What Vorkane can see, and what it keeps.
You are reading this because you are about to let your firm's AI agent work in your Google account, or because someone at your firm asked what happens to the data. Both answers are short.
The short version
Your work stays in your own account.
Vorkane does not hold your email, your files or your diary. It carries them between Google and your agent at the moment you ask for something, and keeps no copy when the answer comes back.
Vorkane signs in as you, so it reaches what you reach and nothing else. There is no shared account behind it, and it cannot act as a colleague or as the firm.
Two things are kept, and both are covered below: your sign-in, so you do not have to reconnect every morning, and a record of what was done, which is written to exclude what was in it.
What is kept
Two things, and neither is your content.
- Your mail and filesNot kept. The text of an email, the contents of a document, an attachment, a diary entry: these pass through memory while your request is being answered and are not written down, cached or copied anywhere. If you deleted Vorkane tomorrow there would be nothing of yours to hand back, because it is all still sitting in your own Google account where it always was.
- Your sign-inKept, encrypted, on the machine running your firm's connector. It is what stops you reconnecting every time. It is deliberately never backed up anywhere: losing it costs you a thirty-second sign-in, and an offsite copy of a live key to your mail is a liability with nothing to show for it. It lapses on its own after a year unused, and withdrawing your permission at Google stops it working immediately.
- A record of what was doneKept, on the same machine. One line for each action: who did it, which tool, whether it read or wrote, whether it worked, and Google's own reference for the item. It is built to leave out what was in it. Who you emailed, what you searched for, subject lines, the text of anything, and the names of documents and files are all excluded, by listing what may be recorded rather than what may not, so that a field nobody has thought about yet stays out by default.
- This websiteNo cookies, no analytics and no tracking. Every page loads one file and makes no other request, which you are welcome to confirm in your browser's network tab. The one script on the site switches between light and dark, and the preference it saves stays in your own browser and is never sent anywhere. I can see from Cloudflare that somebody visited; I can't see who.
Who else sees it
Google, your agent's maker, and nobody after that.
- GoogleWhere your data already lives. Vorkane reads and writes it through Google's own interfaces, under permission you granted from your own account and can take back the same way. Your firm's Workspace rules on sharing, group membership and access apply exactly as they did before.
- Your agent's makerWhatever you send your agent, and whatever Vorkane hands back for it to work with, reaches the company that runs the agent: Anthropic for Claude, OpenAI for Codex. It is covered by the terms your firm has with them. This is the one place your content leaves Google, and it happens because you asked the agent a question. Vorkane never sends anything on its own.
- Nobody elseThe connector makes no other outbound connection. There is no analytics service, no error reporting, no usage tracking and no third-party service of any kind behind it. The record of actions stays on your firm's own deployment and is never shipped anywhere central. I don't sell anything to anyone, and there is nothing here to sell.
- Advertising and trainingData obtained through Google's interfaces is used to provide the feature you asked for and nothing else. It is not used for advertising, not sold, and not used to train any model. Vorkane's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
What you can do
You can end it without asking anyone.
- WithdrawGo to your Google account, then Security, then your third-party connections, and remove Vorkane. It takes about thirty seconds, you don't need my agreement or your administrator's, and it stops working straight away.
- Nothing is destroyedVorkane cannot permanently delete anything. The permission that would allow it is deliberately not requested, so mail and files go to the bin like anything else and you can get them back for thirty days.
- Ask what was doneThe record of actions belongs to your firm and sits on your firm's deployment. Ask and you'll get it.
- Correct or removeIf you want your sign-in and your entries in that record removed rather than left to lapse, say so and I'll do it.
Who is responsible
Your firm owns the data. I run the software.
The connector runs as an application registered inside your firm's own Google account rather than as an outside service, so your firm decides what happens to the data in it and I act on your firm's instructions. The software itself is mine to build and maintain; the data it touches is never mine. In the language of the data protection rules, your firm is the controller and Vorkane is the processor.
Each client's connector runs on its own, with no process or storage shared with any other client.
If this page changes in a way that matters, your firm's contact is told rather than left to notice.
Ask
Anything not answered here has an answer.
Questions about any of the above, from you or from whoever at your firm has to sign it off, come back with specifics rather than assurances. The technical version of every claim on this page is at vorkane.com/how-it-works, and the source it is verifiable against is available on request.