Privacy Policy
F&M Engineering Services — Gmail Automation
1. Overview
This Privacy Policy describes how F&M Engineering Services ("we", "us", "our") handles information when you use our Gmail automation service, accessed through our self-hosted n8n workflow platform at n8n.fmes.online (or the equivalent internal address).
This policy applies specifically to the Gmail automation feature. Our engineering calculators (timber and wind) run entirely in your browser and do not collect or transmit your data — see the homepage for details.
By connecting your Google account to our automation service, you acknowledge and agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide
When you connect your Google account, you grant our application access to your Gmail data through Google's OAuth 2.0 system. The specific access scopes are determined by the Google OAuth consent screen and may include:
- Reading your emails (Gmail read access)
- Sending emails on your behalf (Gmail send access)
- Modifying labels and message metadata (Gmail modify access)
- Access to your Google Calendar (if calendar integration is enabled)
Gap: The exact OAuth scopes currently granted are not confirmed in this draft — verify against the active Google OAuth client configuration before publishing.
2.2 Information We Process Automatically
When you configure and run workflows, our system may process the following types of data from your Google account:
- Email messages (headers, body content, attachments)
- Email labels, folders, and metadata
- Calendar event information (if calendar access is granted)
- Workflow execution logs containing data passed between steps
2.3 Information We Do Not Collect
- Our engineering calculators do not send any data to our servers — all computation happens in your browser.
- We do not collect personal data through the public website (homepage, privacy policy, terms of service pages) beyond standard server access logs.
3. How We Use Your Information
We use the information accessed through your Google account solely for the purposes you configure in your workflows, including:
- Automating email processing according to your workflow rules
- Filtering, labeling, and organizing emails
- Sending automated email responses or notifications
- Integrating Gmail data with other tools in your workflow
We do not use your email content, attachments, or personal data for any purpose unrelated to the workflows you create and run.
4. Google API and Third-Party Access
4.1 Google API Limited Use
Our application uses Google APIs (Gmail, and potentially Calendar) pursuant to Google's API Terms of Service and the Google API User Data Policy. We commit to the Limited Use requirements, which prohibit using Google Workspace API data for:
- Advertising or marketing purposes
- Training general-purpose AI models not specific to your workspace
- Any use not explicitly permitted by your authorization
4.2 Third-Party Services
Our n8n automation platform may connect to third-party services as part of your workflows. When you configure a workflow that sends data to a third-party service, that data is processed by the third party according to their own privacy policies. We are not responsible for third-party data handling.
Gap: The full list of third-party services your workflows connect to is not enumerated in this draft — update this section to list each integrated service before publishing.
5. AI and External Processing
Gap: This section requires confirmation. If any workflow step sends email content or personal data to an external AI provider (e.g., for summarization, classification, or generation), that must be disclosed here with the provider name, data types sent, and purpose. If no AI processing is used, state that explicitly.
As of this draft, we have not confirmed whether external AI providers are used. Do not publish this policy until this is verified.
6. Data Retention and Security
6.1 Retention
Data accessed through your Google account is retained only as long as needed to operate your workflows and for the period you configure in your workflow settings. Execution logs may be retained for troubleshooting purposes.
Gap: Specific retention periods for tokens, email data, execution logs, and backups are not yet defined — set explicit retention periods before publishing.
6.2 Security
Our n8n instance runs on a self-hosted server with the following measures:
- HTTPS encryption in transit (when accessed via Cloudflare tunnel or direct TLS)
- Encrypted credential storage for OAuth tokens (Fernet/AES encryption at rest)
- Authenticated access to the n8n web interface
Gap: The full security measures are not verified — confirm TLS configuration, access controls, backup encryption, and network isolation before claiming specific safeguards.
6.3 Token and Credential Handling
Google OAuth access tokens and refresh tokens are stored encrypted in our n8n instance. Tokens are used only to access your Google data on your behalf and are not shared with any other party.
6.4 Data Deletion
You may disconnect your Google account at any time from the n8n credential management screen. Disconnecting revokes our access to your Google data. Workflow execution logs stored on our server may persist until manually deleted or until retention policies are applied.
Gap: The procedure and timeframe for requesting deletion of stored logs and data is not defined — establish a deletion request process and response timeframe before publishing.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your data, subject to legal retention obligations.
- Opt-out: Disconnect your Google account at any time to stop data access.
To exercise these rights, contact us at the email address in Section 9. We will respond within a reasonable timeframe.
Gap: Formal data subject request procedure and statutory response timeframe are not defined — align with applicable privacy laws (e.g., Australian Privacy Act, GDPR if applicable) before publishing.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the policy page. The "Effective" date at the top of this document will be updated when changes are made.
9. Contact Us
Email: fmecc02@gmail.com
For privacy-related questions, concerns, or data requests.
- Legal operator name: The legal entity name behind "F&M Engineering Services" is not confirmed. The policy currently uses the trading name only.
- Business address: A physical or mailing address is not provided. Privacy laws in some jurisdictions require this.
- Effective date: Not confirmed. Replace
[TBD]with the actual date before publishing. - OAuth scopes: The exact Google API scopes in use must be verified against the active OAuth client configuration.
- Workflow data handling: Confirm which workflows read email content, access attachments, apply labels, send mail, or delete mail — and reflect that accurately.
- Third-party services: Enumerate all external services integrated by your workflows.
- AI processing: Confirm whether any external AI provider is used and, if so, disclose it. If not, state that explicitly.
- Retention periods: Define explicit retention periods for tokens, email data, execution logs, and backups.
- Data deletion procedure: Define the process and response timeframe for deletion requests.
- Security measures: Verify TLS, access controls, backup encryption, and network isolation before claiming specific safeguards.
- Applicable law: Determine which privacy law applies (e.g., Australian Privacy Act 1988, GDPR) and ensure the policy complies.