Data and permissions
Privacy policy
Jim CRM is a private customer relationship management application operated by Uvrey LLC for Jim Lawrence's private residential and commercial business workflows. Uvrey LLC is the parent company; this policy covers Jim CRM specifically, not every future Uvrey product.
Google data accessed
When a mailbox is connected, Jim CRM accesses its Google account email address, verified-email status, and account identifier to associate authorization with the correct account. It receives access and refresh tokens; it does not receive the Google account password.
The Gmail connection requests openid, email, https://www.googleapis.com/auth/gmail.send, and, for receiving mail, https://www.googleapis.com/auth/gmail.readonly.
Gmail permissions allow the app to send email and read mailbox messages. Data processed can include sender and recipient addresses, names, subjects, message text, dates, labels, message and thread identifiers, reply references, history identifiers, and attachment names, types, sizes, and counts. The current receive workflow stores attachment metadata, not downloaded attachment files.
Read-only permission technically permits access across the mailbox. The current receive workflow performs bounded inbox synchronization and excludes spam and trash. The app does not request Gmail modify, mailbox-settings management, or permanent-delete permissions.
Why and how the data is used
Data is used to send Jim's business messages, display correspondence, associate incoming messages with contacts and opportunities, reconcile conversation history, avoid duplicate processing, and support follow-up and email-activity records. Gmail's acceptance of a sent message is not proof of delivery.
Access is limited to these CRM workflows and the optional features described here. Google data is not sold, used for advertising or credit decisions, or authorized for training general-purpose AI models.
Storage and protection
The CRM stores account identifiers, granted permissions, encrypted OAuth tokens, expiry information, selected message content and metadata, and related CRM activity in its local database on Jim's computer. Access and refresh tokens are encrypted with a separate encryption key. Message text and metadata are not separately encrypted by the CRM application; their protection depends on device, account, storage, and backup safeguards.
Local backups may contain this database. CRM access is restricted to authorized accounts and Jim's private operating environment. This public information website does not host the CRM database or receive mailbox tokens or messages. These pages contain no advertising, analytics scripts, or signup forms; the hosting provider may process ordinary web-request information to deliver and secure the pages.
Sharing and optional assistant features
Google processes authorization and Gmail requests, and outgoing messages are transmitted to their intended recipients. The CRM assistant export excludes Gmail message content, sender/subject activity summaries, attachments, email status, and other Gmail-derived content. Because copied email text has no reliable source label, it also withholds free-text CRM fields, including names, addresses, notes, task titles, and activity summaries. Hermes receives only validated CRM record and stage identifiers and the residential/commercial record type. Today's Work summaries are generated locally without sending their records, rankings, or contactability information to an AI provider.
Jim must not manually send Gmail data through separate assistant prompts or tools. Earlier assistant sessions or derived records, if any, are not automatically deleted by this export restriction and require a separate retention/deletion review. Google data is not shared for unrelated purposes or general model training. Human access is limited to Jim and access specifically authorized for support, security, or legal obligations in accordance with Google's rules.
Optional Google Calendar connection
Calendar access requires separate authorization, using calendar.events.owned, calendar.events.readonly, and calendar.calendarlist.readonly under https://www.googleapis.com/auth/, plus openid and email. If connected, the app can read the calendar list and event details for conflict checks, and create, update, or cancel CRM-linked events in a calendar the connected account owns. Appointment details may include titles, times, locations, contact names, and notes. The CRM retains the selected calendar, linked event identifiers, appointment data, sync status, and encrypted Calendar tokens. Connecting Gmail alone does not authorize Calendar access.
Retention, deletion, and revocation
Records are retained for the active CRM workflow and business correspondence history until Jim removes them or they are no longer needed. The current CRM has no automatic age-based deletion schedule or self-service erasure process. Deletion is handled manually and must cover message records, associated activity, assistant-derived records where applicable, and retained backups; deleting a live record does not immediately remove backup copies.
Jim can request or arrange deletion through the contact below. Applicable recordkeeping obligations may require limited records to be retained. Deleting CRM copies does not delete messages in Gmail or copies held by recipients.
Google access can be revoked in Google Account → Third-party connections by selecting the app and removing access. The CRM's Gmail Disconnect action clears its locally stored tokens and attempts to revoke the Google authorization. Disconnecting or revoking access stops authorized future access but does not itself erase previously stored CRM records or backups.
Google API data commitments
Jim CRM's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace user data and developer policy, including their Limited Use requirements.
Material changes to Google-data access, use, or sharing will be disclosed in this policy and in the app before the changed use begins, with consent obtained where required.
Contact
For privacy questions, access concerns, or deletion requests:
Uvrey LLC · Jim Lawrence · [email protected]