Privacy
Privacy and Gmail access.
How Tradour uses Google user data for authorised market-forecast email ingestion.
Gmail access
Tradour requests only the Gmail read-only OAuth scope (https://www.googleapis.com/auth/gmail.readonly). That scope can view messages and Gmail settings. Tradour limits its use to reading authorised Buy Sell Pass and market-forecast emails from the source mailbox.
Tradour does not request permission to send mail or modify the mailbox. It cannot send, edit, label, move, archive or delete Gmail messages.
How authorised messages are used
Authorised forecast messages are used only to deduplicate source records, run Tradour's canonical parser, reconcile company identity, test the existing research rules and create confirmed research observations. A qualifying observation may then enter the Today, Live and eToro Demo workflow under Tradour's separate execution safeguards.
Gmail data is not used for personalised advertising, determining creditworthiness or training a general-purpose artificial intelligence model.
Storage and retention
The Preview integration stores only authorised forecast messages that pass its source-cohort filter. Raw content is held in a restricted server-side database table for no more than 90 days and is deleted by the ingestion worker after its expiry time. The website and Demo execution database identities cannot read that table.
Message digests, ingestion receipts, durable mailbox-cursor events, canonical research observations and execution audit records are retained after raw content expires so that Tradour can deduplicate messages, preserve provenance, reconcile Demo activity and detect failures. The public site receives only a presentation-safe projection, such as company, ticker, date, versioned rule and evidence state. It does not receive raw message bodies, mailbox addresses, OAuth credentials or private provider identifiers.
The mailbox owner may request deletion of retained derived records through the contact method below. Records needed to document an already-submitted Demo order may need to remain in the append-only execution audit so that the activity is not presented misleadingly.
Security
Gmail OAuth credentials must remain server-side in an environment-specific secret store. They are not placed in browser code, committed to the repository or included in public logs. Database connections use transport encryption and the managed database encrypts stored data. Tradour's ingestion design advances its durable mailbox cursor only after validation and publication succeed, and public outputs exclude raw correspondence.
Sharing, sale and advertising
Tradour does not sell Google user data, share it with advertising platforms or use it to serve targeted advertising. Raw Gmail data is not published or disclosed to unrelated third parties.
Tradour's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Read the Google API Services User Data Policy.
Control and contact
The mailbox owner can withdraw access through their Google Account permissions. For a privacy question or a request concerning data derived from the authorised mailbox, use the user-support email displayed on Tradour's Google OAuth consent screen, or contact the Tradour project owner through the established private channel used to authorise the source mailbox.