Privacy Policy
Privacy Policy
Cowork Fatima OS · Last updated 19 September 2026
Cowork Fatima OS is a private bookkeeping tool. It is not a public product and is not offered to third parties. It is operated by the owner of this domain and used solely to collect that owner's own invoices and receipts from their own email accounts and file them into their own Google Drive.
What the application accesses
The application requests two Google API scopes:
-
gmail.readonly— read-only access to the authorising Gmail account, used to find invoices and receipts and download their attachments. The application cannot send, modify, label or delete email. -
drive— used to upload the collected documents into a folder in the owner's own Google Drive, and to read back that folder to avoid creating duplicates.
What is stored, and where
- Invoice and receipt documents are stored in the owner's own Google Drive.
- A local index is kept on the owner's own computer, recording for each document the supplier, date, source mailbox, filename and a content checksum used to detect duplicates.
- OAuth refresh tokens are stored locally on that same computer so the application can run on a schedule. They are not transmitted anywhere.
No data is stored on any server operated by this application. There is no hosted backend, no database in the cloud, and no account system.
What is not done
- Data is never sold, rented or shared with third parties.
- Data is never used for advertising or profiling.
- Data is never used to train machine learning models.
- There is no analytics, tracking or telemetry of any kind.
- No other person's mailbox is accessed — only accounts the owner authorises.
Limited Use disclosure
The use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Documents remain in the owner's Google Drive until the owner deletes them. Local tokens and the local index can be deleted at any time by removing the application's folder. Access can be revoked at any moment from myaccount.google.com/connections, which immediately and permanently ends the application's ability to read any mailbox.
Contact
Questions about this policy: qfmomen@gmail.com