Privacy Policy
Last updated: 23 September 2026
Vaktcentralen – VaktPosten is a privately operated email-delivery monitoring service. This policy explains how VaktPosten accesses, uses, stores, and shares Google user data when a Gmail account is connected to the service.
Google data VaktPosten accesses
VaktPosten uses Google OAuth and the Gmail API. Its requested Gmail permissions are limited to the functionality needed to:
- search for expected messages in the authorized Gmail account, including Spam and Trash;
- read message metadata needed to identify a message, such as RFC822 Message-ID, date, and selected addressing headers;
- import an original RFC822 message into Gmail when that message is confirmed missing from an intended destination.
The application currently requests the Gmail scopes gmail.readonly and gmail.insert.
How Google user data is used
Google user data is used only to verify whether expected forwarded email has arrived and, when necessary, to repair a failed delivery by importing the corresponding original message into the authorized Gmail account.
VaktPosten does not use Google user data for advertising, marketing, profiling, sale of data, or training generalized AI or machine-learning models.
Data storage
VaktPosten stores only the operational information required for monitoring and message matching. Gmail message bodies are not persistently stored as part of normal monitoring. When a missing message is repaired, the original message is obtained from the configured source mailbox, held in memory for the import operation, and sent to Gmail.
For unattended operation, the Google OAuth refresh token is stored locally on the machine running VaktPosten and protected using Windows Data Protection API (DPAPI) machine-scope encryption. OAuth access tokens are short-lived and are not persistently stored. The OAuth client credentials and other protected secrets are stored locally in access-restricted protected storage.
Data sharing and disclosure
VaktPosten does not sell Google user data and does not share Google user data with third parties for advertising, marketing, analytics, or other unrelated purposes. Data is processed only as required to provide the email-delivery monitoring and repair functionality described above.
Human access
VaktPosten is designed for automated operation. It does not provide third parties with human access to Gmail data. Any direct access by the operator is limited to administration, troubleshooting, security, or maintenance of the privately operated service.
Security
VaktPosten uses OAuth 2.0 for Gmail authorization. Stored refresh tokens are protected locally with Windows DPAPI, and the protected secret storage is restricted by Windows access controls. The service is designed to minimize persistent storage of email content.
Retention and deletion
Operational monitoring records may be retained locally to support delivery history and service operation. Gmail message content is not persistently copied into VaktPosten during normal monitoring or automatic repair. OAuth access can be revoked at any time from the connected Google Account. Local authorization credentials can then be removed from the machine running VaktPosten.
Google API Services User Data Policy
VaktPosten's use and transfer of information received from Google APIs is limited to providing the functionality described in this policy and is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.
Changes to this policy
This policy may be updated if VaktPosten's functionality or handling of Google user data changes. The current version will be published at this URL with an updated revision date.