About this policy
Effective 29 September 2026.
CPL Tool Radar is operated by Curious Pi Labs. It reads newsletters from sources you select, identifies software and AI tools, checks linked web pages, and emails a digest to the recipients you configure. Privacy questions and requests can be sent to hello@curiouspilabs.com.
Gmail access and information we process
You authorize Gmail access through Google's consent flow. For the current service, we request the gmail.readonly permission. This permission technically allows access to the mailbox; Google does not limit it to selected senders. The application applies your sender list and processing dates when selecting newsletters.
We process the connected mailbox address, matching message identifiers, message headers and metadata (including sender, recipient, subject and dates), text or HTML body content, and links in selected messages. The application skips named file attachments; Gmail may serve large message-body parts through its attachment endpoint. We also store your selected newsletter senders, digest recipients, schedule, and application preferences.
The Gmail connection does not let this deployment send from your Google account, delete messages, change labels, or mark messages as read. Digests are sent separately through Azure Communication Services. A mailbox profile request checks that the authorization belongs to the configured account, including during periodic connection checks.
How information is used
We use selected newsletter content to identify tools, retrieve their public web pages, generate summaries, attribute each result to its source email address, and deliver your digest. We retain processing and delivery records to avoid duplicate emails, reconcile interrupted sends, and resume work after a failure. Connection and operation status are used to maintain the service and notify the operator of failures.
The application does not use Gmail content to serve advertising, build advertising profiles, or determine creditworthiness. We do not sell Gmail data or use it to train or fine-tune general-purpose AI models. Our handling of Gmail data, including derived information and permitted transfers, is governed by the Google API Services User Data Policy, including its Limited Use requirements. Human access must be limited to consented support, necessary security investigations, legal requirements, or other uses permitted by those requirements.
AI processing, delivery and other disclosures
Selected newsletter subjects, body text and links are submitted to models hosted by Microsoft Azure to extract tool information. Relevant fetched web-page text and generated tool summaries are also processed by those models. OAuth credentials are not included in model prompts. Microsoft describes its processing and abuse-monitoring practices in its Foundry model data-privacy documentation. The application does not request model training with this data. Provider security and abuse monitoring can involve retention and authorized human review; this policy does not promise zero provider retention.
Azure Communication Services receives digest contents and configured recipient addresses to send email. Each selected recipient receives the digest, including summaries, links, source email addresses and any included excerpts. Choose recipients only where sharing that information is appropriate. Copies in recipient mailboxes are controlled by those recipients and their email providers. Engagement tracking is disabled for digest submissions made by this application.
When retrieving linked pages, the destination website receives the requested URL, including any query parameters, and the service's network address and user agent. Newsletter links can contain publisher tracking identifiers. The application does not submit Gmail credentials or the newsletter body to those websites. A publisher may also observe a recipient opening a link from a digest.
Azure provides hosting, secret storage, application settings, processing records and operational monitoring. Monitoring exported by this application contains operation names, timing, success or failure, fixed outcome categories and model token counts. Its exporter excludes newsletter bodies, OAuth tokens, mailbox addresses and exception text. Operational alert emails go to the designated operations inbox. Cloud providers' own security and service records are governed by their applicable terms and settings.
Storage, retention and deletion
OAuth client credentials and refresh tokens are stored in Azure Key Vault and used to maintain the authorized connection. The application does not ask for or store your Google password. Settings and processing records are stored in Azure Blob Storage with authenticated access. The application uses encrypted connections to Google, Azure and HTTPS web sources; some publisher links may use HTTP.
The scheduled service does not create an archive of newsletter bodies or completed digest bodies in its application state. Those contents are processed in memory and submitted to the model or email services described above. An operator-run local preview can save a digest on the operator's computer.
Current processing state keeps a watermark, up to 2,000 recently processed message identifiers, up to 100 completed schedule slots, and any unresolved delivery record. An unresolved record is kept until delivery is reconciled. Settings, secrets and the current state do not have a general automatic deletion deadline. Blob versioning can preserve earlier records beyond the current limits. Cloud recovery settings and provider retention can also preserve copies after active data is deleted.
You may ask Curious Pi Labs to stop processing and remove the stored connection, settings and application records. We will verify the request and explain any retained records needed for security, legal obligations, recovery or unresolved deliveries. Deleting application records does not delete the original messages in Gmail or copies of digests already delivered to recipients.
Your choices
You can change the sender list, recipients and schedule, or pause processing, through the application's settings. You can also remove CPL Tool Radar's access from your Google Account connections. Removing access stops future authorized Gmail access; it does not itself erase existing application records or previously delivered digests. Contact hello@curiouspilabs.com to request help or deletion.
Public website and support
The public Curious Pi Labs website uses Google Analytics to understand visits and page usage. This website analytics is separate from Gmail processing; Tool Radar does not submit newsletter content or Gmail credentials to website analytics. If you email us for support, we receive your address and the information you include and use it to handle your request. Please avoid sending unnecessary sensitive information.
Information may be processed in countries where our cloud and email providers operate. Contact hello@curiouspilabs.com to request access, correction or deletion of personal information, or to raise a privacy concern. We will verify your request before disclosing account information.
Policy changes
We will update this policy when the service's data practices change. Material changes to how Google data is accessed, used or shared will be disclosed before the new use and will require consent where applicable.