Legal
Privacy Policy
Last updated: June 18, 2026
This Privacy Policy explains how Corsair Workspace ("we", "us", or "our") collects, uses, stores, and protects information when you use our website and application at corsair-workspace.vercel.app.
Google API Services User Data Policy
Corsair Workspace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Under those requirements, we commit that Google user data will:
- Be used only to provide or improve user-facing features that are prominent in Corsair Workspace's user interface.
- Not be transferred to third parties except as necessary to provide or improve those features, comply with applicable law, or as part of a merger or acquisition with notice to users.
- Not be used for serving advertisements.
- Not allow humans to read the data unless you give affirmative consent for a specific message, it is necessary for security purposes, to comply with applicable law, or the data is aggregated and anonymized for internal operations.
Information we collect
When you use Corsair Workspace, we may collect:
- Account information such as your name and email address when you sign up or log in with email verification (OTP).
- Google account data that you explicitly authorize through OAuth when connecting Gmail or Google Calendar plugins.
- Cached copies of Gmail messages, labels, threads, drafts, and Google Calendar events needed to provide inbox, calendar, agent, and task features.
- Technical information such as session data, logs, and usage events required to operate and secure the service.
Google OAuth scopes we request
When you connect Gmail or Google Calendar, Google shows you the exact permissions before you approve. Depending on the plugins you connect, we may request the following scopes:
- OpenID Connect (
openid) — Authenticate your Google account during plugin connection. - Email address (
email) — Identify which Google account you connected to your workspace. - Basic profile (
profile) — Display your name on connected plugin status where applicable. - Gmail modify (
https://www.googleapis.com/auth/gmail.modify) — Read, search, organize, compose, send, and manage messages and labels in your Gmail inbox. - Gmail compose (
https://www.googleapis.com/auth/gmail.compose) — Create and update email drafts inside Corsair Workspace. - Gmail send (
https://www.googleapis.com/auth/gmail.send) — Send email on your behalf when you explicitly request it. - Google Calendar (
https://www.googleapis.com/auth/calendar) — View your calendars, events, and availability; create, update, and delete events; send meeting invites. - Calendar events (
https://www.googleapis.com/auth/calendar.events) — Sync and manage calendar events shown in the workspace and used by the AI agent for scheduling.
How we use Google user data
We use Google user data only to provide features you request inside Corsair Workspace, including:
- Displaying and searching your Gmail inbox, sent mail, drafts, and labels.
- Composing, updating, and sending email when you take those actions.
- Archiving, starring, labeling, or trashing messages you manage in the app.
- Displaying your calendar week, event details, and availability.
- Creating, updating, deleting calendar events and sending invites you request.
- Powering AI agent and automated task features within your workspace using the data you have authorized.
- Receiving webhook notifications from Google to keep synced data up to date.
We do not sell Google user data. We do not use Google user data for advertising or creditworthiness decisions.
How we use other information
- To authenticate you and maintain your workspace account.
- To maintain security, prevent abuse, and improve reliability.
- To respond to support requests and legal obligations.
Data storage and security
Integration credentials (OAuth refresh tokens) are encrypted and stored per user. Cached Gmail and Calendar data is stored in our database infrastructure (Supabase Postgres) while your account and plugin connections remain active so the product can function.
Each workspace user has separate integration credentials and cached data scoped to their account. We do not share one user's Google data with another user.
Data retention and deletion
We retain Google user data while your plugin connections remain active. You may disconnect Gmail or Google Calendar at any time from the Plugins page, which stops future syncing. You may also revoke access from your Google Account permissions page.
To request account or data deletion support, contact us at amar.nextdev@gmail.com.
Sharing and third parties
We share data only with service providers necessary to operate the app (such as hosting and database infrastructure) and with Google when you choose to connect Google integrations. AI model providers may process content you explicitly submit to agent features; we do not sell personal information.
Your choices
- Disconnect Gmail or Google Calendar at any time from the Plugins page.
- Revoke Google access from your Google Account security settings.
- Contact us to request account or data deletion support.
Contact us
If you have questions about this Privacy Policy or your data, contact us at amar.nextdev@gmail.com.
See also our Terms & Conditions.