CoworkingSpace.ai — Sales Intelligence

Location configuration unavailable

← Back to Prospector

Privacy Policy

Effective Date: August 17, 2026

1. Overview and Core Purpose

Prospector ("we", "our", or "the Service") provides intelligent local business research, commercial occupancy signals, and sales workflow automation for workspace operators. This Privacy Policy explains how we handle personal data, operator credentials, and third-party platform integrations (including Google Workspace and Microsoft 365).

2. Google API & Gmail Limited Scope Disclosure

When an authorized operator connects their Google Workspace or Gmail account to Prospector:

  • User-Authorized Access Only: Mailbox connectivity occurs solely after an authenticated operator explicitly grants consent via Google's OAuth authorization screen.
  • Minimal & Restricted Scopes: In Phase 1, Prospector requests only basic identity (openid, email, profile) and the send scope (https://www.googleapis.com/auth/gmail.send).
  • No Inbox Reading: Prospector does not request or use read, modify, or manage permissions for your Gmail inbox in Phase 1. We do not read, search, or index your private email messages.
  • Human-Approved Sends Only: Prospector never sends automated or unapproved messages through your Gmail account. Every outbound communication requires explicit review and clicking "Approve & Send" by the authenticated operator.
  • Google Limited Use Compliance: Prospector's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • No Data Selling: We never sell Google user data or transfer it to data brokers or advertising networks.

3. Microsoft 365 & Outlook Integration

When an operator connects Microsoft 365 or Outlook, we request delegated Mail.Send permissions under standard delegated user authentication. The token is used exclusively to transmit operator-approved sales emails on behalf of the signed-in user.

4. Token Storage and Encryption

All OAuth access and refresh tokens are encrypted at rest using server-side AES-256-GCM authenticated encryption (OAUTH_TOKEN_ENCRYPTION_KEY). Plaintext tokens are never stored in databases, never logged, and never transmitted to client-side browsers.

5. Multi-Tenant Isolation

Mailbox connections are strictly scoped to the specific authenticated user, location, and organization. An operator's connected mailbox is never accessible or usable by any other user or organization.

6. Disconnection and Data Deletion

Operators can disconnect their Google or Microsoft account at any time directly in Settings → Sales Mailbox by clicking "Disconnect". Disconnecting immediately revokes token usage and purges encrypted tokens from our records.

To request permanent deletion of your account data or integration logs, contact support at support@coworkingspace.ai.

7. Changes to this Policy

We may update this Privacy Policy to reflect system enhancements or regulatory changes. Any material updates will be published with an updated effective date.