Privacy policy
Last updated September 12, 2026 · Version 2026-09-12
Automations247 is operated by Praveen Lokesh. This policy covers automations247.com, its connected computer workers and its management apps. Contact praveen.lvnp@gmail.com for privacy, access or deletion requests. Do not send passwords or API keys.
This policy explains our processing for account administration and operation of the service. When you use bots to process other people’s information, you are responsible for having the necessary authority and notices. Contact us before using sensitive or regulated data that requires a separate processing agreement.
What we collect and why
- Account and security: your email, a password hash, login sessions, paired-device records and connection status let you sign in and control only your authorized workspaces. We use necessary login cookies and local application storage.
- Your work: company profiles, bot instructions, messages, memories, tasks, routines, tool results, usage records and files or screenshots requested during a task let your team perform and remember the work you assign.
- Connected services: the identity, permissions and authorization tokens for accounts you connect let approved bots use the selected features. Relevant service content can become part of a saved task, result or memory.
- Support and testing: TestFlight requests include your name, testing email and device choice. Optional diagnostic reports include only the fields you review before submitting.
Google data and permissions
Google connections are optional and belong to the company you select. Google’s consent screen lists the permissions requested. You choose the connected account, connector access level and bots that can use it.
- Gmail: read message and thread content and metadata to find, summarize or respond to mail. If you enable additional access, tasks can prepare drafts, send messages or organize messages and labels.
- Google Calendar: read calendars and events to check schedules and availability. With write access, tasks can create, update or cancel events.
- Google Drive: search file metadata and read supported file contents, including Google Docs, Sheets and Slides, for requested tasks. The current connector is read-only.
- Google Business Profile: read managed business locations, reviews and existing replies. With the required access and task authorization, publish or update review replies. Google project approval is a separate requirement.
Automations247 uses Google data only to provide the user-facing connected features you request. We do not sell it, use it for advertising or use Google Workspace API data to develop, improve or train generalized AI or machine-learning models. Automations247’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Human access to Google data is limited to your affirmative agreement for specific data, security needs, applicable legal obligations, or aggregated and anonymized internal operations as permitted by that policy. Connecting Google does not make your mailbox, calendar or files public.
AI processing and third parties
To carry out your instructions, relevant prompts, memories, connected-service content, tool results and requested screenshots may be sent to the AI connection you select. Cloud processing currently uses OpenAI through your own API key or supported ChatGPT connection. Eligible text work may instead use an optional local model on your assigned computer; other steps can still use the selected cloud connection.
Your provider’s account terms, privacy settings and retention rules also apply. You must use provider settings that prevent connected Google Workspace data from being used for generalized model training. Automations247 cannot verify or change your provider’s training settings for you. Local AI does not make an entire workflow local or prevent its task history from being saved on the server.
Our hosting provider, DigitalOcean, stores the hosted service data. Google and other services you connect receive the API requests and content needed for your requested actions. An enabled MCP service receives its tool arguments. Apple Push Notification service, Google Firebase Cloud Messaging and web push delivery services receive device or subscription identifiers, opaque routing identifiers and generic task-update notifications. Delivery does not give those providers access to the task conversation. Your operating system may display notifications on its lock screen; you control that in device settings. We do not include advertising SDKs or advertising tracking identifiers.
Optional analytics and device storage
Essential cookies and app storage keep you signed in, remember your selected company, pair computers and apply security or accessibility choices. These are needed for the service. You can clear them using your browser or device, which may sign you out.
Product analytics is off until you allow it on the device. Declining does not affect your bots or free beta place. Allowed events contain only a random session identifier, a broad page or screen category, platform, download-button category, notification-open event or a bounded amount of active time. They exclude chat text, company and bot names, task titles, file contents, screenshots, URLs, search terms, passwords, API keys, email addresses and advertising identifiers.
Our server retains these events for up to 30 days and shows aggregate counts to the owner. Events from a signed-in session are associated internally with that account to support deletion; they are not anonymous. Request IP addresses are needed to deliver the service and prevent abuse but are not included in analytics records. If Google Analytics delivery is configured, these coarse events and random session identifiers are forwarded to Google without your account identifier or IP address. Google’s processing and retention settings also apply; aggregated reporting can remain after individual events expire. We do not enable advertising personalization or share connected Google account content with analytics.
Choose Privacy choices here or in Settings to change the choice for this browser or app. Turning it off stops future optional events; request deletion for earlier records. The website also honors Global Privacy Control and Do Not Track by leaving optional collection off. Native analytics has its own off-by-default switch. Notification permission is separate from analytics permission.
Where data is stored and who can see it
Hosted account records and task history are stored on our server. Each account has a separate database and vault key. Company-scoped conversations, connections, instructions and memory are kept separate within your account. API keys and connection tokens are encrypted in the account vault. Connections to the hosted service use HTTPS.
Browser profiles, website sign-ins and workspace files normally remain on the assigned computer. Content requested by a task or opened or downloaded through the dashboard travels through the service. Optional searchable document text is saved on the server. A reviewed computer-to-computer file transfer stores encrypted prepared bytes for up to 24 hours.
The owner’s admin panel shows account emails, bot names, task titles and statuses, routine names and schedules, computer connection status and usage totals, plus aggregate optional product engagement counts. It does not expose conversations, file contents, screenshots or credentials. Server administrators have technical access to hosted records and vault keys outside that panel; this service is not end-to-end encrypted against its operator.
Project sharing reveals only the text you explicitly publish and human comments to the people you invite; comments show the author’s email. Guests do not receive your computer, credentials or private bot conversations. A recipient may retain a copy they have already seen.
Retention and deletion
Saved work remains available for ongoing conversations and routines until you remove it or delete your account. Disconnect a service in Connections to remove its stored authorization. You can also revoke Google access from your Google Account connections. Disconnecting stops future connector use; it does not remove content already saved in task history or undo actions on an external service.
Settings → Account data & deletion provides export and account-deletion controls. Account deletion revokes paired devices and removes active hosted account records, credentials, shared material owned by that account, and administrative activity tied to it. An anonymous used-beta-place count remains without the deleted account link. Local files, downloaded models and browser profiles remain on your computer until you remove them.
Earlier server database backups expire through a seven-copy rotation; these backups are stored on the same server, not offsite. This is a copy-count retention rule, not a guaranteed seven-day deletion period. The latest 10,000 administrative activity events are retained; deployment history is retained separately. Optional diagnostic drafts and shared reports can be withdrawn and deleted. Privacy or deletion requests can also be sent to the contact above.
Your controls
You can pause tasks and routines, revoke devices, change bot and connector access, review remembered approvals, disconnect services and delete your account. Initial screen-recording, accessibility and other operating-system permissions are granted on your computer. Permission revocation may stop work that requires that access.
Privacy requests, security and international processing
Contact praveen.lvnp@gmail.com to request access, correction, export or deletion, withdraw consent, raise a grievance, or ask about a legally available right. We verify ownership using proportionate information; never email your password or API key. Where available under applicable law, you may complain to the relevant data-protection authority. We do not sell personal information or use it for targeted advertising.
We process information to provide the service you request, protect accounts, meet legal obligations and, for optional features, act on your consent. Your information may be processed in countries where our hosting and selected providers operate. Contact us before transferring data that requires a specific location or contractual safeguard. Encryption, access restrictions and revocable permissions reduce risk, but no system is completely secure. We will address security incidents and notify affected users or authorities when required by applicable law.
Age requirement
The service is intended for adults aged 18 or older and is not directed to children. Contact us if a child has provided personal information so we can investigate and remove it where required.
Policy updates
We will update the date on this page when the policy changes. Material changes will be described in the application’s update information. Changes to the product’s name or domain do not create a new account or authorize broader use of your connected data.