Zora Workspace Assistant Privacy Policy
Effective date: September 29, 2026.
This policy describes Zora Workspace Assistant, an AI-assisted productivity tool operated by Luxmana Investments, LLC ("Luxmana," "we," or "us") for the operator and explicitly authorized users. It covers Google Workspace data accessed by the assistant. Other websites and services have their own policies.
1. Information we access
When you authorize a Google account, the assistant receives OAuth credentials and account identity information. Depending on the permissions you grant and the work requested, it may access:
Gmail messages, headers, recipients, attachments, drafts, labels, and basic mail settings.
Calendar details, events, attendees, and scheduling information.
Drive files and their contents and metadata, including Google Docs, Sheets, and Slides.
Read-only Google Contacts information.
Google Tasks and supported Google Meet space information and settings.
Your instructions, assistant responses, and records needed to operate and troubleshoot workflows.
Not every task requires all available data. Granted access and actual use are distinct. This integration does not request Google Workspace administrator privileges or Google Meet media-capture permissions.
2. How information is used
We use information to provide requested assistance, such as email summaries and drafts, approved communications, scheduling, document and spreadsheet work, task management, and specifically authorized automations. We also use operational records to maintain service reliability, investigate errors, and protect account access. Sensitive actions require an explicit instruction or a previously approved workflow.
3. AI processing and service providers
The assistant operates outside Google's infrastructure. Relevant Google data and user instructions may be transmitted to configured AI model providers for inference and to hosting, messaging, or other service providers needed to fulfill an authorized workflow. Provider selection can vary by task and configuration. Information returned through a messaging channel is also processed by that channel's provider. Do not assume that data stays solely within Google or solely on your device.
Access and disclosure should be limited to what is needed for the requested service. Authorized operators may review information for approved assistance, security, support, and troubleshooting. We do not sell Google user data or use it to target advertising.
4. Google API Limited Use
Zora Workspace Assistant's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data must not be used to develop, improve, or train generalized AI or machine-learning models. Service-provider arrangements and settings must support these restrictions before production use under this policy.
5. Storage and safeguards
OAuth tokens, service credentials, workflow artifacts, and operational records may be stored on the operator's managed infrastructure. Depending on the workflow, records may include conversation history, logs, generated files, and configured memory or retrieval systems. Accounts use separate credential files where configured. Access is restricted to authorized operators and necessary service components. Credentials must not be placed in public pages or source-code repositories. No system can guarantee absolute security.
6. Retention and deletion
Information is retained as needed for authorized work, continuity, security, and applicable legal or business-record obligations. Different stores, backups, and providers can have different retention periods; this policy does not specify a uniform automatic deletion deadline. To request deletion of assistant-held data or disconnection of an account, contact admin@luxmana.com. Requests are reviewed for scope, identity, technical feasibility, and any required retention. Provider-controlled copies and backups may follow separate deletion schedules.
7. Your choices and revocation
You can decline authorization or revoke the assistant's Google access through Google Account connections. Revocation prevents future access through that authorization but does not automatically delete information already copied into conversation history, generated documents, logs, or other systems. Contact us separately for deletion requests. Workspace administrators may impose additional access restrictions.
8. Experimental Gmail reconstruction
The planned thread-reconstruction feature is experimental. Initial testing uses selected test conversations and preserves original messages. Reconstructed messages are copies and may have changed subjects, identifiers, or threading headers. We will not treat testing authorization as permission to rewrite or delete unrelated historical business correspondence. A future extension's permissions and data handling will be reviewed separately before release.
9. Changes and contact
We will update this policy when material changes to the service or data practices require it and identify the effective date of the updated policy. Privacy, support, access, and deletion requests may be sent to admin@luxmana.com.
