01 / Scope
What this policy covers
This policy covers the Literature Aggregator informational website and the operator-controlled workflow that connects to Gmail through Google OAuth. The application is used for private literature monitoring and is not offered as a public account-based service.
02 / Information accessed
Read-only Scholar alert data
The application requests the Gmail API scope https://www.googleapis.com/auth/gmail.readonly. For messages from Google Scholar Alerts, it may access:
- sender and message headers needed to identify the alert;
- subject, Gmail message identifier, RFC Message-ID, and received date;
- plain-text or HTML message content needed to extract literature results; and
- paper titles, author and publication information, snippets, and links contained in the alert.
The production workflow filters for the Google Scholar alert sender and configured alert types. It does not download attachments. The read-only scope technically permits viewing Gmail messages and settings, but the workflow is designed for the Scholar-alert purpose described above.
No mailbox changes: the workflow does not send email, mark messages as read, move them, archive them, or delete them.
03 / Use
Why the information is used
Information from Scholar alerts is used only to:
- identify whether a message belongs to an enabled literature alert;
- extract bibliographic information and the alert snippet;
- deduplicate the same paper when it appears in multiple alerts;
- retain the tracking sources that discovered each paper; and
- prepare a paper-level literature digest for the operator.
Google user data is not used for advertising, credit decisions, surveillance, or general-purpose profiling.
04 / Enrichment
External scholarly metadata
The workflow may query OpenAlex and Crossref using a paper title or DOI to obtain or verify public bibliographic metadata, such as authors, journal, publication date, canonical link, or abstract.
These enrichment requests are limited to scholarly identifiers or citation information. The workflow is not designed to send the connected Google account identity, OAuth token, full mailbox, or full email message to those services.
05 / Storage
Local records and retention
Source-derived message identifiers, routing results, alert snippets, parsed bibliographic metadata, source labels, and delivery records are stored in a PostgreSQL database controlled by the operator. The system and database run locally and are not exposed through this public website.
OAuth credentials are held by the local n8n credential system. They are not embedded in this website, committed to the project repository, or included in workflow exports.
No fixed automatic retention period is currently configured. Locally stored records remain until the operator deletes them. Original messages remain in Gmail under the connected account's own retention and deletion settings.
06 / Security
Security boundary
The application follows a limited-access design: Gmail access is read only, the operational system runs locally, credentials are kept out of the static site and source repository, and the public website does not connect to the database or workflow runtime.
No claim is made that the project has undergone an independent security audit or holds a security or privacy certification. As with any software system, absolute security cannot be guaranteed.
08 / Deletion
Revoke access and remove data
Because this is a single-operator local deployment, there is no public self-service account or deletion endpoint. The operator can stop access and remove data by:
- revoking Literature Aggregator's access in the connected Google Account's third-party access settings;
- disconnecting or deleting the Scholar Gmail OAuth credential in the local n8n instance; and
- deleting related records from the local PostgreSQL database and any operator-managed backup copies, where applicable.
Revoking Google access stops future Gmail API access but does not by itself delete records already stored locally. Those records must be removed separately by the operator.
Questions or deletion requests can be directed to the developer support contact displayed on the Google OAuth consent screen.
09 / Website
Static site data
This website does not create user accounts, accept uploads, set tracking cookies, run analytics, serve advertising, or load external JavaScript. It does not contain a connection to the local Literature Aggregator system.
The site is planned to be hosted on Cloudflare Pages. As the hosting provider, Cloudflare may process ordinary network information such as IP addresses, request headers, and service logs under its own terms and privacy practices. This site does not add separate visitor tracking.
10 / Changes
Updates to this policy
This policy may be updated if the application's data practices change. The effective date at the top of this page will be revised when a material update is published.