PCC Mail

Privacy policy

Effective September 14, 2026. This notice covers PCC Mail’s handling of Google Mail, Calendar, and personal-contact data.

Data PCC Mail can access

When the operator separately enables Pristine Source Trust, PCC Mail uses the Gmail API read-only scope for one enrolled Pristine mailbox. It can read stable message and thread identifiers, labels, headers, snippets, message bodies, provider history identifiers, deletion evidence, and attachment metadata. It does not download attachment bytes or interpret attachment contents in Release 1, and this grant cannot send, draft, delete, label, or otherwise mutate mail.

For an account whose operator has enabled Google productivity access, PCC Mail uses the Google Calendar API to read calendar metadata, events, and busy intervals, and to create or change events when explicitly requested. Event data can include titles, descriptions, locations, times, organizers, attendees, recurrence information, and provider identifiers.

PCC Mail uses the Google People API to search and read the user’s personal contacts, and to create or change personal contacts when explicitly requested. Contact data can include names, email addresses, phone numbers, organizations, job titles, postal addresses, birthdays, notes, timestamps, and provider identifiers.

The Calendar/People integration does not search Google organization directories, directory profiles, or Google “Other Contacts.” Its OAuth grant is separate from the dedicated Gmail read-only Source Trust grant.

How data is used

Calendar and contact data is used only to complete operations initiated by the authenticated PCC Mail client for the explicitly selected account. Source Trust mail data is read by the operator-enabled background sync only to maintain durable Pristine mail evidence and is returned only through its separately scoped authenticated reader. Writes are sent only when a client calls an existing calendar, contact, or mail write operation and satisfies its validation and confirmation requirements; the Source Trust grant cannot write.

Storage and retention

Google refresh tokens and OAuth client credentials are kept only in the deployment platform’s secret store. Short-lived access tokens are cached in process memory and are not persisted in SQLite.

When Pristine Source Trust is enabled, PCC Mail stores normalized message evidence and append-only content revisions, provider IDs and checkpoints, coverage and sync-run records, deletion tombstones, and attachment discovery metadata in its protected persistent SQLite volume. Attachment bytes are not stored. Disabling ingestion or revoking Google access stops future reads but does not silently erase this durable evidence; the service operator controls its retention, backups, and deletion.

PCC Mail does not persist raw event descriptions, attendee lists, contact notes, names, addresses, phone numbers, or other calendar/contact request content in its mutation ledger. The ledger retains bounded operational metadata such as the selected account, operation, request fingerprint, outcome state, opaque provider resource identifier, concurrency version, and timestamps so retries do not duplicate writes.

Provider records remain subject to the user’s Google retention controls. Authorization remains until the user revokes PCC Mail in their Google Account or the operator removes the credential. Operational ledger metadata remains until the service operator removes it under the service’s retention practices.

Sharing and transfer

PCC Mail transmits data only to Google APIs as necessary to perform the requested operation, to an authenticated client holding the required account-specific scope, and through infrastructure required to operate the private service. The Pristine evidence reader is confined to the enrolled mailbox and cannot enumerate other configured accounts. PCC Mail does not sell Google user data, use it for advertising, build advertising profiles, or use it to train general-purpose artificial-intelligence models.

Security controls

The service requires an explicit configured account before provider access, uses provider-specific least-privilege authorization, keeps credentials out of its database, sanitizes provider errors, and excludes calendar and contact content from application logs. Access can be revoked through the user’s Google Account security settings and by removing the account credential from the deployment secret store.

Google API Services User Data Policy

PCC Mail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Questions or deletion requests

Use the support contact displayed on the Google OAuth consent screen to request removal of the PCC Mail authorization or associated operational metadata.