Security

Security and Confidentiality

Last updated 6 September 2026

You are being asked to connect a mailbox that carries privileged client correspondence. This page sets out exactly what that connection permits, what happens to the data, and what the system will not do. It is written to be read in a few minutes, and it describes how the product actually behaves rather than how we would like it to sound.

1. How access works

2. What we access, and why

We request the narrowest set of permissions the product can run on. You see this list on Google's consent screen before anything is connected.

PermissionWhat it allowsWhy it is needed
gmail.modify Read messages, create drafts, apply labels, and send. It does not permit permanent deletion of anything. To read incoming enquiries, tag them by urgency, and place a drafted reply in your mailbox for you to review.
calendar Read and write calendar events. To check your real availability and write a booked consultation onto your calendar.
openid, userinfo.email The email address of the account being connected. To know which firm a connection belongs to, so that tokens are stored against the right account.

We do not request access to Google Drive, Contacts, photos, location, or anything else unrelated to the three functions above.

3. What the system does not do

Replies are drafted, not sent

Every reply the system produces for a client, including follow-ups and scheduling clarifications, is saved as a draft inside your own Gmail account. It sits there until a person at your firm reads it, edits it if needed, and sends it. The system has no mechanism for sending a reply on its own.

One exception, stated plainly. If you enable the consultation questionnaire, it is emailed to the client automatically once a consultation is booked, so that their answers arrive before the meeting. That is the only client facing message the system sends without a person pressing send. It is configurable: tell us and we will set it to draft mode for your firm, so that it also waits for approval. The case roadmap is set to draft mode by default.

Your mailbox is not copied to our servers

We do not keep a mirror of your inbox. Message content is passed through the classification and drafting step and is not retained by us as a standing archive. Your emails stay in Gmail, under your control.

To be precise about what we do keep: the system stores a structured lead record for each enquiry, containing the sender's name and contact details, the matter type, and a short summary. This is what allows it to track enquiries, chase follow-ups, and report to you. Retention periods for those records are set out in the Privacy Policy.

Nothing is sold or shared

We do not sell your data. We do not share it for advertising or marketing. We do not use the contents of your mailbox to build profiles, train anything of our own, or improve the product for other firms. The service providers strictly necessary to run the product are named in the Privacy Policy, and each is contractually limited to providing its service to us.

Bookings do not email your clients on your behalf

When a consultation is written to your calendar, Google's automatic invitation emails are suppressed. Your client is not emailed by the calendar system without your involvement.

4. How data is protected

5. AI processing

Classification and draft writing are performed by a large language model accessed through the OpenAI API. For each message being processed, what is sent is the sender's name and address, the subject line, and the body of the message, truncated to a fixed length.

OpenAI's published policy is that data submitted through their API is not used to train their models by default. We rely on that commitment and do not opt in to any arrangement that would change it. Their current terms are at openai.com/policies.

If your firm has an obligation that rules out any third party processing of client correspondence, this product is not a fit, and we would rather tell you that now than after you have connected a mailbox.

6. Compliance posture

The system is designed to support the confidentiality obligations that Canadian law societies place on firms, and to handle personal information consistently with PIPEDA. In practice that means data minimisation in what we request, encryption of credentials, no secondary use of client information, and deletion on request.

Two honest limits. First, the firm remains responsible for its own professional obligations, including supervision of outgoing communications, conflicts checking, and any decision about whether a particular matter can be handled with a third party tool. We support those obligations; we do not discharge them, and nothing on this page is advice about what your obligations are.

Second, this product is not intended for processing health records. It is not configured or certified for protected health information, and it should not be pointed at a mailbox whose primary purpose is handling medical records.

7. Security contact

Questions about anything on this page, or a suspected security issue, go to lsautomationsystems@gmail.com. We aim to acknowledge security reports within two business days. If you believe a token or an account has been compromised, revoke access first at myaccount.google.com/permissions, then contact us, in that order.

See also the Privacy Policy for retention, deletion, and the full list of service providers, and the Terms of Service for responsibilities and liability.