Privacy Policy
Last updated 27 August 2026 · Effective 27 August 2026
LS Automation Systems (“LSA”, “we”, “us”) provides an email and calendar assistant for law firms. This policy explains exactly what data we access, why we access it, who it reaches, how long we keep it, and how you remove our access at any time. It applies to lsautomationsystems.com and to the LSA service.
Google API Services User Data Policy. LS Automation Systems’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Who this policy is for
Our customer is the law firm that subscribes to LSA. When a firm connects its mailbox, we necessarily process messages sent to that firm by its own clients and prospective clients. The firm remains the controller of that correspondence; LSA acts as a processor on the firm’s instructions. If you contacted a law firm and have questions about your information, contact that firm directly. We will support them in responding.
2. Google user data we access
We request the narrowest set of scopes that allows the product to function. You see and approve this list on Google’s own consent screen before anything is connected.
| Scope | What it permits | Why we need it |
|---|---|---|
gmail.modify |
Read messages; create drafts; apply labels; send. It does not permit permanent deletion. | To read incoming enquiries, apply urgency labels, and place a drafted reply in the mailbox for the attorney to review. |
calendar |
Read and write calendar events. | To check genuine availability and write a confirmed consultation onto the calendar. |
openid, userinfo.email |
The email address of the connecting account. | To identify which firm a connection belongs to, so tokens are stored against the correct account. |
We do not request contacts, Drive, photos, location, or any scope unrelated to the functions above.
3. How we use it
- Classifying incoming email. Each new message is categorised by type, urgency, and likely practice area so the firm sees what matters first.
- Drafting replies for attorney approval. We generate a suggested response in the firm’s configured voice. Drafts are placed in the mailbox for a human to read, edit, and send.
- Booking consultations. Where a message requests a meeting, we check the firm’s stated availability and create the calendar event.
- Operational reporting. We produce activity summaries for the firm about its own mailbox.
We do not use Google user data for advertising, for building profiles, or for any purpose unrelated to providing these features.
4. Sharing, selling, and service providers
We never sell your data, and we never share it for advertising or marketing. We do not disclose it to any party except the limited service providers below, each of which is strictly necessary to operate the product and is bound to use the data only to provide its service to us:
| Provider | What it receives | Purpose |
|---|---|---|
| OpenAI | The sender name and address, subject line, and message body (truncated) of emails being processed. | Classification and draft generation. Data sent through the OpenAI API is not used to train their models. |
| The mailbox and calendar data described above. | The source system itself, Gmail and Google Calendar. | |
| Netlify | Encrypted OAuth tokens and the connected account’s email address. | Hosting for our connection endpoint and encrypted token storage. |
We may also disclose data where legally compelled, or where necessary to investigate a security incident or prevent fraud or abuse.
Limited Use commitment. Consistent with the Limited Use requirements, we use Google user data only to provide and improve the user-facing features described in this policy; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to affected firms; we do not use it for advertising; and we do not allow humans to read it except with the firm’s explicit consent for specific messages, where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and de-identified.
5. How your tokens and data are stored
- OAuth tokens are encrypted at rest with AES-256-GCM before they are written to storage. The encryption key is held separately from the stored records, so the storage layer alone cannot reveal a token.
- We never receive, request, or store your Google password. Authorisation happens entirely on Google’s own sign-in screen.
- All data in transit is protected with TLS.
- Lead records extracted from correspondence (name, contact details, matter type, summary) are stored to operate the service for the firm.
- Access to production systems is restricted to personnel who require it to operate and support the service.
6. Revoking access
You can disconnect LS Automation Systems at any time, without contacting us:
- Go to myaccount.google.com/permissions.
- Select LS Automation Systems from the list of connected apps.
- Choose Remove access.
Revocation is immediate and permanently invalidates our tokens for your account. We stop processing new mail at once. To also have stored data deleted, make a deletion request as described below.
7. Retention and deletion
- OAuth tokens are deleted within 30 days of you revoking access or terminating your subscription, and immediately on request.
- Message content sent for classification and drafting is processed transiently and is not retained by us as a standing archive. Emails themselves remain in your Gmail mailbox, under your control.
- Lead records and activity logs are retained for the life of the subscription so the service can function, then deleted within 90 days of termination unless you ask us to delete them sooner.
- Deletion on request. Email lsautomationsystems@gmail.com with the subject “Data deletion request”. We will confirm the request, delete the data, and confirm completion within 30 days.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal information we hold, and to object to or restrict certain processing. Contact us at the address below and we will respond within the time required by applicable law. Canadian firms may also raise concerns with the Office of the Privacy Commissioner of Canada.
9. Children
LSA is a business product intended for law firms. It is not directed to children, and we do not knowingly collect personal information from children.
10. Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how Google user data is handled, we will notify connected firms by email before the change takes effect.
11. Contact
Questions, requests, or privacy concerns: lsautomationsystems@gmail.com. We aim to respond within two business days.
LS Automation Systems ·
lsautomationsystems@gmail.com
See also our Terms of Service and
Security and Confidentiality page.