Privacy Policy
Last updated: July 23, 2026
MARUBENI INFORMATION SYSTEMS CO., LTD. ("we," "us," or "our") operates "WinActor for Google Workspace" (the "Software"). This Privacy Policy describes how we handle Google account data and personal information in connection with the Software.
1. Information We Access
The Software accesses the following Google account information via OAuth 2.0:
- Email address and user identifier — to identify the authenticated account and manage sessions
- Google Drive files — to create, read, update, and delete files as specified in scenarios
- Google Spreadsheet data — to read and write cell values and manage sheets as specified in scenarios
- Gmail messages — to send emails, read received messages, and modify labels as specified in scenarios
2. OAuth Scopes Used
The Software uses the following Google API scopes:
openid— User authenticationhttps://www.googleapis.com/auth/drive— Access to Google Drivehttps://www.googleapis.com/auth/spreadsheets— Access to Google Spreadsheetshttps://www.googleapis.com/auth/gmail.modify— Send and read Gmail messages, modify labelshttps://www.googleapis.com/auth/userinfo.email— Read the authenticated user's email address
3. How We Use the Information
Accessed data is used exclusively for:
- Executing WinActor scenarios configured by the user (Drive, Spreadsheet, and Gmail operations)
- Managing OAuth tokens, including refreshing access tokens when they expire
- Identifying the authenticated account to support multiple-account management
We do not use your data for advertising, marketing, analytics, training machine learning models, or any purpose beyond the stated functionality above.
4. Data Storage
OAuth tokens (access tokens and refresh tokens) are stored exclusively on the user's local computer. We do not upload tokens or any Google user data to our servers or any cloud service.
- Storage location: Local file system of the machine running the Software (user-specified path)
- Storage format: Encrypted JSON file
- Access: Limited to the local user account running the Software
5. Sharing with Third Parties
We do not sell, share, or otherwise disclose Google user data to any third party, including our group companies, except as required by applicable law.
6. Data Retention and Deletion
Users can delete OAuth tokens at any time by using the "Delete Credentials" function within the Software. This removes the token from the local machine and revokes it with Google. Users may also revoke access directly from their Google Account settings.
- Manage third-party app access: https://myaccount.google.com/permissions
7. Security
The Software uses Google's standard OAuth 2.0 authentication. We never access or store the user's Google account password. Token files are protected by local operating system user permissions. We recommend following your organization's IT security policies for additional file access controls.
8. Google API Services User Data Policy
The Software's use of Google API Services adheres to the Google API Services User Data Policy , including the Limited Use requirements.
9. Children's Privacy
The Software is intended for business use within organizations and is not designed for individuals under the age of 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes take effect when posted on this page. Significant changes will be announced in the Software's release notes.
11. Contact Us
If you have questions about this Privacy Policy, please contact us via the form below:
MARUBENI INFORMATION SYSTEMS CO., LTD.
Contact form: https://www.marubeni-idigio.com/en/contact/corporate/index.html