Legal

Privacy Policy

n8n_Oshoma · Operated by Oshoma Systems · Effective 28 August 2026

Scope

This policy describes how n8n_Oshoma (the application) accesses, uses, stores, and shares data obtained from Google APIs. The application is a private workflow-automation deployment operated by Oshoma Systems on a self-hosted n8n instance at n8n.oshomasystems.com.

The application is not a public product. It is used by the operator to automate their own workflows and is not offered to, marketed to, or made available for sign-up by the general public.

1. Who operates the application

Oshoma Systems. Questions about this policy, or about data the application has accessed, can be sent to oshoma@oshomasystems.com.

2. What Google data the application accesses

When you authorize the application, Google asks you to grant specific permissions (scopes). The application requests only the scopes listed below, and only accesses data belonging to the Google Account that granted them.

Requested scopes and their purpose
DataWhat the application does with it
Gmail messages
(read and send)
Reads message metadata and content in order to classify, extract, and route information into automated workflows. Sends messages on the authorizing user's behalf when a workflow is configured to do so.
Google Sheets and Docs
(read and write)
Reads spreadsheet and document content as workflow input, and writes results back into files owned by the authorizing user. Results include records, summaries, and status updates.

The application does not access Google data belonging to anyone other than the account that granted authorization.

3. How the data is used

Google user data is used solely to provide the automation features the authorizing user has configured. Specifically, the application does not:

  • sell, rent, or trade Google user data;
  • use Google user data for advertising, ad targeting, or audience building;
  • use Google user data to train, fine-tune, or otherwise improve generalized artificial-intelligence or machine-learning models;
  • transfer Google user data to data brokers, information resellers, or any other party for independent use;
  • allow humans to read Google user data, except with the authorizing user's explicit consent for a specific message or file, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and de-identified.

4. Limited Use disclosure

The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Storage and retention

Credentials

OAuth access and refresh tokens issued by Google are stored in the credential store of the self-hosted n8n instance, encrypted at rest using n8n's configured encryption key. Tokens are used only to make API calls on the authorizing user's behalf.

Content

Message and document content is processed transiently in the course of a workflow run. Where n8n retains execution data for logging or debugging, that data resides on infrastructure controlled by Oshoma Systems and is subject to the instance's configured retention window. No copy of Google user data is maintained beyond what the configured workflows require.

Location

The application runs on private server infrastructure controlled by Oshoma Systems. Data is not stored on third-party analytics, advertising, or data-enrichment platforms.

6. Sharing with third parties

Google user data is not shared with third parties, except where a workflow the authorizing user has explicitly configured sends data to a service of their choosing, and except where disclosure is required by law. Where a workflow routes content through an external service, for example a language model or a storage provider, that routing is configured, and therefore known, by the authorizing user.

7. Revoking access

Authorization can be withdrawn at any time from the Google Account permissions page at myaccount.google.com/permissions. Revoking access immediately invalidates the application's tokens and ends its ability to read or write data. Stored credentials can additionally be deleted from the n8n instance on request to the contact address above.

8. Security

Access to the n8n instance is restricted to the operator and protected by authentication. Traffic to n8n.oshomasystems.com is served over TLS. Credentials are encrypted at rest. No security program is absolute, and no representation is made that the application is immune to compromise.

9. Children

The application is not directed to children and does not knowingly process data relating to anyone under 13.

10. Changes to this policy

This policy may be updated as the application's functionality changes. Material changes will be reflected in the effective date at the top of this page. Continued authorization after a change constitutes acceptance of the revised policy.