Legal

Tessaro Data Privacy Policy

Effective Date: 2026-04-29 Last Updated: 2026-04-29 (reflects Google Cloud product rename: Vertex AI Platform → Gemini Enterprise Agent Platform, announced 2026-04-22) Provider: Tessaro Data LLC


Overview

This Privacy Policy applies to all software products and services offered by Tessaro Data LLC ("Tessaro Data", "we", "us"). Tessaro Data builds backend data infrastructure for commerce — surfaced through APIs, MCPs, AI tools, and Google Workspace add-ons.

This policy describes how Tessaro Data products handle data on behalf of users.

Products Covered

Tessaro Data currently offers one product:

  • Data Migration Tool — a Google Workspace Add-on that assists with data migration into target investment-management systems (currently AppFolio Investment Management).

The data handling described below applies to the Data Migration Tool ("the Add-on"). When additional Tessaro Data products are launched, this policy will be updated to describe their specific data handling in their own dedicated sections.

Authentication Data

When you install or sign in to a Tessaro Data product, Google passes through your Google account email and display name as part of standard OAuth authentication. We use this information solely to identify your active session inside the product. We do not store it, transmit it outside of Google's infrastructure, or use it for any other purpose.

Data We Process

The Add-on processes the following data on your behalf:

  • Spreadsheet data — column headers, cell values, and sheet names from Google Sheets documents you open with the Add-on active
  • Email attachment metadata — file names, sizes, and types of attachments in emails you open in Gmail with the Add-on active
  • Email attachment content — file contents when you explicitly click "Analyze" or "Open in Sheets" on a specific attachment

How Data Is Processed

When you use the AI field mapping feature, your spreadsheet data is sent to Google's Gemini Enterprise Agent Platform (formerly known as Vertex AI) for processing. This is a Google Cloud service operating under Google's data processing terms.

  • Data is processed in real-time only — it is not stored after the API call completes
  • Data is sent to Agent Platform endpoints within Google's infrastructure
  • The Add-on provider (Tessaro Data LLC) does not have access to your spreadsheet data, email content, or AI prompt content

Data We Do NOT Collect

  • We do not store, log, or retain any of your spreadsheet data, investor information, or email content
  • We do not have access to Agent Platform prompt or response content — Cloud Logging for AI content is disabled in our project
  • We do not use your data to train AI models — Agent Platform data-for-improvement is disabled
  • We do not sell, share, or transfer your data to any third party
  • We do not collect personal information beyond what Google Workspace provides as part of standard add-on authentication (your Google account email and name)

Data Stored on Your Device / Account

  • API configuration — stored in your Google account's user properties (accessible only to you)
  • Generated spreadsheets — all output stays in your Google Drive

Permissions Requested

The Add-on requests the following Google OAuth scopes. Each scope is limited to the purpose described and is required for the Add-on to function.

ScopePurpose
gmail.addons.executeAllow the Add-on to run inside the Gmail sidebar in response to your interaction.
gmail.addons.current.message.readonlyRead the specific email message you are currently viewing, only when you open the Add-on, so it can detect data-migration attachments. The Add-on does not access any other messages.
gmail.composeCreate a follow-up email draft — populated with a list of fields the Add-on detected as missing — that you can review and send. The Add-on never sends email on your behalf; you always click Send.
gmail.modifySave the generated follow-up draft into your Gmail Drafts folder. The Add-on does not delete, label, archive, or modify any other messages.
spreadsheetsRead input client spreadsheets and write the structured AppFolio import-ready output sheets.
spreadsheets.currentonlyRead/write data only in the spreadsheet you are currently viewing when running the Add-on.
drive.fileCreate new Google Sheets in your Drive from email attachments you explicitly choose to "Open in Sheets". The Add-on does not access any files it did not create.
script.external_requestMake outbound HTTPS requests required by the Add-on's processing logic.
cloud-platformAuthenticate with Google's Gemini Enterprise Agent Platform (formerly Vertex AI) for the AI field-mapping step. No other Cloud APIs are called.

Third-Party Services

The Add-on uses Google's Gemini Enterprise Agent Platform (formerly known as Vertex AI), part of the Gemini Enterprise suite, for AI-powered field mapping using Google's Gemini models. Agent Platform operates under:

No other third-party services are used. No data is sent to any service outside of Google's infrastructure.

Google API Services User Data Policy / Limited Use

The Add-on's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  1. The Add-on only uses access to Google user data for the purposes described in this Privacy Policy and only as required for the Add-on's user-facing features.
  2. The Add-on does not transfer Google user data to third parties except as necessary to provide or improve user-facing features that are prominent in the Add-on's user interface.
  3. The Add-on does not use Google user data for serving advertisements, including retargeted, personalized, or interest-based advertising.
  4. The Add-on does not sell Google user data, and does not transfer or sell Google user data to data brokers, information resellers, or any party that determines credit-worthiness.
  5. The Add-on does not allow humans to read Google user data unless one of the following applies: (a) we have obtained your affirmative agreement to view specific messages or files; (b) doing so is necessary for security purposes (such as investigating abuse); (c) doing so is necessary to comply with applicable law; or (d) the data has been aggregated and anonymized so it can no longer be associated with an individual user.

Data Security

  • All communication occurs over HTTPS/TLS
  • Authentication uses Google OAuth 2.0
  • No data is transmitted outside of Google's infrastructure
  • The Add-on runs entirely within Google Apps Script and Google Cloud

Data Retention

The Add-on does not retain any user data. All processing is ephemeral — data exists in memory only during active use and is discarded when the operation completes.

Cookies and Tracking

The Add-on does not set cookies, use browser local storage, embed analytics scripts, or otherwise track user behavior. The Add-on runs entirely within Google Apps Script and Google Cloud and has no client-side tracking surface.

Children's Privacy

The Add-on is a business-to-business tool intended for use by investment management professionals. It is not directed at, marketed to, or intended for use by children under 13, and we do not knowingly collect personal information from children under 13.

California and EU Resident Rights

Residents of California (under the California Consumer Privacy Act, "CCPA") and residents of the European Union and United Kingdom (under the General Data Protection Regulation, "GDPR") have additional rights regarding personal data, including:

  • Right of access — request a copy of personal data we hold about you
  • Right to deletion — request deletion of personal data
  • Right to rectification — request correction of inaccurate data
  • Right to object — object to certain processing activities
  • Right to data portability — receive your data in a portable format

Because Tessaro Data products do not retain user data — all processing is ephemeral and completes within Google's infrastructure — most requests are resolved by confirming that no personal data is held.

To exercise any of these rights, email support@tessarodata.com with the subject "Privacy Rights Request". We will respond within 30 days.

We do not sell personal information and do not engage in cross-context behavioral advertising.

Your Rights

You can:

  • Revoke access at any time by uninstalling the Add-on from your Google Workspace account (https://myaccount.google.com/permissions)
  • Delete generated files from your Google Drive at any time
  • Request a data inquiry or deletion confirmation by emailing support@tessarodata.com with the subject "Data Request". Because the Add-on does not retain user data, deletion requests are typically resolved by confirming that no data is held. We will respond within 30 days.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated through the Add-on or via email to administrators.

Contact

For privacy questions or data requests:

Tessaro Data LLC Email: support@tessarodata.com