Privacy Policy
Last updated: June 10, 2026
This Privacy Policy explains how Dalgone Corp (“Dalgone”, “we”, “us”) collects, uses, and protects information when you use the Dalgone application, browser extension, and website (the “Service”). Dalgone connects your Gmail with your own Odoo instance — by design, your business data flows from your Gmail into your Odoo, not into ours.
1. Information we collect
- Account information. Name, email address, organization, and authentication identifiers (via our auth provider, Supabase).
- Odoo connection details. Your Odoo URL and API credentials, stored encrypted (AES-256-GCM envelope encryption) and used only server-side to act on your instructions. They are never sent to your browser or extension after you save them.
- Email data. When you use the Service on an email — for suggestions, attachment scanning, or logging — its content and attachments are processed on our servers to perform that action. Emails you save are PHI-scrubbed, then encrypted at rest (AES-256-GCM) and isolated to your tenant: the body and subject are encrypted, sender and date are retained to organize your archive, and attachments stay isolated to your tenant. We decrypt saved emails only to display them to you or to perform an action you invoke, and we do not sell them or use them to train AI models. Archived emails are kept for 90 days by default and then auto-deleted (we email you about 3 days beforehand); you can change or turn off that window, or delete them, at any time.
- Operational metadata. To make features work we store minimal pointers, not content: e.g., which Gmail message ID was logged to which Odoo record, learned sender-to-record-type preferences, sender-to-partner links, and usage counters (number of AI actions and logged emails).
- Billing. Payments are processed by Stripe; we do not store card numbers.
2. Google user data (Gmail) — Limited Use
With your explicit consent, the Service requests the following Gmail scopes, each used only to provide a feature you actively invoke:
gmail.readonly— to read the message you are working on and its attachments, so the Service can suggest matching Odoo records and copy the email and attachments into your Odoo at your request.gmail.send— to send the reply or forward you compose from the email archive. We send only the message you explicitly submit; we do not send on your behalf otherwise.
Dalgone’s use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.
- We only use Gmail data to provide user-facing features you actively invoke.
- We do not sell Gmail data, use it for advertising, or use it to train AI models.
- Humans do not read your Gmail data except with your consent for support, for security purposes, or as required by law.
- Google access tokens are used transiently per request and are not stored on our servers.
3. AI processing and personal-identifier screening
Some features send limited text to an AI provider (Anthropic) to extract document references — only when you invoke them and only when simpler methods fail. Before any text reaches an AI provider, the Service applies automated screening that removes patterns resembling government health numbers, social insurance/security numbers, and payment card numbers. AI providers process this data to return a result and do not use it to train models. Screening is automated and best-effort; do not use the Service to process data whose disclosure would be unlawful.
4. How we use information
To provide, secure, and improve the Service; to authenticate you; to enforce plan limits; to communicate with you about the Service; and to comply with law. We do not sell personal information, and we do not use your business data for advertising.
5. Service providers (subprocessors)
We use a small set of providers to operate the Service:
- Supabase — authentication and database (account + operational metadata)
- Railway — application hosting (transient processing)
- Vercel — website hosting
- Stripe — payments
- Anthropic — AI processing (screened text, per Section 3)
- Google — Gmail APIs (per Section 2)
- Plausible — privacy-friendly, cookieless analytics on our public website only (aggregate page statistics; no cookies, no personal identifiers, and nothing from inside the app or extension)
Each provider processes data only as needed to provide its function to us.
6. Security
Credentials are encrypted at rest with AES-256-GCM envelope encryption; tenant data is isolated with database row-level security; all traffic is encrypted in transit; access is restricted and logged. No method of transmission or storage is 100% secure, but we design the Service so that the durable copy of your business data lives in your own systems, minimizing what an incident at Dalgone could expose.
7. Retention and deletion
Account and operational metadata are retained while your account is active. On account deletion, we delete your tenant’s data (connection credentials, saved emails and attachments, links, learned preferences, counters) within 30 days, except minimal records we must keep for legal or billing purposes. Data already posted to your Odoo is yours and is unaffected. You may request access to or deletion of your personal information at the contact below.
8. International transfers and legal bases
We operate from Canada; our providers process data in North America (and, for some providers, other regions). Where Canadian (PIPEDA) or European (GDPR) law applies, we process personal information with consent, to perform our contract with you, and for legitimate interests in operating and securing the Service. You may have rights of access, correction, deletion, and portability; contact us to exercise them, and you may complain to your local privacy regulator.
9. Children
The Service is for business use and not directed to children under 16.
10. Changes
We will post updates here and, for material changes, notify you by email or in-app before they take effect.
11. Contact
Privacy questions or requests: privacy@dalgone.com.