Effective and last updated: July 16, 2026.
1. Scope and roles
This Privacy Policy applies to the InOffice website, virtual office application, and related services. “InOffice,” “we,” and “us” refer to Akash Deep, the operator of those services.
When an organization provides your workspace, that organization controls the workspace and may determine why account, profile, messages, files, attendance, and calendar information is used. InOffice processes that information to provide the service to the organization. For our public website, account administration, security, and direct customer relationship, InOffice determines the purposes described in this policy.
2. Data we access
Google account data
If you choose “Continue with Google,” we request the OpenID, email, and profile permissions. We receive your Google account identifier, email address, email-verification status, name, and related authentication response. We use this information to authenticate you, create or match your InOffice account, set an initial display name, and protect the sign-in flow. We retain the Google account identifier and email address; the authentication access token is not retained after sign-in.
Google Calendar data
Calendar connection is optional and separate from Google sign-in. If you connect it, we request only the read-only Google Calendar scope (https://www.googleapis.com/auth/calendar.events.readonly). This permits read-only access to events on your calendars. InOffice reads events from your primary calendar and accesses event identifiers, calendar identifiers, titles, start and end times, all-day status, free/busy or transparency status, update time, and cancellation status. We do not request permission to read calendar settings or sharing rules, or to create, edit, or delete Google Calendar events.
We also receive and store OAuth access and refresh tokens, token expiry information, and a Google sync cursor so the connection can continue until you disconnect it or Google revokes access. We do not retain event descriptions, attendee lists, conference links, locations, or attachments.
Other service data
We collect information you or your organization provide, such as account and workspace details, messages, files, preferences, support communications, and billing records. We also process device, browser, IP address, session, security, and diagnostic data needed to operate and protect the service. InOffice does not record audio or collect screenshots, keystrokes, per-app usage, or productivity scores.
3. How we use Google user data
We use Google user data only to provide these user-facing features:
- sign you in and maintain your InOffice identity;
- show your connected calendar and today's events;
- determine whether an event is busy and, only if you opt in, offer a status suggestion that you must explicitly accept;
- sync changes and troubleshoot or secure the integration; and
- comply with law and enforce security where necessary.
Connecting a calendar does not automatically change your presence or status. We do not use Google user data for advertising, retargeting, credit decisions, data brokerage, or developing, improving, or training generalized artificial- intelligence or machine-learning models. Our use and transfer of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5. Data storage and protection
We use access controls, tenant isolation, least-privilege service access, encrypted network connections, monitoring, and audit controls designed to prevent unauthorized access, alteration, loss, or disclosure. Google OAuth access and refresh tokens are encrypted using authenticated encryption before database storage and are not placed in application logs. We store only normalized calendar fields needed for the visible calendar and suggestion features, rather than the complete Google API response.
No system is perfectly secure. If you believe your account or data is at risk, contact us promptly using the address below.
6. Data retention and deletion
Google identity information is retained while your InOffice account is active so we can authenticate and identify it. Google Calendar tokens, the sync cursor, and the minimal event cache are retained only while the Calendar connection remains active. When you select Disconnect Google Calendarin InOffice, we attempt to revoke the Google token, immediately delete the cached Google events, and remove stored tokens and the sync cursor from the active connection record.
You may also revoke InOffice from your Google Account's third-party connections page. Revoking at Google stops future access; use InOffice's disconnect control or contact us to remove the existing cache and connection data.
To request deletion of your InOffice account and associated personal data, email support@akash-deep.com with the subject “InOffice data deletion request.” We will verify your identity and delete or de-identify data unless we must keep limited records for security, fraud prevention, legal compliance, disputes, or legitimate financial recordkeeping. If your account belongs to an organization, its authorized workspace owner may need to approve deletion of organization-controlled content.
7. Your choices and rights
Google sign-in and Google Calendar access are optional. You can disconnect Calendar at any time and can manage Google permissions in your Google Account. Depending on where you live, you may have rights to access, correct, export, object to, restrict, or delete personal data. Send a request to the contact below. You may also complain to your local data-protection authority.
8. Changes and contact
We will update the date above when this policy changes. If we materially change how we use Google user data, we will provide notice and obtain consent before using it for a new purpose when required.
Questions, privacy requests, and deletion requests may be sent to support@akash-deep.com.