Privacy Policy
Last updated 25 August 2026
Munk builds automations that act inside a client's own accounts. This page explains exactly what data those automations touch, why, and what is never done with it.
Who this is about
Munk is operated by Timothy Richards. Contact: timothy@gomunk.com.
This policy covers the Munk automation service and the Munk application that clients authorise to access their Google account.
Munk's clients are businesses, not the general public. Access is granted deliberately by a client who has engaged Munk to automate part of their own operation, and only after they have connected their own account. Munk does not collect data from visitors to this site.
What Google data Munk accesses
When a client connects their Google account, they grant access to specific services. Munk requests only what its automations actually need:
| Service | What Munk does with it |
|---|---|
| Gmail | Reads incoming messages in order to identify, sort, and log them; applies labels; prepares replies and follow-ups as drafts for a person to review. Some automations do send mail directly where the client has asked for that — scheduled payment reminders, and status summaries sent to the client's own address. Munk does not send mail on a client's behalf except where that behaviour has been agreed. |
| Google Drive | Creates and updates documents that record correspondence and case or client activity, and files them in the client's own Drive. |
| Google Sheets | Reads and writes the tracking spreadsheets that hold the client's working records — enquiries, statuses, follow-up dates. |
| Google Calendar | Reads events and creates or updates entries, for scheduling and availability. |
Access is granted per service. A client can grant some and not others, and the automations that depend on a service simply do not run without it.
Where the data lives
The great majority of it never leaves the client's own Google account. Munk's automations read from and write back to the client's Gmail, Drive, Sheets, and Calendar. The records they maintain are the client's records, in the client's storage, under the client's control.
Munk operates its automations on a dedicated private server that it controls, not on a shared or multi-tenant platform. That server holds:
- Access credentials — the tokens that permit access to a client's Google account, held encrypted.
- Execution records — short-lived logs of what each automation run did, which may include fragments of the message content being processed. These exist so that failures can be diagnosed, and are pruned on a rolling basis.
Munk does not maintain a separate copy of a client's mailbox, drive, or calendar.
Use of AI services
Some automation steps use AI models to draft text or extract details from a message — for example, pulling a name and a request out of an enquiry, or preparing a suggested reply for a person to review.
Where this happens, the relevant content is transmitted to the AI provider solely to produce that specific output, and only for that run. The providers currently used are Anthropic and Google. Munk uses these services under their business API terms, which do not permit the provider to use submitted content to train their models.
Munk does not use client data, or data obtained from Google APIs, to develop, improve, or train any AI or machine-learning model of its own.
Limited Use disclosure
Munk's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Munk never does
- Never sells client data, or data obtained from Google APIs, to anyone.
- Never uses it for advertising, profiling, or marketing of any kind.
- Never uses it to train generalised AI or machine-learning models.
- Never allows humans to read a client's Google data, except where the client asks for help with a specific problem, where it is necessary for security purposes, or where the law requires it.
- Never shares it with third parties beyond the service providers described above.
Security
Access credentials are stored encrypted. The automation server is reachable only over HTTPS and is administered solely by Munk. Access to a client's data is limited to the automations that client has authorised.
No system is perfect. If Munk becomes aware of a breach affecting a client's data, that client will be told promptly and directly.
Retention and deletion
Records created by the automations belong to the client and remain in the client's own Google account for as long as the client keeps them. Munk does not delete them.
On the Munk server, execution records are pruned on a rolling basis and are not kept as a long-term archive.
When an engagement ends — or at any time on request — Munk deletes the client's stored credentials and any remaining execution records, and the automations stop. To request this, write to timothy@gomunk.com.
Withdrawing access
A client can revoke Munk's access to their Google account at any moment, without asking Munk first, at myaccount.google.com/permissions. Revoking access takes effect immediately and the automations stop working.
This website
This site is a plain set of static pages. It sets no cookies, runs no analytics, and embeds no third-party trackers. Nothing is collected from visiting it.
Changes to this policy
If this policy changes, the date at the top of the page changes with it. Where a change materially affects how client data is handled, affected clients will be told directly rather than left to notice.
Contact
Questions about this policy, or about what Munk holds: timothy@gomunk.com.