Legal
Privacy Policy
Last updated: September 27, 2026
1. Who we are
ContactAssist (“ContactAssist,” “we,” “us”) is a software service operated by JC Design Intelligence, LLC, a limited liability company organized under the laws of the State of Tennessee, United States. We build a productivity tool for classroom teachers that scans their school Gmail inbox for parent messages and logs them to a Google Sheet the teacher owns.
If you have any questions about this Privacy Policy or want to exercise any of the rights described below, contact us at drj@jcdesignintelligence.com.
2. What data we access from your Google account
When you sign in with Google, ContactAssist requests the following OAuth scopes. You will see this list on Google's consent screen before granting access.
- Read your Gmail messages (
gmail.readonly) — used only to identify emails from parents about students and to extract the fields shown in your log. - Create and modify Gmail drafts (
gmail.compose) — used only to save AI-drafted replies as drafts in your account. You review and click Send yourself. ContactAssist never sends a draft on your behalf. - Send email as you (
gmail.send) — used only to send the opt-in weekly digest email from your Gmail to yourself. This scope is only exercised if you enable the weekly digest in Settings, and each digest goes to your own address. - See, edit, create, and delete only the specific Google Drive files you use with ContactAssist (
drive.file) — used only to create and update the single spreadsheet titled “ContactAssist – Parent Contact Log.” We cannot see or touch any other file in your Drive. - See, edit, create, and delete your spreadsheets in Google Drive (
spreadsheets) — used only to read and write rows on the ContactAssist spreadsheet we created for you. - Basic profile info (
openid,email,profile) — used to identify your account and display your name and avatar in the app.
ContactAssist's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. What we store, and for how long
We store as little as possible. Concretely, in our database we keep:
- Your Google user ID, email, display name, and profile picture URL.
- An encrypted refresh token so we can run your daily scan while you're not signed in. Refresh tokens are encrypted at rest using AES-256 with a key held outside the database.
- For each parent email your scan surfaces: the Gmail message ID, timestamp, sender and recipient email, subject, and the AI-produced fields shown in your log (student name, parent name, 1–2 sentence summary, topic, urgency, action items, deadlines, contact info parsed from the signature, and the Gmail permalink).
- Scan run history (counts of scanned / logged / skipped emails, and error messages if a run failed).
- Your app settings (scheduled scan time and timezone, digest preferences, paused state).
- Stripe customer ID and subscription state (never card numbers — those live only on Stripe).
We do not store the full body of your emails. The email body is fetched from Gmail at scan time, passed to Anthropic's Claude model for the extraction step, and discarded from our servers as soon as the row is written to your Google Sheet.
Data is retained for as long as your account is active. When you disconnect ContactAssist or delete your account, we delete your stored records within 30 days. You can also delete rows in your Google Sheet at any time — that Sheet is yours.
4. What we do not do
- We do not sell your data. Ever.
- We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized AI or machine-learning models.
- We do not send email from your account without your explicit action. Draft replies are saved as drafts; you click Send. The weekly digest only runs if you opt in and only goes to your own address.
- We do not share your data with third parties for advertising or marketing.
- We do not read files in your Google Drive other than the single spreadsheet ContactAssist creates.
5. Subprocessors
To run the service we rely on the following third parties:
- Google LLC — Gmail, Google Sheets, and Google Drive APIs (to read your inbox and write your log).
- Anthropic, PBC — Claude Sonnet model, invoked once per email to produce the summary and structured fields. Email content sent to Anthropic is not used by Anthropic to train models per Anthropic's API terms.
- Stripe, Inc. — billing, subscription management, and payment processing. Card details are entered directly on Stripe and never touch our servers.
- MongoDB, Inc. and our cloud hosting provider — encrypted storage of the fields listed in §3.
6. Security
Traffic between your browser and our servers is encrypted with HTTPS. Google refresh tokens are encrypted at rest. Access to production systems is restricted to authorized personnel and requires multi-factor authentication. No system is perfectly secure, but we take reasonable industry-standard measures to protect your data.
7. Your rights and choices
You can, at any time:
- Disconnect ContactAssist from Settings inside the app, or from your Google Account permissions page. Once disconnected, we can no longer read your Gmail or your Sheet.
- Delete your account and all associated data. Email us at drj@jcdesignintelligence.com and we will delete your records within 30 days.
- Access or export your data. Your Google Sheet is your export. Additional exports are available on request.
- Correct or update your account details from Settings.
If you are in the European Economic Area, the United Kingdom, or California, you may have additional rights under the GDPR, UK GDPR, or CCPA (including the right to object to processing and the right to lodge a complaint with a supervisory authority). Contact us to exercise any of these rights.
8. Children
ContactAssist is a tool for teachers. It is not intended for use by children under 13, and we do not knowingly collect personal information from children. Emails from students that happen to land in a teacher's inbox are typically classified as non-parent and are not logged, but if you become aware that a child's information has been stored, contact us and we will delete it.
9. International transfers
Our servers are located in the United States. If you are accessing ContactAssist from outside the US, your data will be transferred to and processed in the US.
10. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will always reflect the current version. Material changes will be announced in-app or by email.
11. Contact
JC Design Intelligence, LLC
Attn: Privacy
State of Tennessee, United States
Email: drj@jcdesignintelligence.com
See also our Terms of Service.