Privacy policy
Last updated 16 August 2026
IngramOS is operated by Ingram Technologies. It is a business system used by companies we operate or work with; it is not a consumer product and there is no public sign-up.
Who the data belongs to
A company's records in IngramOS belong to that company. We process them to run the service for them. Companies are separated from one another at the database level: no query in IngramOS returns another company's records, and no credential spans two of them.
What we hold about people who sign in
Signing in uses your company's Google Workspace account. We receive and store your name, email address and Workspace domain, and we keep a session. We use them to know who you are and which company's records you may see. We do not receive your Google password.
Google user data: what we access, and why
An office in IngramOS can be granted access to a Gmail mailbox by the person who owns it. That grant is the only way IngramOS touches Google user data, and it is used for one purpose: turning email that arrives for a business into tracked work, and preparing replies for a person to review.
We request exactly two scopes:
gmail.readonly— to search the mailbox and read a message an office is working on.gmail.compose— to create a draft reply in the mailbox owner's own Gmail. Google offers no narrower scope for drafting; it also permits sending, and IngramOS never sends from your mailbox. No code path in the service sends a Gmail message, and a test fails if one is ever added. Mail the company itself sends leaves through its own sending service, under its own name.
We do not label, archive, delete, or move mail, and we do not read mailboxes other than those explicitly connected to an office.
What is stored, and what is not
Message content is not stored. When an office needs a message, IngramOS fetches it from Gmail at that moment and uses it to answer the task at hand. It is not written into our database and not retained afterwards.
What is recorded, when a new message arrives in a connected mailbox, is the envelope: the mailbox address, sender, recipient, subject line, Gmail's message and thread identifiers, and the timestamp. That record is what lets a piece of work be tracked, found and audited later. A subject line can itself be revealing, and it is treated as company data under the same access rules as everything else.
Your Google refresh token is encrypted at rest and is never returned by any part of our API. Access tokens are short-lived and are never stored.
Automated processing, and who else sees it
An office may be held by an AI agent. When it is, the content of a message it is working on, and the draft it prepares, are processed by a large language model in order to produce that draft or to record what the message means for the business. This happens only for mailboxes that have been connected, and only when an office acts on a specific message.
The sub-processors involved:
- Google — the mailbox itself; it remains the system of record.
- Ingram Cloud (Ingram Technologies) — the agent runtime that carries the model call.
- Anthropic — the model provider used by that runtime. Data sent through the API is not used to train their models.
- Amazon Web Services — hosting and the database, in the EU (Paris, eu-west-3).
We do not use Google user data to develop, improve or train generalised AI or machine-learning models. We do not sell it, we do not use it for advertising, and we do not transfer it to anyone except the sub-processors above in order to run the feature you asked for.
Limited Use
IngramOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Human beings do not read your Gmail data except where you explicitly ask us to (for example, to debug a problem you have reported), where it is necessary for security purposes such as investigating abuse, or where we are required to by law.
How long it is kept
Company records — work, decisions, the audit trail — are kept for as long as the company uses IngramOS, because they are the company's operating history. Envelope records of mail follow the same rule. Message content, as above, is not retained at all.
Taking it back
Disconnect a mailbox on the office's page in the console, or revoke IngramOS in your Google account permissions. Either takes effect immediately: the stored token stops working and nothing further can be read. To have your data deleted, or to ask what we hold about you, write to privacy@ingram.tech. If you are in the EU or UK you have rights of access, correction, deletion, restriction, objection and portability under the GDPR, and you may complain to your national data protection authority.
Contact
Ingram Technologies — privacy@ingram.tech. If this policy changes materially we will say so here, and update the date above.