Privacy Policy

Last updated: September 10, 2026

This Privacy Policy explains how lemongraph(“we”, “us” or “our”) collects, uses and protects your information when you use our application and sign in with Google. By using the app you agree to the practices described here.

Information we collect

When you sign in with Google, Google shares information with us based on the permissions you grant. We collect account information:

  • Basic profile information including your name and profile picture.
  • Email address associated with your Google account.
  • Google account identifier used to recognize you on return visits.

lemongraph runs agents that pursue a piece of work on your behalf over days or weeks, and that requires access to your mail and calendar. With your permission we also access:

  • Gmail messages including subjects, message bodies, attachments, labels, and the participants and timestamps of threads. We read existing mail as well as mail that arrives while an agent is working.
  • Google Calendar events including titles, descriptions, times, attendees and conferencing links, across both past and upcoming events.

We do not collect your Google password. Authentication is handled entirely by Google through OAuth, and you can revoke our access at any time.

How we use your information

We use account information to:

  • Create and secure your account.
  • Authenticate you and keep you signed in.
  • Personalize your experience within the app.
  • Contact you about your account or important service changes.

We use your Gmail and Calendar data to provide the features the product exists for. An agent reads the mail and events relevant to the work you have given it, so that it can understand what has happened and decide what to do next. Acting on your behalf it will:

  • Send email from your account, including replies within existing threads.
  • Apply labels to messages and archive them.
  • Create, update and cancel calendar events, and invite attendees to them.

We never permanently delete your mail, and this is enforced rather than promised. Permanent deletion requires the full Gmail scope. We requested gmail.modify instead, which does not include it. See our security page for what else the scopes we hold rule out.

Agents also keep a working memory of what they have learned about your workflows, so that they can resume correctly after waiting. That memory is scoped to your account and is used only to serve you.

Google API Services and Limited Use

lemongraph’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In line with those requirements, we use Google user data only to provide and improve the user-facing features that are prominent in the app. We do not:

  • Use Google user data for personalized or targeted advertising.
  • Sell Google user data.
  • Transfer Google user data to data brokers or use it to determine creditworthiness or for lending purposes.
  • Use Google user data to train or improve generalized or non-personalized AI or machine learning models.

Humans do not read your Google user data unless you give affirmative agreement, it is necessary for security or to comply with the law, or the data is aggregated and used for internal operations in line with Google policy.

How we share information

We do not sell your personal information. We share data only with the service providers that make the product work, and only to the extent needed to deliver it. These providers are bound by contract to protect your data and to use it only on our instructions.

Because lemongraph is an AI product, some of these providers process the content of your mail and calendar:

  • AI model providers receive the message and event content an agent is reasoning about, in order to generate its decisions and replies. We currently use OpenAI. Our agreement with them does not permit your data to be used to train their models.
  • Our observability provider receives records of those same requests so that we can debug and improve agent behaviour. We remove email addresses, phone numbers, payment card numbers and similar identifiers before these records leave our systems.
  • Cloud hosting and infrastructure providers store your data on our behalf.

Some providers receive no mail or calendar content at all. When an agent searches the web, our search provider receives only the search terms it composed. Our product analytics provider receives account activity, not the content of your mail or events.

Our sub-processor list names each of these providers, what it receives and why. If you have a data processing agreement with us, we will notify you before adding a provider that processes your content.

Data retention

We keep your information for as long as your account is active. Message bodies and attachments have no separate expiry. They live as long as the account, and deleting the account is what erases them.

You can delete your account yourself from Settings. On confirmation we stop the Gmail and Calendar push channels, revoke our Google access, delete your third party credentials and delete your account, all within that request. Everything else follows within a day: jobs, notes, ingested messages and events, agent memory, attachments and traces. Deleted rows can survive in our encrypted database backups for up to seven days, which is how long we keep them, and we retain what the law requires us to retain.

Deletion is not reversible. Signing in again with the same Google account gives you a new, empty account rather than the old one.

Your rights and choices

  • You can revoke our access to your Google account at any time from your Google account permissions page.
  • You can delete your account and all of its data from Settings, without contacting us.
  • You can request access to or correction of your personal data by contacting us.

Security

Your Google tokens are encrypted before they are stored. The application holds no database password and authenticates with a short-lived IAM credential. Tenant isolation is enforced by the database through row level security rather than by application code. Our security page covers what we can and cannot do with your account, and what we do not yet have.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children’s privacy

The app is not intended for children under 13, and we do not knowingly collect data from them.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the date above.

Contact us

If you have questions about this policy or your data, email us at george@lemongraph.dev. Our website is https://lemongraph.dev.