OOperator.

Legal

Privacy Policy

Last updated August 15, 2026

This Privacy Policy explains how Operator processes information when you use Operator at operatorreply.com, connect a Gmail or Google Workspace account, or contact support.

1. Information Operator collects

Depending on how you use Operator, the service processes:

  • Account information: your Supabase Auth user ID, account email, session information, and authentication records. Supabase provides email/password authentication; Operator does not store your password in its product database.
  • Business and preference information: onboarding status, business name, industry, business description, writing tone and style choices, greetings, sign-off, phrases to avoid, custom drafting instructions, notification preferences, and Gmail monitoring settings.
  • Product records: detected opportunity fields, customer display name and email, conversation subject, classifier decision and reason, urgency, confidence, snooze/dismiss/resolve state, AI-suggested subject and body, your edited draft subject and body, send status, and limited operational timestamps and IDs.
  • Billing and notifications: Stripe customer, subscription, price, status, billing-period and cancellation identifiers; webhook processing records; in-app notifications; and transactional email delivery status. Operator does not store full payment-card details.
  • Technical information: essential session and OAuth state cookies, a local theme preference, request timestamps, security and provider error categories, counts, model/token usage, and hosting or operational logs. Hosting infrastructure may process IP address, browser/device information, and request metadata needed to deliver and secure the service.

2. Google and Gmail user data

Permissions requested

Operator currently requests exactly these Gmail scopes:

  • https://www.googleapis.com/auth/gmail.readonly to list and retrieve Gmail profile, thread, message, and history data.
  • https://www.googleapis.com/auth/gmail.send to send only an email that the signed-in owner has reviewed and confirmed in a separate final approval step.

Operator does not request gmail.modify,gmail.compose, or full-mailbox access. It does not create Gmail drafts, change labels, delete Gmail messages, or send customer email autonomously.

Gmail information accessed

The current monitoring flow discovers recent mailbox threads within a 90-day lookback, including non-Trash mailbox locations and a separately handled Spam review. Trash is excluded. For threads that require processing, Operator can access:

  • the connected Gmail address, granted scopes, and Gmail history checkpoint;
  • thread and message IDs, message counts, labels, snippets, and timestamps;
  • subject, sender, recipient, CC, and participant names and email addresses;
  • readable message text from text/plain, or readable text derived from HTML when plain text is unavailable;
  • limited list/automation signals and reply-threading headers needed to filter automated mail and construct an approved Gmail reply.

Operator ignores attachment parts and does not call the Gmail attachment-download API. It fetches the current live Gmail thread again when you open conversation context and immediately before an approved send so stale-thread, recipient, and threading checks use authoritative Gmail data.

Gmail-derived information stored

Operator stores the connected Gmail address and scopes, an encrypted OAuth refresh token, history/sync state, Gmail thread and message fingerprints, limited subject/customer display fields, analysis outcomes, opportunity status, and suggested or owner-edited drafts. It also stores constrained automation-signal booleans/enums and operational counts. Operator does not persist complete raw MIME payloads, full normalized conversations, or complete Gmail message bodies in its Supabase product database.

3. How Operator uses information

Operator uses the information above to:

  • authenticate the owner and maintain the Operator account;
  • connect, monitor, and recover the authorized Gmail account;
  • normalize conversations and distinguish inbound from outbound messages;
  • filter clearly automated or non-actionable mail;
  • identify legitimate sales or revenue follow-up opportunities;
  • prepare a suggested subject and message for owner review;
  • show live Gmail context and manage opportunities, snoozes, and drafts;
  • send the exact reviewed email only after the owner completes the two-step approval flow;
  • provide billing, account notifications, support, security, and reliability;
  • evaluate and improve the accuracy of Operator's visible classification and drafting features using bounded provider and operational telemetry.

Google user data is not sold. Operator does not use Google user data for advertising, targeted or interest-based advertising, retargeting, creditworthiness, lending, surveillance, or unrelated product purposes.

4. AI processing and Google Limited Use

Operator sends bounded normalized conversation information server-side to OpenAI's API. Stage A receives direction, timestamps, sender/recipient display addresses, subject, and trimmed body text to classify a possible follow-up. Stage B runs only for a positive opportunity and receives the bounded conversation, classification, and business communication preferences to prepare a suggested subject and body. Long threads are trimmed while preserving recent messages and limited early context.

OAuth credentials, Gmail access or refresh tokens, raw MIME payloads, Supabase credentials, Stripe information, notification information, and unrelated account records are not sent to OpenAI. Requests use the OpenAI Responses API with application-state storage disabled. OpenAI may nevertheless retain API inputs and outputs in abuse monitoring logs for up to 30 days under its API data controls, unless different approved retention controls apply, and may retain data longer where legally required or necessary to protect services or others.

Operator does not use Google user data to train general-purpose AI models, does not train its own general-purpose model on Gmail data, and does not instruct service providers to use Gmail data for such training. Service-provider processing is limited to providing, securing, or improving Operator's user-facing features.

5. Service providers and limited sharing

Operator uses these providers for the functions described:

  • Google and Gmail: OAuth authorization and Gmail reading and owner-approved sending.
  • Supabase: authentication, session handling, database storage, row-level authorization, and server infrastructure.
  • OpenAI: bounded follow-up classification, draft generation, and evaluation of those user-facing features.
  • Vercel: application hosting, request delivery, and operational logging.
  • Stripe: Checkout, subscription billing, Customer Portal, and payment/financial records.
  • Resend: optional transactional Operator notifications sent to the authenticated account email.

Resend notification content is generic and does not include Gmail bodies or drafted customer replies. Operator permits provider access only as needed to operate, secure, or improve the relevant user-facing service, or as required by law. Operator personnel do not read Gmail content except with the user's explicit consent for a specific support purpose, when necessary for security or abuse investigation, or when required by law.

Maximus Sidoti may disclose information processed through Operator when reasonably necessary to comply with law, protect the service or users, investigate abuse, or complete a sale or transfer of all or part of the Operator service, subject to applicable notice and consent requirements. Google user data is not transferred to advertising platforms, data brokers, or information resellers.

6. Cookies and browser storage

Operator uses essential Supabase session cookies to authenticate users and an HTTP-only, short-lived OAuth state cookie to protect the Gmail connection flow. A local browser preference stores the selected Light, Dark, or System appearance. Operator does not currently implement advertising cookies or third-party behavioral advertising trackers.

7. Retention, Gmail disconnect, and account deletion

Operator retains account settings, minimized Gmail-derived records, opportunities, owner-edited drafts, notification records, and local billing state while the account exists and as needed to provide and secure the service. The repository does not define a separate fixed retention period for those records. Complete Gmail bodies are held in application memory only for request processing and are not stored as complete bodies in the Operator database; provider and operational logs follow the provider retention described above or applicable operational and legal requirements.

Disconnect Gmail: Settings allows you to disconnect Gmail without deleting the Operator account. Operator attempts to revoke the Google refresh token, then removes the local Gmail connection, encrypted credential, and connection-dependent sync and analysis records. Local credential deletion proceeds even if Google revocation is unavailable. Disconnecting does not delete messages from Gmail; account settings and billing records can remain.

Delete the Operator account: after exact email and acknowledgement confirmation, Operator expires open Checkout sessions, removes Operator ownership metadata from Stripe, cancels nonterminal Operator subscriptions, attempts Google revocation, and deletes the Supabase Auth user. A successful Auth deletion cascades through user-owned Operator records, including encrypted Gmail credentials, opportunities, drafts, preferences, notifications, and internal user-linked telemetry. If billing cleanup cannot complete, deletion fails closed rather than deleting the account while future billing remains active.

Stripe can retain customer, payment, invoice, dispute, and transaction records under its own financial, fraud-prevention, and legal obligations. Google retains Gmail messages because Operator never deletes them. See the Data deletion instructions.

8. Security

Operator uses PKCE, an expiring one-time OAuth state bound to the authenticated user, HTTP-only cookies, server-only OAuth exchange, AES-256-GCM encryption for stored refresh tokens, server-side authorization, forced database row-level security, same-origin mutation checks, bounded provider calls, and two-step human approval before Gmail send. Access and refresh tokens are not returned to the browser. No system can guarantee absolute security, and Operator does not make that guarantee.

9. Your choices and rights

You can review and edit communication settings and drafts, change notification preferences, pause monitoring, disconnect Gmail, and delete the Operator account from Settings. Depending on where you live, applicable law may provide rights to access, correct, delete, restrict, or object to processing of personal information, or to obtain a portable copy. Submit a request through the Support page. Operator may need to verify the request using the authenticated account email.

10. Children

Operator is a business service and is not directed to children. The Terms require users to be at least 18 years old and able to enter a binding agreement. Contact support if you believe a child provided personal information to Operator.

11. Changes to this policy

Operator may update this policy as the service or legal requirements change. The updated date will be revised, and material changes to how Google user data is used will be disclosed and, where required, presented for consent before the new use begins.

12. Contact and service operator

Operator is the public product and service name. The service is operated by Maximus Sidoti as an individual sole proprietor, without a separate LLC, corporation, or other legal entity.

Submit privacy questions or rights requests by email at shifubusiness78@gmail.com.