Bizzy Privacy Policy
This page covers how Bizzy Invoices handles vendor bank info, signatures, ACH payments, analytics, Google user data (Gmail), and other data practices.
Google User Data and Gmail Access
Last updated: July 20, 2026
When you connect your Gmail account to Bizzy to enable the Callsheet Watcher, Bizzy requests access to specific Google user data through Google's OAuth 2.0 authorization flow. You will see a Google consent screen listing each scope before granting access. You can revoke access at any time from your Google account's Connected Apps page or from Bizzy's Settings page.
Google API scopes Bizzy requests
- https://www.googleapis.com/auth/gmail.readonly
- Read-only access to your Gmail messages and metadata. Bizzy uses this scope only to detect production callsheets in your inbox and extract the structured information required for invoicing reminders, including subject, sender, shoot date, location, production company, and contact. Bizzy never reads, indexes, or stores messages that are not classified as callsheets.
- https://www.googleapis.com/auth/userinfo.email
- Access to your Google account email address. Used only to identify which Google account you linked and to display it in Bizzy's Settings page.
How Bizzy uses Gmail data
Callsheet detection. Bizzy subscribes to Gmail push notifications for your inbox. When a new message arrives, Bizzy fetches its subject, sender, and — for messages whose subject matches a callsheet keyword classifier — its body. The body is passed to a third-party large language model (Google Gemini) under a zero-retention agreement to extract structured fields: shoot date, location, production company, and contact. The raw email body is held only transiently in serverless function memory and is discarded as soon as extraction completes.
No content indexing or AI training. Bizzy does not read, index, cache, or use your Gmail data to train AI or machine learning models. The extraction prompts and completions exchanged with Google Gemini are not retained by Google under our zero-retention agreement.
Storage and security
Gmail OAuth refresh tokens are stored encrypted at rest in Bizzy's database. Email bodies are transiently fetched into serverless function memory during processing and are never written to durable storage. Only the extracted callsheet fields — subject, sender, shoot date, contact match, and message ID for deduplication — are persisted.
All API traffic to Google and between Bizzy's services is transport-encrypted using TLS 1.2 or higher. Access to the underlying database is restricted to Bizzy's serverless functions running under short-lived service-role credentials; no Bizzy employee has standing access to individual customers' Gmail data.
Bizzy's source code, OAuth implementation, and storage practices are independently audited annually under the Cloud Application Security Assessment (CASA) Tier 2 program required by Google for restricted scopes.
Data sharing
Bizzy does not sell, rent, or share Gmail data with third parties except as strictly necessary to provide the features you have enabled:
- Google Gemini — callsheet body text is sent to Google Gemini for structured field extraction under a zero-retention agreement.
- Infrastructure providers (Supabase, Vercel, Google Cloud Pub/Sub) — store and transport data solely to operate Bizzy's services.
Bizzy does not share Gmail data for advertising, analytics, or profiling purposes.
Deletion and revocation
You may disconnect Gmail at any time by either:
- Going to Settings → Email → Disconnect Gmail in Bizzy. Bizzy asks Google to stop watch delivery, then clears its stored OAuth and watch data. You can additionally revoke Bizzy's access from your Google Account Permissions page at any time.
- Visiting https://myaccount.google.com/permissions in Google and removing Bizzy.
Bizzy reports exactly what the disconnect attempt proved. When Google accepts both the watch-stop and grant-revocation requests, Bizzy may confirm that delivery was stopped and access was revoked. If Google reports that the grant was already invalid, Bizzy clears its copy but does not claim delivery stopped; the old watch lapses on Google's schedule. If a new Gmail connection finishes while a disconnect is running, that newer connection is kept and reported — run the disconnect again if you still want it removed. Existing callsheet history is preserved, while pending prompts expire.
If a provider step fails, Bizzy keeps the connection visible and says it may still be connected. If Google access was revoked but local cleanup did not finish, Bizzy says cleanup is unfinished and asks you to retry. Google notes that revocation can take time to propagate.
Google API Services User Data Policy — Limited Use
Bizzy's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Bizzy:
- Limits the use of Gmail data to providing the user-facing features listed above.
- Does not use Gmail data to serve advertisements.
- Does not transfer Gmail data to third parties except as necessary to provide or improve the user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to users.
- Does not allow humans to read Gmail data unless (a) you give explicit consent for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is required for compliance with applicable law, or (d) the data has been aggregated and anonymized for internal operational analytics.
General privacy practices
The Termly-managed sections below cover how Bizzy handles vendor bank info, signatures, ACH payments, analytics cookies, and all other data practices outside of Gmail.