1Data Controller
The controller of your personal data is:
ul. mjr. Hubala 11/2, 15-174 BiaΕystok, Poland
VAT ID (NIP): 542-197-51-09
Email: kontakt@publishflow.pl
Supervisory authority: UrzΔ d Ochrony Danych Osobowych (UODO β Polish Data Protection Authority), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl
Data Protection Officer (DPO): Not applicable β at the current scale of processing, there is no obligation to appoint a DPO under GDPR Art. 37.
2Scope of this Privacy Policy
This policy describes how we process personal data in connection with:
- PublishFlow Gmail Add-on β a Google Workspace Add-on available on Google Workspace Marketplace
- Website publishflow.pl
This policy is directed to individuals (journalists, editors, content creators) using PublishFlow on their own behalf or for their organization.
3How PublishFlow Works β Non-Proxy Architecture (BYOK)
PublishFlow operates on a Non-Proxy (no intermediary) and BYOK (Bring Your Own Key) model. This means:
"News" label
in-session processing
your own API key
your spreadsheet
Your Anthropic API key is stored exclusively in PropertiesService.getUserProperties() β a Google-managed encrypted storage that PublishFlow's developer cannot access.
Processing results (article title, lead, tags, category) are saved to a Google Sheets spreadsheet on your own Google account β remaining entirely under your control.
4Data We Process
A. Google Account Data (identity)
- Google account email address β purpose: license identification, display in the add-on interface
- Name / profile picture (from Google Profile) β purpose: UI personalization
B. Gmail Data (email content)
- Email content from the "News" label (subject, body, sender) β sent to Anthropic API only upon your explicit action (clicking "Process Emails")
- Attachments (PDF, DOCX, TXT, HTML) β processed temporarily in-session; a temporary Drive copy is deleted immediately after text extraction
- Message metadata (thread ID, date, Gmail labels) β used only to manage the retry system (Retry-1/2/3, Processed, Processing-Failed labels)
C. User Configuration Data
- Anthropic API key β stored exclusively in Google PropertiesService (encrypted by Google, inaccessible to PublishFlow developer)
- Add-on settings (results spreadsheet name, label configuration) β stored in Google PropertiesService
- License status and subscription expiry date β stored in Google PropertiesService
D. Processing Results
- AI-generated data (article title, lead, tags, category, quote, image URL) β saved only to your Google Sheets account, under your full control
E. Billing Data
- Invoice data (name/company, address, VAT ID) β provided voluntarily for invoice issuance; processed directly by the controller (Test Plus Tomasz Radzewicz) using accounting software; payment via bank transfer or instant payment
- Subscription status β stored in Google PropertiesService (active / expired)
F. Technical Data
- Google Apps Script error logs β stored by Google (not PublishFlow), accessible only to the developer in Google Cloud Console
- Anthropic API logs β retention up to 7 days per Anthropic's policy
5OAuth Scopes and Their Justification
PublishFlow requests the following permissions during installation:
| Scope | Classification | Purpose and Justification |
|---|---|---|
gmail.modify |
Restricted | Reading emails from the "News" label and applying processing status labels (Retry-1/2/3, Processed, Processing-Failed). The add-on never sends emails, never reads emails outside the "News" label. |
drive.file |
Sensitive | Creating a results spreadsheet in Google Drive and temporary attachment copies (immediately deleted). Scope is limited exclusively to files created by the add-on β no access to other Drive files. |
spreadsheets |
Sensitive | Writing AI analysis results (title, lead, tags, category) to a Google Sheets spreadsheet. |
script.external_request |
Non-sensitive | Anthropic API calls (UrlFetchApp). Restricted to api.anthropic.com and api.paddle.com only (urlFetchWhitelist). |
script.locale |
Non-sensitive | Formatting dates and numbers according to user locale settings. |
userinfo.email |
Non-sensitive | User identification for license verification and display in the interface. |
userinfo.profile |
Non-sensitive | Displaying name and profile picture in the add-on interface. |
script.container.ui |
Non-sensitive | Displaying the add-on sidebar panel within Gmail. |
6Purposes and Legal Bases (GDPR Art. 6)
| Purpose | Legal Basis (GDPR Art. 6) | Data involved |
|---|---|---|
| Providing the PublishFlow service β processing emails, generating AI results, saving to Sheets | Art. 6(1)(b) β performance of a contract | Email content (session), API key, results |
| License identification and management | Art. 6(1)(b) β performance of a contract | Email address, subscription status |
| Security, retry system, error prevention | Art. 6(1)(f) β legitimate interest (service stability) | Email metadata, retry labels, error logs |
| Handling requests and exercising user rights | Art. 6(1)(c) β legal obligation + Art. 6(1)(f) | Email address, contact history |
| Billing, VAT invoicing, tax records | Art. 6(1)(c) β legal obligation | Invoice data for billing; invoices issued directly by the controller |
7Recipients and Subprocessors
PublishFlow uses the following data processors (subprocessors) to whom we may transfer data to the extent necessary:
Scope: Gmail, Google Apps Script, Google Drive, Google Sheets, PropertiesService β the infrastructure on which the add-on operates
Transfer basis: Standard Contractual Clauses (SCCs) + Google Cloud global infrastructure
Privacy policy: policies.google.com/privacy
Scope: AI analysis of email content via Claude β only upon user request, within the session
Retention: API logs β maximum 7 days; email content is not used to train AI models
Transfer basis: Data Processing Agreement (DPA) with SCCs + EU Regional Processing option (data stays in the EU)
Privacy policy: anthropic.com/privacy
Payment: Bank transfer β no third-party payment processor involved
Data scope: Invoice data provided by the customer (name/company, address, VAT ID) processed by the controller as a legal obligation (GDPR Art. 6(1)(c))
International transfer: Not applicable β invoice data processed exclusively by the controller in Poland (EU)
No other recipients. User data is not sold, not transferred to data brokers, not used for behavioral advertising, and not used to build advertising profiles.
We disclose data to public authorities only when required by applicable law.
8International Data Transfers
PublishFlow aims to minimize data transfers outside the European Economic Area (EEA). Where transfers are necessary, we use the following safeguards:
| Recipient | Country | Transfer Safeguard |
|---|---|---|
| Google LLC | USA (global infrastructure) | Standard Contractual Clauses (SCCs) approved by the European Commission |
| Anthropic PBC | USA (EU option available) | DPA with SCCs + EU Regional Processing option (data processed in the EU since August 2025). We recommend enabling EU Regional Processing in your Anthropic account settings. |
| Billing (controller) | Poland (EU) | No transfer outside EEA β invoice data processed exclusively by the controller in Poland |
You can request a copy of the applicable safeguards by emailing kontakt@publishflow.pl.
9Data Retention and Deletion
| Data Category | Where Stored | Retention Period |
|---|---|---|
| Email content and attachments | Nowhere (GAS session) | 0 β deleted after session ends |
| Anthropic API key | Google PropertiesService | Until deleted by the user or the add-on is uninstalled |
| License status | Google PropertiesService | Until add-on uninstall or deletion request |
| AI analysis results | User's Google Sheets | Under user control β PublishFlow has no access after saving |
| Anthropic API logs | Anthropic servers | Max. 7 days (Anthropic policy) |
| Payment data and invoices | Controller's accounting records (Poland) | 5 years from invoice date (Polish tax law requirements) |
| Temporary attachment copies | Google Drive (momentarily) | Deleted immediately after text extraction (same session) |
What happens when you uninstall the add-on?
- Google automatically deletes data stored in PropertiesService upon add-on uninstallation
- You can manually delete all data before uninstalling using the "Delete My Data" button in the add-on Settings panel
- Results in Google Sheets remain β they are on your Google account and under your control
10Your Rights (GDPR Art. 15β22)
Submit requests to: kontakt@publishflow.pl β we respond within 30 days.
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
11Security (GDPR Art. 32)
We implement the following technical and organizational measures appropriate to the risk:
- Encryption in transit: HTTPS/TLS for all network connections
- Encryption at rest: Anthropic API key stored in Google PropertiesService β encrypted by Google
- Endpoint restriction:
urlFetchWhitelistin the add-on configuration limits outbound connections exclusively toapi.anthropic.comβ preventing data leakage to unauthorized servers - Formula injection protection: data is sanitized before writing to Google Sheets (OWASP guidelines)
- Principle of least privilege:
drive.filescope (notauth/drive) β access only to files created by the add-on - Non-Proxy architecture: absence of PublishFlow backend servers storing user data eliminates server-side breach risk on PublishFlow's end
- Access controls: PublishFlow's developer has no technical ability to read your data from Google PropertiesService
12Data Breaches (GDPR Art. 33β34)
We maintain internal procedures for detecting and handling security incidents. In the event of a personal data breach:
- We assess the risk to the rights and freedoms of affected individuals
- Where a breach may cause risk β we notify UODO no later than 72 hours after becoming aware (GDPR Art. 33)
- Where a breach may cause high risk β we notify you directly without undue delay (GDPR Art. 34)
If you suspect a security incident involving PublishFlow, please contact us: kontakt@publishflow.pl
13Cookies and Tracking Technologies
Website publishflow.pl may use basic cookies necessary for the technical functioning of the site. We do not use analytics or marketing cookies without your consent.
The PublishFlow Gmail Add-on does not use cookies β it operates within the Google Apps Script environment, which does not support browser cookies.
14Google API Compliance (Limited Use)
"PublishFlow's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."
Data Use Restrictions
- Limited to visible features: data from Gmail and Google Workspace is used exclusively for the features visible in the PublishFlow interface β processing "News" label emails and generating results to Sheets
- No data sale: Google user data is not sold, not transferred to data brokers
- No advertising use: Gmail data is not used for behavioral advertising, retargeting, or advertising profiling
- No AI model training: Gmail data is not used to train, improve, or build general-purpose AI models. Anthropic does not train its models on API data (per Anthropic's policy)
- No human reading: PublishFlow's developer has no technical ability to read your email content. The Non-Proxy architecture prevents email content from reaching PublishFlow's servers
- Transfers: Gmail data is transferred only to Anthropic API for AI analysis β upon your explicit request
Full Google API Services User Data Policy: developers.google.com/terms/api-services-user-data-policy
15Changes to this Privacy Policy
We will notify you of material changes to this privacy policy:
- By email to the address associated with your Google account (at least 14 days in advance)
- By a notice in the add-on interface upon next launch
The current version is always available at: publishflow.pl/privacy
This version effective: March 17, 2026 (version 1.0)