← GoodLine Gmail connections

GoodLine Privacy Policy

Last updated: October 7, 2026

This policy covers the client dashboard and Google account data processed by GoodLine's send-only Gmail connection. GoodLine operates this app. For other GoodLine website, call and message data, read our general Privacy Policy. Contact hello@goodline.ai for privacy questions or requests.

Client dashboard

If your business uses the GoodLine dashboard, we store the email addresses given access, sign-in records, follow-up statuses, notes and contact corrections added to leads, and saved email drafts and send records. An emailed sign-in link and one essential cookie on app.goodline.ai keep an authorized user signed in for up to seven days. The dashboard shows only the leads and assistant conversations associated with that business. Account and follow-up records remain while needed to operate and support the service; they currently have no automatic deletion deadline. Contact hello@goodline.ai to request access, correction or deletion; we verify your authority before fulfilling a request.

Connected Gmail and Google user data

GoodLine's optional Gmail connection lets an authorized business user send a reviewed reply to a lead from their own connected Gmail address. Access begins when the user chooses Connect Gmail on the dashboard and authorizes Google's send-email permission. Learn how the Gmail connection works.

What we access and collect

Google provides your account email address, account identifier, granted permissions, OAuth credentials and the message identifier returned after a send. We use these to identify the connected mailbox, maintain authorized access and record the outcome of the email you chose to send. GoodLine asks for send-only Gmail access and account identity. It cannot read, search, label or delete your mailbox messages or read replies. Google handles sign-in; GoodLine does not receive your Google password.

Drafts and outgoing email content originate in the dashboard, not from reading your mailbox. We keep the recipient, sending address, subject, text, time, authorized sender and send status with the lead. Drafts are saved in GoodLine rather than Gmail's Drafts folder.

Use, storage and sharing

GoodLine sends only when the user presses Send and confirms the recipient. The recipient is the lead's own email address. Google processes the outgoing recipient, subject and message to deliver it through Gmail. Replies arrive in the connected mailbox. GoodLine does not automatically read them.

Amazon Web Services hosts the dashboard and processes account, lead, draft and send records in an encrypted database. OAuth credentials are stored separately in AWS Secrets Manager with encryption at rest and restricted service access. Public service requests and requests to Google use HTTPS. Authorized business users can see their business's records; authorized GoodLine operators can access records for necessary setup, support and security.

When you choose Draft with AI, OpenAI processes the lead's details, its conversation with your assistant, your drafting instructions and your business's approved information to generate a draft. Those details come from the GoodLine enquiry, not a Gmail mailbox read. Google OAuth credentials and Gmail API send-result identifiers are not sent to the AI provider. You can edit the draft before sending.

We do not sell Google user data, use it for advertising, or use Google Workspace API data to develop, improve or train generalized or non-personalized AI or machine-learning models. GoodLine's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention, disconnecting and deletion

Account identity and credentials remain available while the Gmail connection is active. Choose Disconnect on the dashboard, remove GoodLine in your Google account connections, or ask hello@goodline.ai to disconnect. Dashboard disconnection stops new sends, requests revocation of Google's grant and clears the credentials available to GoodLine. Older encrypted secret versions may remain subject to AWS's managed version retention.

Disconnection does not delete messages already delivered or the dashboard's draft, send and audit records. Dashboard records currently have no automatic expiry and remain while needed to operate and support the business; you may request their deletion by emailing hello@goodline.ai with the business and connected account. We verify your authority before providing, correcting or deleting records. Messages in Gmail and recipient mailboxes follow their owners' retention choices.