data

  • Anthropic API key – stored exclusively in Google PropertiesService (encrypted by Google, inaccessible to PublishFlow developer)
  • Add-on settings (results spreadsheet name, label configuration) – stored in Google PropertiesService
  • License status and subscription expiry date – stored in Google PropertiesService

D. Processing Results

  • AI-generated data (article title, lead, tags, category, quote, image URL) – saved only to your Google Sheets account, under your full control

E. Billing Data

  • Invoice data (name/company, address, VAT ID) – provided voluntarily for invoice issuance; processed directly by the controller (Test Plus Tomasz Radzewicz) using accounting software; payment via bank transfer or instant payment
  • Subscription status – stored in Google PropertiesService (active / expired)

F. Technical Data

  • Google Apps Script error logs – stored by Google (not PublishFlow), accessible only to the developer in Google Cloud Console
  • Anthropic API logs – retention up to 7 days per Anthropic's policy

5OAuth Scopes and Their Justification

PublishFlow requests the following permissions during installation:

ScopeClassificationPurpose and Justification
gmail.modify Restricted Reading emails from the "News" label and applying processing status labels (Retry-1/2/3, Processed, Processing-Failed). The add-on never sends emails, never reads emails outside the "News" label.
drive.file Sensitive Creating a results spreadsheet in Google Drive and temporary attachment copies (immediately deleted). Scope is limited exclusively to files created by the add-on – no access to other Drive files.
spreadsheets Sensitive Writing AI analysis results (title, lead, tags, category) to a Google Sheets spreadsheet.
script.external_request Non-sensitive Anthropic API calls (UrlFetchApp). Restricted to api.anthropic.com and api.paddle.com only (urlFetchWhitelist).
script.locale Non-sensitive Formatting dates and numbers according to user locale settings.
userinfo.email Non-sensitive User identification for license verification and display in the interface.
userinfo.profile Non-sensitive Displaying name and profile picture in the add-on interface.
script.container.ui Non-sensitive Displaying the add-on sidebar panel within Gmail.

6Purposes and Legal Bases (GDPR Art. 6)

PurposeLegal Basis (GDPR Art. 6)Data involved
Providing the PublishFlow service – processing emails, generating AI results, saving to Sheets Art. 6(1)(b) – performance of a contract Email content (session), API key, results
License identification and management Art. 6(1)(b) – performance of a contract Email address, subscription status
Security, retry system, error prevention Art. 6(1)(f) – legitimate interest (service stability) Email metadata, retry labels, error logs
Handling requests and exercising user rights Art. 6(1)(c) – legal obligation + Art. 6(1)(f) Email address, contact history
Billing, VAT invoicing, tax records Art. 6(1)(c) – legal obligation Invoice data for billing; invoices issued directly by the controller
⚠️ Email content processing by AI
Your email content is sent to the Anthropic Claude API only when you click "Process Emails". Processing does not occur automatically without your action (in MVP version). Legal basis: Art. 6(1)(b) (contract performance) and your informed consent expressed by triggering the function.

7Recipients and Subprocessors

PublishFlow uses the following data processors (subprocessors) to whom we may transfer data to the extent necessary:

πŸ”΅ Google LLC
Infrastructure
Location: USA (global processing)
Scope: Gmail, Google Apps Script, Google Drive, Google Sheets, PropertiesService – the infrastructure on which the add-on operates
Transfer basis: Standard Contractual Clauses (SCCs) + Google Cloud global infrastructure
Privacy policy: policies.google.com/privacy
πŸ€– Anthropic PBC
AI Processing
Location: USA (with EU Regional Processing option – processing in the EU)
Scope: AI analysis of email content via Claude – only upon user request, within the session
Retention: API logs – maximum 7 days; email content is not used to train AI models
Transfer basis: Data Processing Agreement (DPA) with SCCs + EU Regional Processing option (data stays in the EU)
Privacy policy: anthropic.com/privacy
πŸ’³ Billing (direct invoicing)
No third-party payment processor
Model: VAT invoices issued directly by Test Plus Tomasz Radzewicz using accounting software
Payment: Bank transfer – no third-party payment processor involved
Data scope: Invoice data provided by the customer (name/company, address, VAT ID) processed by the controller as a legal obligation (GDPR Art. 6(1)(c))
International transfer: Not applicable – invoice data processed exclusively by the controller in Poland (EU)

No other recipients. User data is not sold, not transferred to data brokers, not used for behavioral advertising, and not used to build advertising profiles.

We disclose data to public authorities only when required by applicable law.

8International Data Transfers

PublishFlow aims to minimize data transfers outside the European Economic Area (EEA). Where transfers are necessary, we use the following safeguards:

RecipientCountryTransfer Safeguard
Google LLC USA (global infrastructure) Standard Contractual Clauses (SCCs) approved by the European Commission
Anthropic PBC USA (EU option available) DPA with SCCs + EU Regional Processing option (data processed in the EU since August 2025). We recommend enabling EU Regional Processing in your Anthropic account settings.
Billing (controller) Poland (EU) No transfer outside EEA – invoice data processed exclusively by the controller in Poland

You can request a copy of the applicable safeguards by emailing kontakt@publishflow.pl.

9Data Retention and Deletion

Data CategoryWhere StoredRetention Period
Email content and attachments Nowhere (GAS session) 0 – deleted after session ends
Anthropic API key Google PropertiesService Until deleted by the user or the add-on is uninstalled
License status Google PropertiesService Until add-on uninstall or deletion request
AI analysis results User's Google Sheets Under user control – PublishFlow has no access after saving
Anthropic API logs Anthropic servers Max. 7 days (Anthropic policy)
Payment data and invoices Controller's accounting records (Poland) 5 years from invoice date (Polish tax law requirements)
Temporary attachment copies Google Drive (momentarily) Deleted immediately after text extraction (same session)

What happens when you uninstall the add-on?

  • Google automatically deletes data stored in PropertiesService upon add-on uninstallation
  • You can manually delete all data before uninstalling using the "Delete My Data" button in the add-on Settings panel
  • Results in Google Sheets remain – they are on your Google account and under your control

10Your Rights (GDPR Art. 15–22)

Art. 15
Right of Access
Request information about your data and obtain a copy
Art. 16
Right to Rectification
Request correction of inaccurate personal data
Art. 17
Right to Erasure
"Delete My Data" button in add-on Settings, or contact us by email
Art. 18
Right to Restriction
Request restriction of processing in certain circumstances
Art. 20
Right to Portability
Results are in your Google Sheets – export via Google formats (CSV, XLSX)
Art. 21
Right to Object
Object to processing based on legitimate interest
Art. 77
Right to Lodge a Complaint
UODO (Polish DPA), ul. Stawki 2, Warsaw; or your local supervisory authority

Submit requests to: kontakt@publishflow.pl – we respond within 30 days.

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

11Security (GDPR Art. 32)

We implement the following technical and organizational measures appropriate to the risk:

  • Encryption in transit: HTTPS/TLS for all network connections
  • Encryption at rest: Anthropic API key stored in Google PropertiesService – encrypted by Google
  • Endpoint restriction: urlFetchWhitelist in the add-on configuration limits outbound connections exclusively to api.anthropic.com – preventing data leakage to unauthorized servers
  • Formula injection protection: data is sanitized before writing to Google Sheets (OWASP guidelines)
  • Principle of least privilege: drive.file scope (not auth/drive) – access only to files created by the add-on
  • Non-Proxy architecture: absence of PublishFlow backend servers storing user data eliminates server-side breach risk on PublishFlow's end
  • Access controls: PublishFlow's developer has no technical ability to read your data from Google PropertiesService

12Data Breaches (GDPR Art. 33–34)

We maintain internal procedures for detecting and handling security incidents. In the event of a personal data breach:

  • We assess the risk to the rights and freedoms of affected individuals
  • Where a breach may cause risk – we notify UODO no later than 72 hours after becoming aware (GDPR Art. 33)
  • Where a breach may cause high risk – we notify you directly without undue delay (GDPR Art. 34)

If you suspect a security incident involving PublishFlow, please contact us: kontakt@publishflow.pl

13Cookies and Tracking Technologies

Website publishflow.pl may use basic cookies necessary for the technical functioning of the site. We do not use analytics or marketing cookies without your consent.

The PublishFlow Gmail Add-on does not use cookies – it operates within the Google Apps Script environment, which does not support browser cookies.

14Google API Compliance (Limited Use)

πŸ”’ Required Google Statement – Limited Use
"PublishFlow's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

Data Use Restrictions

  • Limited to visible features: data from Gmail and Google Workspace is used exclusively for the features visible in the PublishFlow interface – processing "News" label emails and generating results to Sheets
  • No data sale: Google user data is not sold, not transferred to data brokers
  • No advertising use: Gmail data is not used for behavioral advertising, retargeting, or advertising profiling
  • No AI model training: Gmail data is not used to train, improve, or build general-purpose AI models. Anthropic does not train its models on API data (per Anthropic's policy)
  • No human reading: PublishFlow's developer has no technical ability to read your email content. The Non-Proxy architecture prevents email content from reaching PublishFlow's servers
  • Transfers: Gmail data is transferred only to Anthropic API for AI analysis – upon your explicit request

Full Google API Services User Data Policy: developers.google.com/terms/api-services-user-data-policy

15Changes to this Privacy Policy

We will notify you of material changes to this privacy policy:

  • By email to the address associated with your Google account (at least 14 days in advance)
  • By a notice in the add-on interface upon next launch

The current version is always available at: publishflow.pl/privacy

This version effective: March 17, 2026 (version 1.0)