Kairos Bridge

Privacy Policy

Effective date: 31 August 2026

This Privacy Policy explains how Kairos Bridge accesses, uses, stores, and shares information when its authorized operator connects a Google account for the Kwork project-notification feature.

1. Service purpose

Kairos Bridge is a privately operated project-notification service. Its Gmail integration is used only to discover official Kwork project digest emails and turn the projects referenced in those messages into structured project notifications.

2. Google OAuth scope

Kairos Bridge requests https://www.googleapis.com/auth/gmail.readonly. Google describes this scope as permission to view Gmail messages and settings.

Kairos Bridge uses this permission only for read-only Gmail API operations required by the Kwork integration. The application does not send, compose, modify, label, move, or delete Gmail messages.

3. Gmail data accessed

The application searches Gmail using a configured query for official Kwork project digests. The production query targets messages from news@kwork.ru with the subject Новые проекты на бирже Kwork, together with a time checkpoint.

For matching messages, Kairos Bridge retrieves the raw message so it can verify sender and authentication headers and parse the message body for Kwork project links. The parser may process message metadata such as the Message-ID, Date, From, Subject, authentication headers, and URLs contained in the message.

The application is not designed to read or use unrelated mailbox content for any other purpose.

4. How Gmail data is used

Qualifying Kwork email data is used only to:

Raw Gmail messages and unrelated mailbox content are not sent to Telegram. Kairos Bridge does not automatically send Gmail content to OpenAI or ChatGPT and does not use Google user data for advertising or AI model training.

5. Data stored by Kairos Bridge

Kairos Bridge does not intentionally persist raw Gmail message bodies or a mailbox archive. Raw matching messages are processed in memory for the notification workflow.

The service stores operational project records in its local SQLite database, including the project source, project identifier, canonical project URL, processing status, timestamps, and delivery/retry state. It also stores a non-secret Gmail polling checkpoint used to avoid replaying old mail.

OAuth credentials, including the refresh token, are stored locally on the operator's server in a restricted credentials file. Short-lived Google access tokens are held in process memory.

6. Sharing and transfers

Kairos Bridge does not sell Google user data.

Project identifiers and URLs extracted from qualifying Kwork notifications are used to fetch the corresponding Kwork project page and to provide the requested project notification through Telegram. This transfer is part of the user-facing notification feature. Raw Gmail messages and unrelated mailbox content are not transferred for that purpose.

Google, Kwork, and Telegram process information under their own terms and privacy policies when their respective services are used.

7. Retention and deletion

Kairos Bridge has no separate persistent archive of raw Gmail messages. Operational project records remain in the local application database until they are removed by the service operator or the database is replaced or restored as part of normal administration.

The operator can stop Gmail access by revoking the application's Google authorization and removing the local OAuth credentials. Revocation prevents future Gmail API access.

8. Security

The Gmail integration is read-only. OAuth credentials are kept outside the source repository in a local file with restricted filesystem permissions. Access tokens are not written to the application database. The application validates expected Kwork sender information and Gmail authentication results before production ingestion.

9. Google API Services User Data Policy

Kairos Bridge's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Public website

This informational website does not intentionally set tracking cookies, run analytics, or include advertising scripts. Standard infrastructure-level request handling may still occur as necessary to serve the website over HTTPS.

11. Changes

This policy will be updated if Kairos Bridge changes how it accesses, uses, stores, or shares Google user data. The effective date above identifies the current version.

12. Contact

Privacy questions or requests concerning the Google authorization can be sent to the support contact displayed on the Kairos Bridge Google OAuth consent screen.