IMBOX
Balrog · Privacy

Balrog Privacy Policy

How Balrog accesses, uses, stores and shares Google user data when you connect Gmail, Google Drive or Google Calendar.

Effective date: 8 September 2026

Who is responsible for Balrog

Balrog is an IMBox product provided by SPOTBROS TECHNOLOGIES, S.L. ("SPOTBROS", "IMBox", "we" or "us"), with registered address at Calle Antonio Acuña 17, Madrid, Spain, Tax ID B-95662581. You can contact us at support@imbox.me or contact our Data Protection Officer at fernando.calvo@imbox.me.

This policy supplements the general IMBox privacy policy and applies specifically when Balrog connects to Google Workspace services.

Google user data Balrog accesses

Balrog accesses Google user data only after you connect a Google Account and grant OAuth consent. Access is limited by the connectors, resources and permissions you choose.

  • Google Account identity: account identifier, verified email address and the OAuth permissions granted.
  • Gmail: message and thread metadata, message content, recipients, drafts and attachments. Depending on the permissions enabled, Balrog may also create, update or delete drafts and send, reply to or forward messages.
  • Google Drive: file and folder metadata, content, exports and comments for resources within the selected scope. Depending on the permissions enabled, Balrog may create, upload, update, move, copy, comment on, trash, restore or delete permitted resources.
  • Google Calendar: calendar metadata, free/busy information, events, descriptions, attendees, reminders and conference details. Depending on the permissions enabled, Balrog may create, update, respond to or delete events.

How we use Google user data

Balrog uses Google user data solely to provide the user-facing connector features you request: finding, reading, summarising and organising information, preparing content, and carrying out an explicitly requested action.

Balrog applies the permissions configured for each connector. Operations that change Google data are initiated by the user and, where the product presents a preview or confirmation step, are not committed until that confirmation is given.

We do not use Google user data for advertising, sale, creditworthiness, lending, surveillance or unrelated profiling.

Storage and security

OAuth refresh tokens are stored on the user's device in the operating system credential store. Access tokens are held only in memory while needed. Google content and OAuth tokens are not synchronised to the IMBox backend and are not intentionally written to application logs.

The IMBox backend may retain the connector configuration needed to make the connector available to the user's workspace, such as the expected Google account email, enabled permissions and opaque identifiers for selected resources. It does not receive the user's Google content or OAuth tokens.

Balrog may create encrypted local operation previews, paging handles or downloaded artefacts. These are short-lived and designed to expire automatically, normally within 15 minutes for prepared changes and 30 minutes for paging handles and artefacts.

AI processing and sharing

Balrog uses Codex and OpenAI to interpret a user's request and produce a response. Relevant Google user data returned by a connector may be transmitted to OpenAI solely when necessary to provide the user-facing feature requested by that user. Neither Balrog nor its processors use Google user data for any independent purpose.

Balrog does not use Google Workspace APIs or Google user data to develop, improve or train generalised or non-personalised artificial intelligence or machine-learning models. SPOTBROS does not permit OpenAI or any other processor to use Google user data for those purposes.

We disclose Google user data only to processors needed to provide the user-facing Balrog feature requested by the user, when the user explicitly directs us to disclose it, or when required by applicable law. We do not sell Google user data or use it for advertising, profiling, data brokerage, creditworthiness or lending.

Retention, disconnection and deletion

Local Google credentials remain on the device until the user disconnects the Google Account in Balrog, removes the local application data or revokes Balrog's access through the Google Account permissions page. Expired temporary artefacts and operation data are deleted locally by Balrog's cleanup process.

You can revoke Balrog at any time from your Google Account at myaccount.google.com/permissions. You may also request help deleting Balrog or IMBox account data by contacting support@imbox.me. Any Google user data processed by an AI provider is retained only as needed to provide or secure the user-facing feature requested by the user and is not authorised for model development, improvement or training.

Google API Services User Data Policy

Balrog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Human access to Google user data is prohibited except when the user has given affirmative permission for support, when necessary to investigate abuse or a security incident, or when required by applicable law.

Legal basis and your rights

We process data to provide Balrog at your request, perform our contract with you or your organisation, protect the service and comply with legal obligations. Where consent is the applicable basis, you may withdraw it at any time without affecting prior processing.

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection. You may also lodge a complaint with the Spanish Data Protection Agency. Requests can be sent to the contacts listed above.

Changes to this policy

We may update this policy when Balrog, its Google integrations or legal requirements change. We will publish the updated version at this URL and change the effective date. Material changes will be communicated through an appropriate channel.