CHIEF LOCAL GMAIL
Privacy policy
Last updated 27 September 2026
This policy explains how the personal Chief Local Gmail integration accesses and handles Google user data. It runs on one user's Windows computer with Open WebUI and a local language model. It is not a hosted service, and this website has no login, mailbox, analytics, advertising, or contact form.
Google data accessed and why
After the user signs in and grants consent, the integration requests the Gmail scope https://mail.google.com/. This broad scope is used to provide the features the user requested: search the mailbox, read selected messages, change labels, mark or restore spam, move messages to or restore them from Trash, send or forward messages, and permanently delete a selected message. The Google permission covers the Gmail mailbox and is not technically limited to messages already selected in a search; the local connector is intended to perform individual actions when the user asks Chief to use a Gmail tool. This integration does not run a background mailbox sync.
How data is processed
- Gmail API requests go from the user's computer to Google to perform searches and mailbox actions.
- Search results and selected message text are returned to local Open WebUI and processed by the local Chief model through the local TabbyAPI service. The integration does not send Gmail content to an external AI provider.
- A saved Open WebUI chat may retain the messages, search results, or email text shown in that chat on the user's computer. That local chat history is controlled and deleted through Open WebUI.
- When the user instructs Chief to send or forward a message, the message and any forwarded original are submitted to Google and delivered to the specified recipient through Gmail. Forwarding may include the original message as an attachment.
- This informational website is hosted on Cloudflare. Cloudflare may process ordinary website request information under its own policies; this site does not receive Gmail messages or OAuth tokens.
Storage and security
The OAuth client configuration and authorization credentials are stored on the user's computer in the Windows application data folder. Chief encrypts this file with Windows Data Protection API (DPAPI), tied to the Windows user account. Gmail message content is not stored in a separate Chief cloud database. Email text included in saved Open WebUI conversations remains subject to the local chat-history settings and deletion controls.
Sharing and use
Use of information received from Google APIs is limited to providing these Gmail features and will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Gmail data is not sold, used for advertising, or sent to an external AI service. Google processes requests to provide the Gmail API and, for user-directed outgoing messages, Gmail delivers mail to the recipients the user specifies. The user controls whether to ask Chief to read or change mailbox items.
Retention and disconnecting
Authorization credentials remain on the user's computer until removed or revoked. The user can revoke access from their Google Account's third-party app connections. Removing the local Chief Gmail authorization file disconnects the saved local authorization; deleting saved Open WebUI chats is a separate action. A Google refresh token may also stop working if Google revokes it or it expires under Google's rules.
Contact
For questions about this personal integration's use of Google data, use the support contact displayed on the Google authorization screen for Chief Local Gmail.
This is a personal-use local integration. It is not offered as a multi-user product or a remote email-processing service.