Draft · pending counsel
Privacy
This is a working draft so Google can see what the product does. Counsel has not redlined it. Last written 26 August 2026. Oregon.
Who we are
Steward is a hosted office manager. We operate from Oregon. Write hello@startsteward.com.
What Steward is
You connect Gmail, Calendar, one QuickBooks Online company, and a phone number. Steward runs a night shift on our servers, then puts irreversible acts in front of you at the Table. We do not sell the product as an inbox, a command center, or an unsupervised intern.
Google user data we read
Sign-in uses Google for profile only: openid, email, profile.
Connecting a mailbox is a separate grant. For the night shift we request gmail.readonly (a restricted scope) and calendar.events.readonly. We read Gmail and Calendar on our servers. That is the product: ingest and triage cannot run only in your browser.
If you later enable sending and calendar write, we request gmail.send and calendar.events. Those still execute only after you approve at the Table.
We pull message bodies, headers, attachments needed for receipts, thread metadata, and calendar events. Mail bodies are encrypted at rest with a per-workspace key. We keep copies while the mailbox is connected and the workspace is active. There is no automatic purge clock yet.
Why
Night shift: ingest new mail and events, classify threads, extract receipts and appointments, match them to the books, draft replies, and write Dawn. We use this data to run your office in Steward — not to advertise, not to train a foundation model, not to build a dossier on anyone else.
What we do not do
We do not sell your data. We do not train foundation models on customer mail or calendar.
We do not use Google user data for ads, credit scoring, or any purpose that is not providing or improving Steward’s visible office-manager features.
Limited Use (Google restricted scopes)
Steward’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve user-facing features in Steward. We do not transfer it to third parties except as needed to run those features (our hosting, and actions you approve), or as required by law. We do not allow humans to read it unless you ask us to, it is required for security or legal reasons, or it is aggregated and no longer identifiable. That includes gmail.readonly.
Other data
QuickBooks: we mirror the chart of accounts, vendors, bills, invoices, and related records for the one realm you connect. QBO remains your books of record.
Phone: inbound calls on the Steward number are recorded on our servers (Twilio), transcribed, and turned into appointment drafts. A disclosure plays before the call is connected. We do not write the calendar until you approve.
Pay: when enabled, we hold Plaid processor tokens and Modern Treasury identifiers — not routing or account numbers. Live dollars are off until we say otherwise in product.
Hosting is currently Fly.io in the United States.
How to disconnect, how to delete
Disconnect Gmail or QuickBooks under Office after you sign in. Disconnecting Gmail revokes our Google token. Ingested copies are not wiped by disconnect alone.
To delete: email hello@startsteward.com from the Google account you used, name the workspace, and say you want it deleted. We will delete workspace copies of Google user data (mail, calendar, tokens) and close the Steward copy of that office. We may keep what the law requires, and what you already posted to QuickBooks stays in QuickBooks — that is Intuit’s system, not ours.
There is no self-serve “delete everything” button yet. Asking us is the way.
Children
Steward is for firms. It is not directed at children under 13.
Changes
When counsel redlines this, the live page will change. The draft mark comes off only then.