Our approach
We design Skillpack to keep your workspace under your control. We collect and use information needed to provide the Skills Hub, authenticate members, and keep the service secure. This policy focuses on the Gmail integration and its data practices; your organization may also host its own Skillpack deployment and set additional rules for its workspace.
Data access
When you connect the Gmail integration, Skillpack requests exactly two OAuth scopes and no others: gmail.readonly (read your mailbox) and gmail.compose (create drafts). No Gmail send, delete or modify permission is ever requested, and no other Google service is accessed.
Data use
These permissions are used solely to let your AI assistant, at your direction: search and read email threads to answer questions and summarize conversations; and create drafts in your own mailbox for you to review and send yourself. Skillpack never sends email on your behalf — drafts are created in your own Gmail mailbox and you send them yourself.
Data sharing
Your Gmail data is accessed directly from Google's Gmail API through Google's hosted Gmail endpoint. It is never sold, rented, shared, transferred, or disclosed to any third party other than Google. It is never used to train machine learning models, never used for advertising, and never combined with other data. The only copy of Gmail content that exists outside Google is inside your private Skillpack conversation transcript, which is visible only to you and workspace members you explicitly invite, and is never shared.
Data protection
Your OAuth access and refresh tokens are stored encrypted at rest using envelope encryption, are never returned by any API, and are never logged. All data access is scoped by organization with forced row-level security and least-privilege database roles. All transport uses TLS. You can revoke access at any time by disconnecting the Gmail integration in Skillpack settings or via your Google Account permissions page — revocation deletes stored credentials immediately.
Retention and deletion
OAuth credentials are retained only while the Gmail integration remains connected. Disconnecting the integration — or revoking access from your Google Account permissions page — deletes stored credentials from our systems immediately and permanently. Gmail content referenced in a conversation transcript is retained only as long as your Skillpack conversation exists, and is permanently deleted when you delete the companion or the conversation. Deleting your account deletes all associated data, including stored credentials and transcripts.
Your choices and contact
You can disconnect Gmail from Skillpack settings or revoke it through your Google Account permissions page. You can delete your Skillpack, conversation, or account using the controls available in the product. For questions about this policy or a privacy request, contact the administrator for your Skillpack workspace or The Vibe Company through its public website.