Privacy Policy

Big Shot OS · Last updated September 17, 2026

Big Shot OS ("we", "us") provides a business operating system (CRM, invoicing, projects, scheduling, and related tools) to businesses ("you"). This policy explains what we collect, how we use it, and your choices. Questions: [email protected].

Information we collect

How we use it

Google user data (Gmail)

If you choose to connect a Google account, Big Shot OS asks for these Gmail permissions, and uses each only for the in-app email features you use:

Changes in Gmail happen only because you made them. Big Shot OS changes your Gmail only to mirror an action you take yourself in the Big Shot OS inbox:

Big Shot OS makes no other changes in Gmail and runs no background changes of its own. Marking a message read or unread, flagging, and archiving currently change the copy in Big Shot OS only.

A Gmail account connected before the organize permission was added keeps read and send access only until you reconnect it. Until then, moving and deleting its messages change the copy in Big Shot OS only, and nothing in that Gmail account is changed.

No permanent deletion at Google. Big Shot OS never permanently deletes a message from your Google account and never bypasses your Gmail Trash. The gmail.modify permission does not allow that, and we do not request the full-access https://mail.google.com/ permission that would.

Emptying the Trash in Big Shot OS permanently removes our copy of those messages, including the message body. We keep a minimal record of the removed message (its technical message identifier and the mailbox it came from, not its content) so that the next sync does not import it again. It does not delete anything further in your Gmail: a message you deleted is already in your Gmail Trash, where Gmail's own 30-day rule applies.

While a mailbox stays connected, mail you do not delete is kept in Big Shot OS as an archive, and stays available to you even if it is later removed from the connected mailbox. You can permanently delete our copy at any time, or ask us to erase your data as described under Your choices.

Disconnecting. You can disconnect Google at any time from Settings → Integrations. When you do, we revoke Big Shot OS's access with Google (the app is removed from your Google Account's list of third-party connections), stop accessing and changing your Gmail, and delete the stored Google access and refresh tokens. The copy of that mailbox's mail already stored in Big Shot OS is kept for 30 days after you disconnect, so reconnecting within that time restores it, and is then permanently deleted. You can ask us to delete it sooner, as described under Your choices.

How Google user data is handled (Limited Use)

Big Shot OS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will also adhere to the Google Workspace user data and developer policy. Specifically, Google user data:

AI and machine learning. We do not use Google user data, or data received from Google Workspace APIs, to create, train, or improve any machine-learning or artificial intelligence model, and we do not transfer it to anyone for that purpose. If you choose to use an AI feature on a message (for example, "AI Reply"), the text of that message is sent to the AI service that powers the feature (Anthropic's Claude, unless your workspace administrator has chosen another) only to produce the result you asked for, under terms that do not permit that service to train its models on it.

Google Calendar

If you choose to connect Google Calendar, Big Shot OS requests read-only access (calendar.readonly) to list your calendars and read their events, so your schedule appears alongside your tasks and jobs in the app's unified calendar. We use openid and email only to label which account you connected. Big Shot OS never creates, edits, or deletes anything in your Google Calendar. Calendar data is handled under the same Limited Use terms as Gmail data above, and disconnecting stops access and deletes the stored tokens.

Microsoft / Outlook data

If you connect a Microsoft account, we access your Outlook mail solely to power the same in-app inbox and sending features, under the same handling: stored securely, associated only with your account, never shared with other customers, and never used for advertising.

Big Shot OS never permanently erases mail from your Microsoft account, and emptying the Trash in Big Shot OS removes only our copy, as described for Gmail above. You can disconnect at any time, which stops access and deletes the stored tokens; mail already copied into Big Shot OS is permanently deleted 30 days later, as described for Gmail above.

QuickBooks / Intuit data

Data accessed through the Intuit QuickBooks Online API is used solely to deliver the connected features within your own workspace, is stored securely, is associated only with your account, and is never shared with other customers. You can disconnect QuickBooks at any time from Settings → Integrations; on disconnect we stop accessing your QuickBooks data and remove stored Intuit access tokens.

Bank connections (Plaid)

We use Plaid Inc. to let you securely connect your bank and financial accounts. With your authorization, Plaid provides us your account balances and transaction history so we can display your accounts, forecast cash flow, and reconcile payments within your workspace. By connecting an account you also agree to Plaid's End User Privacy Policy. Plaid data is used solely to provide these features, is stored securely, is associated only with your account, is never shared with other customers, and is never used for advertising. You can disconnect a financial institution at any time; on disconnect we stop accessing it, instruct Plaid to remove the connection, and delete the stored access tokens.

Storage, security, and retention

Data is stored in access-controlled databases with tenant isolation; credentials and tokens are encrypted. We retain data while your account is active and delete or anonymize it on request or a reasonable period after account closure.

Sharing

We share data only with service providers that help us run the service (database hosting, application hosting, email delivery, and the AI service named above) under confidentiality obligations, and where required by law.

Your choices

Changes

We may update this policy and will revise the date above. Continued use means acceptance of the updated policy.

Contact: [email protected]