Obskur Admin

Privacy Policy

Last updated: September 21, 2026

1.What this policy covers

This policy describes how the Obskur Admin application handles personal data, and in particular how it handles data it receives from Google APIs when you sign in with your Google account. It applies to admin.obskur.studio and to nothing else.

The obskur.studio website has its own, separate privacy policy covering visitors, the contact form and the newsletter. If you came here from the website rather than from the application, that is probably the one you want.

2.Who is responsible

Obskur Admin is operated by Obskur BV, a creative studio based in Tielt, Belgium, acting as data controller. Obskur BV, Deinsesteenweg 250, 8700 Aarsele, Tielt, Belgium. For any question about this policy or about your data, write to info@obskur.studio.

3.Who can use the application

Obskur Admin is a private back office. There is no self-service signup. Accounts exist for the Obskur Studio team and for the client organisations and partners the studio works with, each added by invitation. Signing in requires a Google account whose address sits on a domain the studio has vetted, or matches an exact address a studio administrator invited by name.

4.Which Google permissions are requested

When you sign in, Obskur Admin asks Google for your basic profile (your name, email address and profile picture) and for these further permissions: read access to Gmail (gmail.readonly), send access to Gmail (gmail.send), full access to Google Calendar (calendar), and full access to Google Drive (drive). Google classifies some of these as restricted scopes, which is why this policy exists and why the application is subject to Google verification.

What the application does with each of them is described below. The permissions it asks for are fixed in its Google OAuth client and are shown to you on Google’s own consent screen before you approve them, so a permission not named there cannot be acquired without asking you again.

5.Gmail, read access

Scope: https://www.googleapis.com/auth/gmail.readonly. Obskur Admin reads your mailbox for the purposes described below, including the place where the application receives more than it uses.

Document filing searches recent messages for attachments in PDF or image format, so an invoice or receipt mailed to you is filed against the right entity. The search is on file type alone — has:attachment together with filename:pdf, filename:jpg, filename:jpeg or filename:png — and not on who wrote to you or on what the message is about. Attachments it matches, below a size limit, are sent in full to the document analysis described further down, whatever that attachment turns out to be: private correspondence, a personal photograph, a medical or administrative document that happens to arrive as a PDF. The analysis expects to meet those, because its own classification covers correspondence, reminders and notices as well as anything else, and a document classified that way is filed like the rest rather than discarded. When the filing runs on a schedule rather than from a button in the application, it does not even bound the search by date. To reach an attachment it retrieves the message in full from Google, body included, because that is the form in which the Gmail API returns attachment data. Only the attachments are taken from it: the body is not shown to you, is not sent anywhere else, and is not written to our database.

The inbox panel fetches the sender, subject line and snippet — the first 200 characters Gmail itself supplies — of up to ten unread messages, so the application can show you which ones still need an answer. It runs when you open the Today screen, at most once every four hours, and only between 07:00 and 19:00 in your own timezone. Follow-up detection reads the subject, recipient and date of up to ten messages you sent in the last fourteen days and checks whether anything newer exists in the same thread, to work out whether a client has answered you yet.

Obskur Admin also reads your account profile, which is not your mail. Before a message can go out from your own address, Obskur Admin has to know the address Gmail itself will accept as the sender, so it asks Gmail for your account profile, which returns that email address. Profile metadata is not mailbox content, but the endpoint that answers it is served by the read permission rather than by the send permission, which is why it is named here.

Obskur Admin does not mirror, index or archive your mailbox, and message bodies are never written to our database. What it keeps from your mailbox includes the identifiers of the messages document filing has already handled, so the same attachment is not filed twice; the attachment files themselves, once document filing has taken them in; and, when you turn one of the inbox panel's suggestions into a task, the task title the language model wrote from that message's subject line, together with the Gmail message identifier, which is stored in the task's description. Those last two are stored text derived from your mail, and they stay until you delete the task.

6.Gmail, send access

Scope: https://www.googleapis.com/auth/gmail.send. Obskur Admin can send messages from your own address rather than from a shared robot address, so that clients reply to a person. It is used for quotes, ImageBox delivery and review invitations and notifications, workshop invitations, invitations to join an organisation, and the one-time sign-in code a bookkeeper needs to open the document portal. Obskur Admin also sends the monthly ImageBox storage billing summary this way, to an administrator of the entity concerned, and the ImageBox notifications that a scheduled job flushes when a client comments on or decides about their gallery — see "Access while you are not signed in". Whether a given message leaves through your Gmail account or through our own mail provider depends on the studio's mail configuration; where it leaves through Gmail, it appears in your Sent folder.

Sending is triggered by an action you take in the application, by a scheduled job, or by an action someone else takes that the application answers on your behalf. Obskur Admin does not request the Google permission that allows writing to your Drafts folder, so it cannot leave a draft sitting in your mailbox with the access you grant it. This permission gives the application no ability to read anything; the profile lookup described above is answered by the read permission, not by this one.

7.Google Calendar

Scope: https://www.googleapis.com/auth/calendar. Reading: Obskur Admin lists the calendars on your account and the events in the period currently on screen, so that the built-in calendar view shows your real day and the daily planner can schedule work around meetings that already exist.

Writing is narrower than reading. When you schedule, reschedule or unschedule a task in Obskur Admin, it creates, updates or deletes the corresponding event on your primary calendar. It only ever updates or deletes events it created itself, identified by the event id it stored when it made them. It does not modify or delete anything else in your calendars.

8.Google Drive

Scope: https://www.googleapis.com/auth/drive. You choose, through a folder picker in the application, which Drive folders Obskur Admin may work in: typically a folder of incoming receipts and invoices, a folder of scanned business cards, and a destination folder for filed documents.

Within that arrangement the application lists your Shared Drives, folders and files so you can pick them; reads and downloads the files in the chosen folders for processing; creates subfolders (dated folders, and folders named "# Scanned" and "# Errors"); moves handled files into them; renames and uploads filed documents back to Drive; and adds or removes a single named bookkeeper address on the permissions of one specific folder.

Obskur Admin requests full Drive access rather than the narrower per-file permission for one concrete reason: the folders it works in already exist, were created by you outside the application, and frequently live on a Shared Drive. The per-file permission only ever sees files the application itself created or that you opened through Google's own picker, so it cannot list or read those folders. Obskur Admin touches only the folders you have configured and the files inside them.

9.Access while you are not signed in

Some of what Obskur Admin does with your Google account happens when nobody is at the screen. Scheduled jobs run each day at 08:00 UTC. For each organisation they select the first administrator or super administrator whose Google account is connected, and act with that person's stored credentials: one searches that mailbox for messages carrying PDF or image attachments and files what it finds, without bounding the search by date; another reads the configured Drive folders and files the documents in them. If you are an administrator, it may therefore be your mailbox and your Drive that these jobs read, at a moment when neither you nor anyone else is signed in.

Outgoing mail runs unattended as well, and far more often. A job runs every five minutes to flush ImageBox notifications that were waiting — a comment a client left, a decision on a gallery, a selection submitted. Each of those is addressed to the administrator resolved for the entity concerned, and where the studio's mail configuration has mail leaving through Gmail, it leaves through that administrator's Gmail account with nobody signed in. A monthly job, on the first day of the month, does the same with the ImageBox storage billing summary. Caps on how many messages one account may send per hour and per day bound the volume, but within those caps mail can leave your account around the clock.

The same pattern applies outside the schedule. When a bookkeeper you invited requests a sign-in code for the document portal, that message is sent from the mailbox of the entity's owner, or failing that of the first administrator in the organisation with a Google account connected. Granting and revoking a bookkeeper's access to a Drive folder is done with the same person's credentials, whoever pressed the button in the application. One person's grant therefore services other people's actions inside their organisation.

This stops the moment that person revokes access in their Google account: the scheduled jobs then find no usable credentials and do nothing.

10.Automated processing and artificial intelligence

Some of this data is processed by a large language model, run by Anthropic and reached through the Anthropic API, in order to provide the feature you asked for. The most frequent of those transfers is the inbox panel: each time it runs it sends Anthropic the sender, the subject line and the first 200 characters of up to ten unread messages, and asks which of them look like they need an action and what the resulting task should be called. That is content from your mailbox leaving our servers, and it happens whenever you open the Today screen and the four-hour interval has passed.

Obskur Admin also sends the Anthropic API: every PDF or image attachment that document filing picked up from Gmail, and every file read from the configured Drive folders, in full and whatever the document turns out to be — receipts and invoices, but equally the private correspondence and unrelated attachments described above — so that fields such as supplier, date, amount and contact details can be extracted; the titles and the start and end times of today's calendar events, together with your open tasks, when a daily plan is generated; the supplier names of candidate expenses, which are names read off documents that came from Gmail attachments or from Drive, together with the bank transaction being matched, when the application proposes which expense a bank line belongs to; the company name, website and industry read off a scanned business card downloaded from Drive, when it enriches a new lead with a description and an industry label; and, where you ask it to draft a reply, the message you are replying to in full, body included; and the titles of your tasks — and, where a task has one, its description — when you ask the application to suggest what to work on next, to break a task into steps, or to estimate how long one will take. That last route reaches your mail indirectly: a task created from an email keeps that subject line as its title and the Gmail message identifier in its description, so both travel with it.

This processing happens to deliver the user-facing feature and nothing else. Google user data obtained through the scopes above is not used, by us or by any processor acting for us, to develop, improve or train generalised artificial intelligence or machine learning models. It is not used for advertising, is not sold, and is not transferred to data brokers or information resellers.

11.Limited Use

Obskur Admin's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means: the data is used only to provide and improve the user-facing features described in this policy; it is not transferred to others except as necessary to provide those features, for security purposes, or to comply with applicable law; it is not used for serving advertising; and no human reads it except with your explicit permission, for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.

12.What is stored, and what is not

Stored: your name, email address and profile picture from your Google profile; the OAuth access token and refresh token that allow the application to act on your behalf, the refresh token encrypted at rest; the identifiers of email messages already handled by document filing; task titles the language model derived from an email's subject line, together with that message's Gmail identifier, for emails you turned into tasks; the most recent daily plan generated for you, which contains the titles and the start and end times of that day's meetings as read from your calendar; the identifier of each calendar event the application created for one of your tasks; the identifiers of the Drive folders you configured; and the documents recovered from Gmail attachments or from Drive — financial or not, since the search that finds them goes on file type — together with the fields extracted from them.

Not stored: the contents of your mailbox. Message bodies are never written to our database, and senders and snippets are used in the moment and then discarded. Some things derived from your mail are kept, and they are described in the Stored list above: a task you create from an email keeps a title taken from that subject line — written by the language model where one is configured, and otherwise the subject line itself — and attachments that document filing has taken in are stored as business documents. Your calendar is likewise not copied. The daily plan described above is written to our database and holds the titles and times of that day's meetings. It carries a four-hour expiry after which it is no longer served, but the row itself is replaced rather than deleted, so the most recent plan stays stored until a newer one overwrites it or the account is deleted. Drive files stay in your Drive; the ones that went through document filing are copied into our storage as well.

13.Where the data is stored and who processes it

Obskur Admin runs on Vercel (United States) and stores its database and uploaded documents with Supabase. ImageBox galleries and client deliveries are stored on Cloudflare R2. Text and document analysis is performed by Anthropic (United States). Outbound platform email that does not go through your Gmail account is delivered by Resend (United States).

Where personal data is transferred to providers outside the European Economic Area, those transfers are covered by Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

14.Who the data is shared with

Data from your Google account is not sold and is not shared with anyone for their own purposes. It is visible to the processors listed above, acting on our instructions, and within the application it is visible to you and to administrators of your organisation.

One kind of sharing is deliberate and under your control: when you add a bookkeeper in the application, Obskur Admin grants that named email address access to the one Drive folder you designated, using Drive's own sharing. Removing the bookkeeper in the application revokes that access again. The share and the revocation are both performed with the Google credentials of the entity's owner, or failing that of the first administrator in the organisation with a Google account connected — not necessarily with the credentials of whoever pressed the button.

15.How long it is kept

OAuth tokens are kept for as long as your account exists and the connection stands. They stop working as soon as you revoke access in your Google account. Documents filed by the application and the data extracted from them are kept at least as long as Belgian bookkeeping law requires of business records, currently seven years — documents that turned out not to be business records included — and are not deleted automatically; they are removed on request or when the account is deleted. The lists of handled message identifiers and stored calendar event ids are kept while the corresponding feature is in use, and deleted with the account. A task created from an email keeps its title and the message identifier until you delete the task. The stored daily plan is kept until a newer one replaces it or the account is deleted.

When an account is deleted, everything attached to it, tokens included, is deleted with it.

16.Withdrawing access and requesting deletion

You can withdraw Obskur Admin's access to your Google account at any time, without asking us, at https://myaccount.google.com/permissions. Select Obskur Admin and remove access. The application immediately loses the ability to read or write anything in your Gmail, Calendar and Drive.

To have your account and the data stored about you deleted, write to info@obskur.studio from the address you sign in with. We will confirm and carry out the deletion within 30 days. Revoking access in Google stops further access but does not by itself delete what is already stored, so if you want both, do both.

17.Security

Traffic runs over HTTPS. Google refresh tokens are encrypted before they are written to the database. That encryption was introduced after the application was already in use, and a refresh token written before it is still stored in the form it was written: it is read as it stands the first time it is needed and encrypted at that point, so rows predating the change may hold a token in plain text until they are next used. Access tokens, which Google expires within the hour, are stored as issued. Access inside the application is scoped per organisation, so members of one organisation cannot reach another organisation's data. Access to the production infrastructure is limited to Obskur BV.

18.Your rights under the GDPR

As a resident of the European Economic Area, you have the right to access, rectify, erase and port your personal data, as well as the right to object to processing and to withdraw consent. To exercise any of these rights, contact us at info@obskur.studio. We will respond within 30 days. If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit): gegevensbeschermingsautoriteit.be.

19.Changes to this policy

We may update this policy. Any change will be published on this page with an updated revision date. A change that widens what is done with Google user data will be notified to signed-in users before it takes effect.