Cardinal Finance OS privacy notice
Cardinal Finance OS is a private financial workspace for its owner. Access to financial records is restricted to the owner's configured accounts.
Google account and Gmail access
Google sign-in identifies the owner. The optional account feed requests read-only Gmail access and offline authorization. Google grants access to the mailbox; the collector searches for bank activity and statement messages. It retrieves message headers, contents and attachments contained in the original email to maintain financial evidence and provisional activity.
The hosted collector does not send, delete, label or otherwise change Gmail messages. It processes supported bank notifications with deterministic code. It does not send those messages to an AI model as part of routine collection.
Storage and use
The application stores retrieved evidence, extracted records, provenance and processing receipts on its private Railway volume. It encrypts the Gmail refresh token in private storage and restricts financial API and document access to the owner. Google and Railway provide the services used for authorization, retrieval and hosting.
The owner may separately use Codex and connected services to investigate financial evidence. Those interactions use the services and permissions selected by the owner. The hosted Gmail feed itself does not create an AI training dataset or use mailbox information for advertising.
Retention and control
Original financial evidence and processing history remain in the private workspace until the owner authorizes removal. The feed keeps three rolling compressed database snapshots for recovery; other existing backups have their own retention. Revoking access in Google Account stops future authorized Gmail retrieval but does not erase financial evidence already retained.
The owner can revoke the connection under Google Account's third-party connections. For access, correction or deletion requests, contact jc@cardinalinc.io.
Updated 8 September 2026.