Effective September 3, 2026 · Operator: aSpace (provider of the MATO service)
MATO is a service where companies work with AI staff through their Telegram bot and a web console. This policy explains what Google data MATO accesses when a user links a Google account, and how it is used, stored, and deleted.
1. Google data and scopes
MATO accesses only the scopes the user grants on Google's consent screen after asking the bot to link Google. The default link covers Calendar, Sheets, and sending Gmail. Reading Gmail requires a separate, explicit consent.
Service
Scope
Purpose
Default
Google Calendar
calendar.events
List, create, and delete events on the user's request
Yes
Google Sheets
spreadsheets
Read, write, append, create, and format spreadsheets on the user's request
Yes
Gmail (send)
gmail.send
Send email the user asked the AI staff to compose, from the user's account
Yes
Gmail (read)
gmail.readonly
Search and read the inbox on the user's request
No (separate consent)
2. How data is used
Google data is used only to carry out the specific task the user explicitly requested in Telegram or the web console.
Requests are processed inside the user's company-dedicated runtime (an isolated server per company, or the company's own PC). Data is never shared across companies.
Google data is not used for advertising, profiling, creditworthiness, or training generalized AI models.
Humans read Google data only with the user's explicit consent, for security purposes, to comply with law, or in aggregated, anonymized form for internal operations.
3. Storage and security
Refresh tokens are stored per chat inside the company runtime, in owner-only files (mode 0600). They are not stored on MATO's central servers.
During linking, tokens returned by Google are held for at most 10 minutes until the one-time confirmation code is used, then deleted.
Retrieved mail, events, and sheet contents are processed to answer the request and are not retained, except for outputs the user asked the AI staff to save.
All transport is encrypted with HTTPS. Keys and secrets live only in owner-only files and are never logged.
4. Third parties
MATO does not sell or share Google user data with third parties. Parts of the request context may be sent to AI model providers (Anthropic, OpenAI) strictly to perform the task the user requested.
Ask the bot to unlink Google, or contact us below, and the stored tokens and link records in the runtime are deleted.
When a company's contract ends, its runtime and the link records in it are deleted.
6. Google API Services User Data Policy
MATO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Changes
Changes are posted on this page with a new effective date. Material changes are announced through the Telegram bot.