Skip to content
Private development testing · September 9, 2026

Athena privacy notice

This notice describes Athena’s current private testing integration. CanAI operates and develops Athena. Contact us at development@canaivoice.ai.

We will update this notice before introducing materially different data use or a hosted customer rollout. We will seek any additional authorization needed before using connected Google data for a new purpose.

Information accessed

A Google connection provides the authorized mailbox address, accepted sending aliases and OAuth credentials. When Athena sends a message or verifies an uncertain send, it processes the recipient, subject, body, message identifiers and relevant sent-message content and status.

Gmail’s read permission allows broader access than the messages Athena needs. Connecting Google verifies the mailbox, accepted sending aliases and sent-message evidence. Incoming email is a separate, optional setting: an owner selects a business-specific Gmail label and enables email for that workspace.

When incoming email is enabled, Athena checks message changes and routing metadata for that label. It stores eligible new messages’ sender, subject, text content, date and conversation identifiers in the selected business workspace. Mail without that label is excluded from intake. Sent mail, verified self-addresses, and identified automatic or bulk messages are excluded. Attachments are not processed or stored; oversized or unsupported content requires review in Gmail.

How information is used and shared

Athena uses this information to carry out authorized sending, show connection status and investigate delivery outcomes. Optional incoming email matches or creates a customer record, shows messages for owner review, and stops existing follow-up sequences when a customer replies. Receiving an email does not grant marketing permission. Replies entered in Athena require review and approval before entering the sending queue. Gmail receives outgoing messages through its API and delivers them to the recipients specified in the authorized message.

Application records and connection credentials are held in CanAI’s private local development environment. The public information website is hosted through OpenAI Sites and Cloudflare; it does not host the Athena testing database or Gmail credentials. Website hosting providers may process connection information, such as IP addresses and requests, to serve these pages. Website inquiries are covered by the CanAI website privacy policy.

CanAI does not sell Google user data, use it for advertising, or use it to train general-purpose AI models. The current Gmail verification and incoming-email processes do not submit retrieved messages to a language model. AI interpretation and automatically generated replies remain future work.

Who can access information

Business workspace access is limited to authorized account users and audited Athena support administration. CanAI operators administer the development environment and investigate operational issues.

Human reading of Google data is limited to specific data you affirmatively authorize for review, necessary security investigations, or applicable legal requirements, in accordance with Google’s Limited Use requirements. General support access does not provide unrestricted permission to read a connected mailbox.

Storage and retention

OAuth credentials are stored in private server files separately from ordinary CRM records. Athena retains imported message text, related customer records, synchronization progress and duplicate-prevention identifiers, as well as queued message content and delivery evidence. An uncertain send is retained for investigation instead of automatically sending another copy.

The complete email-record and backup deletion lifecycle is still being implemented. There is currently no fixed automatic deletion period for these testing email records. You can request their removal using the contact address below. Please use synthetic test data and avoid unrelated personal or confidential information during development tests.

Disconnecting Google

Pause incoming email to stop new intake. Removing a Gmail label prevents future intake of that message but does not erase a copy already imported into Athena. If a configured inbox is paused, disconnected, behind or unable to synchronize, Athena holds its customer follow-up sequences until the inbox can be checked again.

Disconnecting Google in Athena removes its active local connection credentials and stops new use of that connection. It does not delete messages from Gmail, recall an email already being sent, or automatically delete existing delivery records and backups.

You can separately revoke Google’s grant in your Google Account connections settings. Contact CanAI to request deletion of remaining development records. We will identify any retained copies that still need to be addressed.

Google user-data commitment

Athena’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Questions and requests

For questions, corrections or testing-data deletion requests, email development@canaivoice.ai. Do not include passwords, access tokens or unnecessary private message content in your request.