Tokyo Personal Gmail privacy policy
Effective September 12, 2026. Operator and privacy contact: Ammon Ehrisman, [email protected].
Access and purpose
The app requests Google's Gmail read-only permission. This permission can read email messages and settings throughout the authorized mailbox. The reader's own query limits collection to recent AwardFares messages; this is an application restriction, not a Google-enforced restriction to a sender or label. It also checks the account email address to confirm the intended account.
The app uses message identifiers, sender, subject, dates, authentication headers, and message text to collect and classify award-flight leads and prevent duplicates. Subject-based filters exclude common sign-in, activation, and billing messages; these filters are not a guarantee that every sensitive message will be recognized.
Storage and processing
OAuth credentials are stored in macOS Keychain. Imported message text and metadata, candidate records, and review packets are stored in the private local project runtime folder. Local files and computer backups are subject to the owner's device and backup protections. The reader does not publish mailbox data to this website.
The owner may review selected email data and candidate records through Codex as part of the travel workflow. Data supplied to Codex is processed under the owner's applicable OpenAI account terms and data controls. The reader itself has no separate AI API integration. Google processes authentication and Gmail API requests under Google's applicable policies.
The app does not sell Gmail data, use it for advertising, or use it to train a generalized AI model. Tokyo Personal Gmail's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Retention and control
Local records remain until the owner deletes them; automatic expiry is not currently implemented. The owner can revoke access through Google Account third-party connections settings. Revocation stops future authorized access but does not erase existing local records. To remove them, delete the app's private runtime records and its Keychain credentials; any retained backups and Codex conversations must be managed separately through their respective controls.
Changes and questions
This policy will be updated when the app's data practices change. Contact [email protected] with questions or deletion requests.