Privacy policy
Effective date: 2026-10-11 · Xessenger
This policy explains how Xessenger handles account, conversation and connected Google data. Contact the Xessenger operator at dev.blackbull@gmail.com for questions or deletion requests.
Information we process
For registration and sign-in, we process your name, email address, password verification hash and login sessions. For connected Instagram and WhatsApp accounts, we process account identifiers, profile information, connection credentials, conversation participants, messages, attachments and delivery status. Connection credentials are used to maintain the accounts you choose to connect.
For Gmail, we access the connected account address, message and thread identifiers, sender and recipient addresses, subjects, message content, dates, labels, read state and supported attachments. We use these to display and synchronize email conversations and send messages or replies that you request, including scheduled messages. Xessenger does not import your entire mailbox by default.
Google Drive, Sheets and Calendar
The Jenny assistant requests access to Google features when you choose to enable them. Drive search can search and read files in the connected account. Sheets can create a spreadsheet and read or add rows to files created with Xessenger or explicitly selected for use with the app. Calendar access reads events to answer your questions. The current assistant tools do not delete or share Drive files, overwrite existing spreadsheet cells, or modify calendar events.
Basic Google identity permissions identify the connected account. Gmail reading and sending, Drive-wide reading, selected-file Sheets access and Calendar reading have distinct purposes. The permissions shown on Google's consent screen describe the scope requested by the particular connection. You can decline optional assistant features.
AI processing and Google Limited Use
When you request translation, summaries, analysis, reply drafts or other assistant work, relevant conversation or connected-app content and your instructions may be sent to the AI provider used for that feature. Automatic translation processes incoming messages while enabled and can be switched off. Built-in writing features use OpenAI API; Jenny uses the AI provider you select and connect, such as OpenAI, Anthropic or OpenRouter and its selected downstream model provider. Review that provider's account settings and retention terms before connecting sensitive information.
Jenny's tools execute on your device, but model requests can be processed by an external AI service. Local execution does not mean all analysis stays on the device. OAuth access tokens and refresh tokens are not included in the assistant's Google tool responses.
Xessenger uses Google data to deliver the visible functions you authorize. We do not sell Google data, use it for advertising, or use it to train general-purpose AI models. Our access, use and permitted transfers of Google API data follow the Google API Services User Data Policy, including its Limited Use requirements. Human access is limited to your specific permission, necessary security or abuse investigation, or legal requirements.
Storage and service providers
Email synchronization runs through Xessenger's server-side email connector and messaging infrastructure. Imported conversations and related state are stored in service databases and an app cache. Jenny's Google credentials are stored in the device's protected application profile using the operating system's secure storage facilities. Jenny conversation history and working files remain in the local application profile; they are not automatically synchronized between devices.
Amazon Web Services hosts the API, connectors, databases and operational records; the current server region is Seoul. Cloudflare R2 stores encrypted supported attachments and encrypted recovery backups. Vercel serves the public website. Meta and Google operate the original connected services. AI providers process the content needed for the AI feature you use. Providers and their subprocessors may process information internationally, including in the United States, according to their applicable terms.
We use access controls, HTTPS, protected credential storage and encrypted backups to protect information. Diagnostic and security records support service operation. These measures do not make every local file end-to-end encrypted or eliminate all provider operational logs.
Retention, disconnection and deletion
Account records, imported conversations and saved work are retained while needed to provide the service, until you delete your account or request deletion. Disconnecting an account stops further access through that connection and removes its active stored connection credentials; it does not automatically remove previously imported conversations, local assistant history or files you created in Google.
Deleting your Xessenger account removes the app's account and related operational database records and disconnects its linked service sessions. Request removal of remaining connector copies, attachments or other stored data through the contact address below. We may need to verify ownership before processing the request. No passwords or access tokens are needed in a deletion email.
Routine database backups use a seven-day RDS retention period and encrypted export backups use an eight-day rotation. Backup expiry follows the configured cleanup process, so deletion is not immediate from every recovery copy. Local app profiles on other devices need to be removed on those devices; contact us for help. Original Gmail messages, Drive files, calendar events, and messages on Instagram or WhatsApp remain with their original services unless you separately delete them there.
Your controls and contact
Use Xessenger account management to disconnect email or messenger accounts and request account deletion. Use Jenny's connected-app settings to disable or disconnect its Google connection. You can also revoke Xessenger's access in your Google Account's third-party connections settings. Revoking access stops subsequent API access but does not itself erase earlier imports.
We use session cookies and local app storage for authentication, drafts and connection state. You can request access, correction, deletion or restriction of your information by emailing dev.blackbull@gmail.com. When material processing practices change, we update this policy and provide notice or obtain additional consent where required.
Google API Services User Data Policy · Manage Google connections