Privacy
Privacy Policy
Effective September 17, 2026
Agent Doorbell is operated by NthPlus (“we”, “us”). It watches the Gmail accounts you connect for new messages that match rules you set, then wakes the agent routine you choose. This policy explains what information we collect, how we use and share it, and the choices you have. It applies to agentdoorbell.com, the Agent Doorbell dashboard, and the Agent Doorbell plugin.
Information we collect
- Sign-in information. The email address you sign in with, your sign-in sessions, and, if we invited you, a record of your invitation: who invited you and when you were invited, first signed in or had your access revoked. Deleting your data does not remove this record, so your invited address can still sign in. When you sign in with Google, Google provides your Google account identifier, name, email address and profile photo URL. We store Google's sign-in tokens encrypted. Signing in with Google does not give us access to your Gmail.
- Connected Gmail accounts. When you connect a Gmail account, Google provides its email address and OAuth tokens that let us read that account's message metadata.
- Gmail message metadata. For each new message that arrives in a connected inbox while a notifier is active, we read its message ID, labels, received time, and its From, To, Cc and Subject headers. We also read Gmail's mailbox history identifiers to find new messages.
- Notifier settings. Notifier names, matching rules, and the destination URL and key you provide.
- Wakeup history. Records of wakeups we sent, including the notifier, the connected Gmail addresses where matching activity occurred, and whether the destination accepted the wakeup.
- Plugin connections. Records of the AI assistants you authorize to manage your notifiers, and the tokens issued to them.
To connect Gmail, we request only Google's gmail.metadata permission. It does not allow access to message bodies or attachments, and Agent Doorbell never requests them.
How we use Google user data
We use Google user data only to provide the features you configure:
- to sign you in, when you sign in with Google;
- to identify the Gmail account you connected;
- to receive Gmail's notifications about new messages in that inbox;
- to compare a new message's sender, recipients and subject with your notifier's matching rules; and
- to send a wakeup to your chosen destination when a message matches.
Message headers used for matching stay in memory except the source properties selected on that notifier, which are stored on the first matching contribution. A wakeup includes only those selected properties, default none, and never message bodies. We keep message IDs for 30 days only so the same message cannot trigger a notifier twice.
We do not sell Google user data, use it for advertising, use it to develop, improve or train artificial intelligence or machine learning models, or use it to determine creditworthiness. No person at NthPlus reads your Gmail data unless you give us permission for a specific support request, it is necessary for security purposes such as investigating abuse, it is required to comply with law, or it has been aggregated and anonymized for internal operations.
How we share information
- Your destination. Wakeups go to the agent routine you configure. You control that destination and any separate mailbox access you give it.
- Service providers. Railway hosts our application and database. Google Cloud Pub/Sub delivers Gmail change notifications. Resend delivers sign-in links and service alerts to your sign-in address. They process data only to provide these services to us.
- Legal requirements. We may disclose information when required by law or to protect the security of our service and its users.
We do not transfer Google user data to anyone else. If Agent Doorbell is involved in a merger, acquisition or sale of assets, we will ask for your explicit consent before transferring your Google user data.
Storage and security
Gmail OAuth tokens and destination keys are encrypted with AES-256-GCM before they are stored, and sign-in links are stored only as hashes. Data travels over HTTPS, and our database is reachable only from our application's private network. Access to production systems is limited to the people who operate Agent Doorbell.
Retention and deletion
- Wakeup history is deleted after 7 days, and the message IDs used to prevent duplicates after 30 days.
- Disconnecting a Gmail account in the dashboard immediately deletes its stored tokens and monitoring records.
- Deleting your data from the dashboard removes your sign-in account, connected Gmail accounts, notifiers, destinations and history.
- You can remove Agent Doorbell's access at any time from your Google Account permissions. We then stop accessing that mailbox and show it as needing reconnection.
Deleted data can remain in infrastructure backups until those backups expire.
Your choices
While you can sign in, you can view, change and delete your connected accounts, notifiers and destinations in the dashboard, and delete all your data there. If your access has ended, email privacy@agentdoorbell.com and we will temporarily restore your access so you can delete your data. Contact us to ask about or correct the information we hold about you.
Google API Services User Data Policy
Agent Doorbell's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Children
Agent Doorbell is intended for business use and is not directed to children under 13. We do not knowingly collect their information.
Changes
We will post changes on this page and update the effective date. We will notify you by email of material changes.
Contact
Send questions or requests to privacy@agentdoorbell.com.