Privacy Policy
Last updated July 8, 2026
Doable is an AI workspace and chief-of-staff assistant. This policy explains what data Doable accesses, why, how it is used and stored, and the choices you have. It covers data from Google services (Gmail, Google Calendar, Google Contacts, and — for a near-term feature — Google Drive) as well as data you enter directly.
Doable is a product of Words and Music and is currently offered as a private alpha. If anything here is unclear, contact us at support@wordsandmusic.tech.
Google user data
Doable accesses Google data only after you authorize it through Google's consent screen, and only for the scopes you approve. Below is what each connection is used for and what, if anything,Doable stores.
Gmail
- Reading mail — When you ask Doable about your email or ask it to act on a message, it reads the relevant messages (including sender, subject, metadata, snippets, and body content) to understand the request and prepare a response.
- What is stored — For the inbox/notification feature, Doable stores limited message details (sender name and address, subject, received time, a short summary, and a short body excerpt) so it can show and act on recent items. Draft text and recipient information you work on can also be saved as part of your conversation history. Doable does not store full copies of your mailbox.
- Drafts & sending — Doable can create Gmail drafts and send email, but only for messages you review and confirm. A record of the action (recipient, subject, and outcome) is kept so you have a history of what was done.
- Send-as identities — Doable reads your Gmail send-as settings so that mail is sent from the correct address you use.
Google Calendar
Doable reads your calendar to show your agenda and find free time, and creates, updates, or deletes events only when you approve them. Event details are used to answer your requests and may appear in your conversation history; events you create or change are written to your Google Calendar.
Google Contacts
When you ask Doable to email someone by name, it looks up your contacts and other contacts to find the right address. Doable may remember that a name maps to a particular email address (a resolution memory) so it can act faster next time. It does not import or store your full contact list.
Google Drive (near-term feature)
Doable is adding the ability to work with Google Drive files and folders that you specifically select through Google's file picker, using the narrow drive.file scope. This scope limits Doable to only the items you choose or create with it — not your entire Drive.
- To reference a selection, Doable may store the file or folder's identifier, name, and link.
- If you ask Doable to act on a selected file (for example, attach it to an email), the file's content is transmitted only as needed to complete that action.
- Doable does not browse, index, or download your Drive beyond the files and folders you select.
How Google data is used
Doable's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide and improve the features described above.
- Doable does not sell your Google user data.
- Doable does not use it for advertising, for credit or lending decisions, or transfer it to data brokers.
- Doable does not use your Google user data to train generalized or unrelated AI models.
To generate drafts, summaries, and answers, Doable sends the content necessary for your request to third-party AI model providers (such as Anthropic and OpenAI). These providers process the content solely to return a result for you and, under their API terms, do not use it to train their models. They are the only sub-processors that receive relevant Google-derived content, and only to deliver the feature you asked for.
Can humans read your Google data?
Doable does not allow anyone to read your Google user data except in the limited cases the Google API Services User Data Policy permits: with your explicit consent (for example, when you ask us for support on a specific item); where necessary for security or to investigate abuse; to comply with applicable law; or as part of operations on data that has been aggregated and anonymized. Automated processing to provide the features above is not human access.
Storage, protection, and separation
- Your data is stored in Doable's application database and is scoped to your own workspace, kept separate from other users' data.
- Your Google OAuth tokens are encrypted at rest (AES-256-GCM) so they are not stored in plain text.
- Doable accesses Google APIs on your behalf using these tokens over encrypted connections; it never receives or stores your Google password.
Retention, revocation, and deletion
- Revoke access — You can disconnect Google inside Doable (which deletes the stored tokens) or remove Doable at myaccount.google.com/permissions at any time. After that, Doable can no longer access your Google account.
- Retention — Data Doable stores (such as conversation history and the limited email details above) is kept to provide the service until you delete it or request deletion.
- Deletion — You can request deletion of your stored data by emailing support@wordsandmusic.tech. We will delete your workspace data and disconnect any linked accounts.
Other data you provide
Aside from Google data, Doable stores what you enter to use the product: your messages and requests, tasks, notes, preferences, and files you upload. This is used only to operate the service for you and is subject to the same protections and deletion rights above.
Changes
We may update this policy as Doable evolves. Material changes will be reflected here with a new “last updated” date.
Contact
Questions or requests: support@wordsandmusic.tech.