Application policy · Updated September 30, 2026
Privacy policy
This policy describes New Wave Gmail Assistant, operated by Andrei for New Wave's account owner and authorized users. It covers this informational website and the associated private Gmail connector.
Information accessed
With the account holder's Google OAuth authorization, the connector can access their email address, message headers, senders and recipients, subjects, message bodies, conversation information, attachment metadata and requested attachments. It can also access, create and update drafts, and send a reviewed draft when explicitly instructed.
The requested Google permissions are gmail.readonly and gmail.compose. Google issues authorization tokens; the connector does not ask for or store the account's Google password.
How information is used
Google user data is used to perform the account holder's requested email workflows: searching, reading, summarizing correspondence, retrieving attachments, preparing drafts, and sending explicitly authorized replies. Email content may contain personal or business information about correspondents.
AI processing and service providers
Information returned by the connector is passed to the account holder's Codex session and configured AI service, including OpenAI when used in that setup, to perform the requested task. The amount shared depends on the search, message, thread, or attachment requested. Conversation history and tool results may be retained by that service under the account's applicable agreement and settings.
The operator does not sell Google user data, use it for advertising, or use it to develop or train generalized AI or machine-learning models. Google data must only be transferred to providers as needed for the requested user-facing functionality and in accordance with Google's Limited Use requirements. Authorized users must use service settings and agreements consistent with those requirements.
New Wave Gmail Assistant's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage, retention and security
OAuth credentials and refresh tokens are stored in private files on the operator's computer. Requested attachments are saved locally. Drafts and sent messages are stored in Gmail. Local exports, downloaded files, and conversation records remain until deleted through their respective storage or application controls; this connector does not impose automatic deletion of those copies.
Google API communications use HTTPS. Access to the local computer and its private files is restricted through the operator's system controls. The public website contains application information only and has no Gmail credentials, mailbox connection, or email-content storage.
Website hosting
These application information pages are hosted on New Wave's Shopify storefront. Shopify and the storefront's configured services may process website visitor information, cookies, and analytics independently of the private Gmail connector, as described in the storefront privacy policy. The Gmail connector does not send mailbox contents or OAuth credentials to these public pages.
Your choices and deletion requests
You can stop using the connector and revoke its authorization in Google Account connections. Revocation stops future authorized access but does not remove copies previously saved in Gmail, local files, or conversation history. Delete those through the corresponding service or contact the operator for help removing operator-held copies. Service-provider retention and backups may be governed by their applicable terms.
Contact and changes
For privacy questions, access concerns, or deletion requests, contact andrei@newwavegear.com. Material changes to these practices will be reflected in this policy and its update date.
