Legal
Privacy.
What SelfOperate collects, what it does with it, and what it will not do. Written to be checked against the product rather than to sound reassuring.
Who we are
SelfOperate is a product operated by Stromation LLC, a company registered in Texas, United States. Where this policy says “we”, it means Stromation LLC acting through the SelfOperate product.
What we collect
- Account and profile data — the name, email address and sign-in identifiers you use to access SelfOperate.
- Business and company data — what you tell us about the business being built or operated: services, pricing, service area, operating preferences, and the records the product keeps about your company.
- Connected-provider metadata — which third-party accounts you have connected, the account identifier at that provider, the permissions you granted, and the health of the connection.
- Files and evidence you upload — documents and images you provide so work can be done or verified.
- Operational and audit data — a record of what was requested, what was approved, what was done, and by whom. This is what makes the product auditable, and it is deliberately not optional.
- Payment metadata — our payment processor handles card details. We receive the result of a payment and the identifiers needed to reconcile it. We do not receive or store full card numbers.
- OAuth connection data — the tokens that let SelfOperate act on a connected account, held as described below.
Google user data, and Gmail specifically
Some SelfOperate features connect to Google accounts. Those connections exist only because you, as the account owner, completed Google’s consent screen and granted them. This section describes what happens after that.
gmail.readonly scope and nothing else. The product has no ability to send, delete, modify, label, archive, or configure forwarding or filters in your Gmail account. That is not a policy promise layered on top of a broader permission — the permission itself was never requested.- Authorised by you. A Gmail connection begins with the account owner completing Google’s consent screen. Nothing is connected on your behalf.
- Bounded reads, not crawling. Reads are searches and message fetches performed to carry out work you asked for. SelfOperate does not autonomously traverse or index an entire mailbox.
- Verified before storage. A connection is checked against Google’s profile endpoint before any credential is stored, so a connection that cannot actually work is never recorded as usable.
- Provenance. Where information from an email is deliberately used in your company record, the product keeps a reference to where it came from, so you can see why it believes what it believes.
- Revocable. You can disconnect inside SelfOperate at any time, and you can revoke access directly in your Google Account permissions.
Limited Use. SelfOperate’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not sell Google user data; we do not use it for advertising; we do not transfer it except as needed to provide the features you asked for, to comply with applicable law, or as part of a merger or acquisition after notice; and we do not allow humans to read it except where you explicitly ask us to, where it is necessary for security or to comply with law, or where the data has been aggregated and anonymised.
Credentials and tokens
- OAuth tokens are held in SelfOperate-controlled encrypted secret storage, separate from the application database.
- Connections are scoped to your tenant and company. One customer’s connection is not reachable from another’s.
- Tokens are never returned in customer-facing API responses. The product works with opaque references, and the credential itself is supplied only at the moment an authorised action runs.
- On disconnect, SelfOperate destroys its own copy of the credential first, then asks the provider to drop the grant. A provider being unavailable cannot block a disconnect.
What we do not do
- We do not sell your data, or Google user data, to anyone.
- We do not use your data, or Google user data, to serve advertising.
- We do not use your business data to train general-purpose models for other customers.
- We do not transfer Google user data for purposes unrelated to the features you connected it for.
Your data is yours
The company we help you build is yours. Accounts are created in your name, and SelfOperate exports your company data on request — records, evidence and the audit trail — in a structured, readable form. Stopping a subscription stops the operating layer; it does not transfer ownership of your business, your accounts or your data.
Retention
We keep account, company and audit data for as long as your account is open, because the product’s value depends on an unbroken record of what was done. When you ask us to delete your account we remove your company data and destroy stored credentials. We may retain a limited record of transactions where we are required to — for example tax and accounting records — and backups age out on their ordinary cycle rather than being edited. We have not set arbitrary retention windows we do not actually enforce.
Security
These are controls the product implements, not aspirations:
- Tenant isolation — every read and write is scoped to a tenant and company, and cross-tenant access is refused rather than filtered.
- Least-privilege permissions — each provider connection requests a narrow, explicitly listed set of scopes. Anything outside that list is rejected before a request is made.
- Approval controls — actions are read-only, approval-required, or permitted, according to limits you set. Nothing escalates itself.
- Audit trail — requests, approvals and outcomes are recorded.
- Malware scanning — uploaded files are scanned, and a file that has not returned a clean result is not usable.
- Separated secrets — credentials live in encrypted secret storage, not alongside application data.
No system is perfectly secure, and we do not claim a certification we have not obtained. We hold no SOC 2, ISO 27001 or comparable third-party attestation today, and this page will say so until that changes.
Third-party services
SelfOperate runs on cloud infrastructure and connects to providers you choose — Google, payment processors and others. Those providers handle data under their own terms and privacy policies, and connecting an account means data moves between SelfOperate and that provider to do the work you asked for.
Disconnecting and deletion
- Disconnect a provider — in SelfOperate, from your connections. You can also revoke directly at the provider.
- Export your data — request a full export at any time while your account is open.
- Delete your account — email support@selfoperate.com. Export first if you want a copy; deletion is not reversible.
Children
SelfOperate is a business product and is not directed to anyone under 18.
Changes
When this policy changes materially we will update the effective date and tell account holders. We will not quietly broaden what we do with data already collected.
Contact
Stromation LLC, Texas, United States · support@selfoperate.com