Privacy Policy
1. Overview and Purpose
Wakeport ("we", "us", or "our") provides an automated notification routing and event classification gateway. Wakeport allows authorized users to connect communication channels—including Google Gmail mailboxes—to detect time-critical automation events such as two-factor authentication (2FA) verification codes, passwordless sign-in links, and transactional notifications, dispatching structured wake events to user-designated local agents, Model Context Protocol (MCP) endpoints, or webhooks.
We are dedicated to safeguarding user privacy and being transparent about our data handling practices. This Privacy Policy details how we access, process, protect, and store information when you use Wakeport.
2. Google User Data Accessed by Wakeport
When you explicitly connect a Google account to Wakeport via OAuth 2.0, we request access only to the minimum scopes required for the application's functionality:
- Google Identity & Profile (
openid,userinfo.email): Used solely to identify your connected account and verify your email address. - Gmail Messages (
https://www.googleapis.com/auth/gmail.readonly): Used to inspect incoming message headers (sender, recipient, subject, date, message ID) and evaluate message bodies against your user-defined subscriptions (e.g. searching for one-time verification passcodes or tracking updates). - Optional Mailbox Management (
https://www.googleapis.com/auth/gmail.modify): If explicitly enabled by you, this scope allows Wakeport to apply labels or mark notifications as processed after a wake signal has been emitted.
3. How We Use Google User Data
Wakeport processes Google user data strictly to deliver user-facing automation features:
- Scanning incoming Gmail notifications received via Google Cloud Pub/Sub push notifications or periodic sync to detect matching subscription patterns.
- Extracting verification codes (OTPs), authentication links, or order updates according to user-defined filters.
- Emitting structured, metadata-sanitized wake events to destinations you explicitly configure (such as local development agents or webhook targets).
- Refreshing OAuth access tokens to maintain continuous synchronization for your account.
4. Google API Services User Data Policy Compliance (Limited Use Requirements)
Wakeport's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In strict compliance with the Google API Services User Data Policy:
- We only use Google API data to provide or improve user-facing features that are prominent in the user interface of Wakeport.
- We do not transfer Google user data to third parties, except: (a) as necessary to provide or improve user-facing features, (b) to comply with applicable laws, or (c) as part of a merger, acquisition, or sale of assets with prior user notification.
- We do not use or transfer Google user data for serving advertisements, including personalized, re-targeted, or interest-based advertising.
- We do not allow humans to read Google user data unless: (1) you have provided explicit affirmative consent for specific messages to resolve technical issues; (2) it is necessary for security purposes (such as investigating abuse or vulnerabilities); (3) it is required by law; or (4) the data is aggregated and anonymized for internal operational metrics.
5. Prohibition on Artificial Intelligence (AI) and Machine Learning (ML) Training
Wakeport does not use Google user data—including Gmail message contents, email headers, or recipient metadata—to train, retrain, fine-tune, or improve generalized artificial intelligence (AI) models or machine learning (ML) models.
6. Data Sharing, Sale, and Disclosure
We never sell, rent, monetize, or trade your personal data or Google user data under any circumstances.
Your data is never shared with third-party data brokers, marketers, or analytics aggregators. We only utilize trusted infrastructure subprocessors (such as Cloudflare for secure global edge routing and Google Cloud for authorized Pub/Sub message delivery) bound by strict confidentiality and data protection agreements.
7. Data Storage and Security Practices
We implement rigorous technical and administrative security measures:
- Encryption in Transit: All communications between your devices, Google API servers, and Wakeport edge endpoints use modern TLS 1.3 encryption.
- Local / Single-Tenant Storage: OAuth tokens and operational event databases are stored locally in isolated, permission-restricted environments on the operator's machine or dedicated single-tenant datastores.
- Zero Public Persistence: Message body contents are not stored in shared multi-tenant cloud databases. Messages are processed transiently to extract required challenge data and discarded.
8. Data Retention and User Control (Deletion & Revocation)
You maintain complete control over your data:
- Token Retention: OAuth credentials are retained only while your account connection remains active in Wakeport.
- Revoking Access: You can disconnect your Google account and revoke Wakeport's access at any time through the Google Account Permissions page.
- Data Deletion Requests: You may request the immediate deletion of any associated metadata or configuration by contacting us at privacy@wakeport.io. Upon receiving your request, all credentials and local data associated with your identity will be permanently deleted within 48 hours.
9. Contact Information
If you have questions, feedback, or requests regarding this Privacy Policy or our compliance with Google API policies, please reach out to us:
- Privacy Inquiries: privacy@wakeport.io
- General Support: support@wakeport.io
- Developer & Operator: Daniel Hallman / Moosh Works