Privacy Policy

Last updated: June 2026

Durian Stack OS (“Durian Stack OS”, “we”, “us”) provides a workflow control plane that helps small businesses — primarily law firms and psychology clinics — coordinate work across the third-party tools they already use, such as Google Workspace, Meta Lead Ads, SMS, and WhatsApp. This policy explains what data we access, why, and how we protect it. Our guiding principle is data minimization: we hold as little as possible and defer storage to the source systems wherever we can.

Who controls your data

Durian Stack OS is offered to businesses (each, a “workspace”). When you use the product as part of a workspace, that business is the controller of the data processed through it, and we act as its processor. If you are an end client of one of those businesses, please direct data requests to the business you work with.

Information we access through Google APIs

When a workspace connects its Google account, we request only the access needed to deliver the features it has enabled. Access is granted per workspace through Google’s standard OAuth consent flow and can be revoked at any time. We request the following scopes:

  • Sign-in and profile (openid, userinfo.email, userinfo.profile) — to identify the Google Workspace account that has been connected and display it in your settings.
  • Drive files we create (drive.file) — to create and organize folders and documents on your behalf (for example, a workspace root folder and per-matter folder trees). This is a narrow scope: it grants access only to files and folders that Durian Stack OS itself creates or that you explicitly open with us. We cannot see the rest of your Drive.
  • Calendar events (calendar.events) — to create and manage appointments and scheduling on your connected calendar.

Form intake (turning Google Forms submissions into leads) does not use a Google OAuth scope: you install a small Apps Script in your own Form that sends new submissions to Durian Stack OS. That data is covered under “Integration data” below.

Gmail access — planned, not yet enabled

We intend to offer optional Gmail features in a future release — sending messages you compose or approve (gmail.send) and associating email threads with the right matters and clients (gmail.readonly). These scopes are not currently requested by Durian Stack OS; you will not be asked to grant them today. We will request them only after completing the additional security assessment Google requires for Gmail access, and only for workspaces that enable the feature. The same data-minimization and Limited Use commitments below will apply.

We never store the bytes of your files. For documents in Drive we keep only a reference (a file identifier and metadata such as name), never a copy of the file contents. AI features are assistive only: any AI-generated output is a draft that a person in your workspace must review and approve before it takes effect or is sent.

Google API Services User Data Policy — Limited Use

Durian Stack OS’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for serving advertisements; we do not sell Google user data; we do not transfer or use it for purposes unrelated to the features you have enabled; and we do not allow humans to read it except where you give us explicit consent for specific data, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data is aggregated and anonymized.

Other information we process

  • Account information — your name and email used to sign in, handled by our authentication provider.
  • Workspace content — leads, contacts, matters, tasks, and notes that you or your workflows create within Durian Stack OS.
  • Integration data — messages and leads delivered to us by connected services such as Meta Lead Ads, SMS, and WhatsApp.
  • Operational logs — limited technical logs used to keep the service running and secure. We do not log the contents of your OAuth tokens or file bytes.

How we protect your data

  • Per-workspace OAuth tokens are encrypted at rest and are never written to logs. They are decrypted only in memory, only to make the API calls a feature requires.
  • Data is isolated per workspace at both the application layer and the database layer.
  • We retain only what a feature needs and prefer references to source systems over copies.

Sharing

We do not sell your data. We share it only with the infrastructure providers needed to run the service (for example, hosting, database, authentication, and the integration APIs you connect), and where required by law. Each provider processes data only on our instructions.

Your choices

You can disconnect any integration at any time from your workspace settings, which revokes our access and removes the stored tokens. You may also revoke Durian Stack OS’s access directly from your Google Account permissions. To request access to, correction of, or deletion of your data, contact us at the address below.

Contact

Questions about this policy or your data? Email us at privacy@durianstack.com.