← Vaktcentralen – VaktPosten

Privacy Policy

Last updated: 23 September 2026

Vaktcentralen – VaktPosten is a privately operated email-delivery monitoring service. This policy explains how VaktPosten accesses, uses, stores, and shares Google user data when a Gmail account is connected to the service.

Google data VaktPosten accesses

VaktPosten uses Google OAuth and the Gmail API. Its requested Gmail permissions are limited to the functionality needed to:

The application currently requests the Gmail scopes gmail.readonly and gmail.insert.

How Google user data is used

Google user data is used only to verify whether expected forwarded email has arrived and, when necessary, to repair a failed delivery by importing the corresponding original message into the authorized Gmail account.

VaktPosten does not use Google user data for advertising, marketing, profiling, sale of data, or training generalized AI or machine-learning models.

Data storage

VaktPosten stores only the operational information required for monitoring and message matching. Gmail message bodies are not persistently stored as part of normal monitoring. When a missing message is repaired, the original message is obtained from the configured source mailbox, held in memory for the import operation, and sent to Gmail.

For unattended operation, the Google OAuth refresh token is stored locally on the machine running VaktPosten and protected using Windows Data Protection API (DPAPI) machine-scope encryption. OAuth access tokens are short-lived and are not persistently stored. The OAuth client credentials and other protected secrets are stored locally in access-restricted protected storage.

Data sharing and disclosure

VaktPosten does not sell Google user data and does not share Google user data with third parties for advertising, marketing, analytics, or other unrelated purposes. Data is processed only as required to provide the email-delivery monitoring and repair functionality described above.

Human access

VaktPosten is designed for automated operation. It does not provide third parties with human access to Gmail data. Any direct access by the operator is limited to administration, troubleshooting, security, or maintenance of the privately operated service.

Security

VaktPosten uses OAuth 2.0 for Gmail authorization. Stored refresh tokens are protected locally with Windows DPAPI, and the protected secret storage is restricted by Windows access controls. The service is designed to minimize persistent storage of email content.

Retention and deletion

Operational monitoring records may be retained locally to support delivery history and service operation. Gmail message content is not persistently copied into VaktPosten during normal monitoring or automatic repair. OAuth access can be revoked at any time from the connected Google Account. Local authorization credentials can then be removed from the machine running VaktPosten.

Google API Services User Data Policy

VaktPosten's use and transfer of information received from Google APIs is limited to providing the functionality described in this policy and is intended to comply with the Google API Services User Data Policy, including its Limited Use requirements.

Changes to this policy

This policy may be updated if VaktPosten's functionality or handling of Google user data changes. The current version will be published at this URL with an updated revision date.