Privacy Policy
This is an English reference translation. The Japanese version is the official version, and it prevails if there is any difference.
Your data is safe
We don't store email bodies on our servers
They're used only while posting to Slack and drafting with AI, and deleted as soon as that's done.Not used to train AI
Your content is never used for training, and we tell OpenAI not to store the exchanges (store: false), keeping data on the AI vendor's side to a minimum.Draft bodies are deleted after 30 days
The body of a draft you edit in Slack is deleted 30 days after its last edit. Drafts saved to Gmail stay in Gmail.Never used for ads or sold
Following Google's API Services User Data Policy, email bodies are used only to show them in Slack and draft replies with AI, and our staff do not read them (except in the cases set out in our privacy policy).
STUDIO SPOON Inc. (“we”, “us”) has established this Privacy Policy (this “Policy”) to explain how we handle users’ personal and usage information in connection with our service SuccocoPon (the “Service”).
1. Information we collect
The Service collects the following information to provide its features.
1.1 From your Google account
- Email address, name and profile picture (for sign-in)
- Gmail message headers, bodies and attachments (only for emails with the labels you choose)
- Your list of Gmail labels (for setting up forwarding rules)
- Profile information of contacts (the sender’s picture and display name) (obtained through the Google People API scope
contacts.other.readonlyand used to show the sender’s icon in Slack notifications) - OAuth refresh tokens (for continued API access)
1.2 From your Slack workspace
- Workspace ID, list of channels, and basic user information (display name, email address)
- Bot token
1.3 Generated through use of the Service
- Identifiers of ingested messages (Gmail message ID, thread ID)
- Subject and sender of messages (as a record of forwarding)
- Draft bodies and your instructions to the AI (for up to 30 days after the last edit)
- The list of links in an email, kept to summarize the linked articles (only when article summaries are turned on for a forwarding rule; for up to 30 days after creation)
- Identifiers of created Gmail drafts
- Operation logs and audit logs (who did what and when)
2. How we use information
We use the information only for the following purposes:
- Showing incoming emails in Slack channels
- Generating reply drafts with AI and saving them as Gmail drafts
- Summarizing articles linked from newsletters (only when turned on for a forwarding rule: we fetch the linked articles, summarize them with AI and post the summaries to Slack)
- Configuring forwarding rules and understanding how the Service is used
- Detecting abuse and keeping the Service secure
- Incident response and customer support for the Service
- Improving the Service (creating statistics that do not identify individuals)
3. Compliance with the Google API Services User Data Policy (Limited Use)
SuccocoPon’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Data obtained from Google APIs (Gmail and Google Contacts) is used only to provide the user-facing features listed in Section 2 of this Policy.
- We do not transfer or sell this data to third parties, except for showing it in Slack at your instruction and sending it temporarily to our AI model provider (see Section 4).
- We do not use this data for advertising.
- We do not use this data to develop, train, or improve AI or machine-learning models. The OpenAI API we use for AI processing does not use submitted content for training by default, and we additionally use the
store: falsesetting to minimize the history stored by OpenAI. - No human reads this data unless (a) you have given explicit consent, or (b) it is necessary for security investigations, responding to violations, or complying with applicable law. In either case, access follows appropriate procedures and is limited to the minimum necessary.
Data received from Slack, including your instructions to the AI, is likewise not used to train AI or machine-learning models.
4. Service providers (sub-processors)
We use the following external services to provide the Service. Each provider handles user data under its own privacy policy and data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting of the Service | United States |
| Neon Inc. | Database of the Service | United States (AWS region) |
| OpenAI, L.L.C. | Generating AI reply drafts and article summaries (store: false so that exchanges are not stored; not used for training) | United States |
| Google LLC | Sign-in and Gmail integration (new-mail notifications / saving drafts) | United States |
| Slack Technologies, LLC | Slack integration | United States |
5. Retention
- OAuth tokens: until you disconnect. You can disconnect at any time yourself from the “Connections” page of the Service. We delete them at that point and also revoke the access you granted to Google and Slack. The same applies when an organization’s data is deleted.
- Email bodies: never stored permanently. They are held in memory only briefly for posting to Slack and generating AI drafts, and discarded immediately after processing. Attachments and the original HTML of emails are not stored either; they are discarded as soon as they have been posted to Slack.
- Subject and sender of messages: kept as a record of forwarding, for the same period as “forwarding settings and conversation metadata” below. Records of emails that were not delivered by any forwarding rule are deleted after 30 days. We do not store any part of the body (snippets).
- Forwarding settings and conversation metadata: kept while the contract is active, and deleted within 30 days after the contract ends.
- Sender display names and profile-picture URLs: a copy is kept to show icons when posting to Slack, and deleted 90 days after it was last retrieved (messages already posted to Slack are not affected).
- Audit logs: kept for 1 year.
- Draft bodies and instructions to the AI: kept for editing in Slack and saving to Gmail, and deleted 30 days after the last edit (drafts saved to Gmail remain in your Gmail). Content sent to the AI is kept by OpenAI for up to 30 days for abuse monitoring and then deleted automatically.
- Link lists for article summaries: kept to post the summaries to Slack, and deleted 30 days after creation. The text of fetched articles is not stored.
6. Security measures
- The database, including OAuth tokens, is protected by Neon (Postgres) encryption at rest (AES-256)
- All communication uses HTTPS
- Staff access is limited to what is needed for work, and operations are recorded in audit logs
- We have appropriate data processing agreements with our service providers
- We run vulnerability scans regularly
7. Your rights
You may exercise the following rights with respect to the Service:
- Request access to your information
- Request correction of incorrect information
- Request a copy of your information in a portable format
- Disconnect from the Service (revoke OAuth connections; you can do this yourself from the “Connections” page)
- Request deletion of your account and the related data
Please contact us at the address below for these requests. We will generally respond within 30 days.
You can also revoke the Service’s access at any time from your Google account’s third-party app access page.
8. Cookies and session information
The Service uses authentication cookies to keep you signed in. We do not use tracking cookies or third-party cookies.
9. Children
The Service is intended for business use and is not intended for use by anyone under 13.
10. Changes to this Policy
We may revise this Policy as the Service changes. We will announce important changes in advance on the Service or by email to your registered address.
11. Contact
For questions about this Policy or data requests, please contact:
STUDIO SPOON Inc.
E-mail: info@succocopon.com
Service URL: https://www.succocopon.com
Effective date: 2026-05-15 / Last updated: 2026-09-30