Privacy policy
Last updated 21 September 2026
Gracious Workplace (workplace.gjco.jp) is a business email, calendar and communication application operated by Gracious Japan Co., Ltd. (グレーシャス日本株式会社) for its staff, group companies and their clients. This policy explains what information the application handles and how it is protected.
Information we handle
- Account information: your name, work email address, role and company membership.
- Mailbox and calendar data from connected accounts (Google Gmail / Google Calendar, Microsoft 365 Outlook, Zoho Mail): message headers, message bodies, attachments, labels and folders, calendar events, and the addresses you send to. This data is accessed only for the mailboxes you connect yourself.
- Chat, call and meeting data you create in Gracious Connect (messages, files, meeting schedules).
- Technical data needed to run the service: sign-in sessions, device push-notification subscriptions, and error logs.
How we use it
Data from connected accounts is used solely to show you your own mail and calendar inside Gracious Workplace, to send messages and calendar invitations on your behalf when you ask, to notify you of new messages, and to let colleagues you explicitly delegate access to work in your mailbox. We do not use this data for advertising, we do not sell it, and we do not use it to train artificial-intelligence models. Optional AI features (for example translation) send only the text you choose to translate to the AI provider and nothing else.
Google user data
Gracious Workplace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is read to display your mailbox, to synchronise message metadata and bodies into your private mailbox store, and to send mail you compose. Calendar data is read and written only for the calendars you choose to show. No human reads your Google data except with your explicit permission, when required for security or legal reasons, or in aggregated, anonymised form.
Storage and security
Data is stored in a Supabase (PostgreSQL) project hosted in the Asia-Pacific (Tokyo) region and served from Vercel. Access tokens for connected accounts are stored encrypted at rest on the server and are never sent to the browser. Every person can only read their own data; delegated access must be granted by the mailbox owner or a company administrator and is recorded. All traffic is encrypted in transit (HTTPS).
Sharing
We share data only with the service providers needed to run the application (Supabase, Vercel, the email providers you connect, LiveKit for calls, the push-notification services of your browser, and the AI provider for optional features), each bound by their own data-processing terms, and with authorities when legally required.
Retention and deletion
Synchronised mailbox data is kept while an account stays connected so the mailbox loads quickly. Disconnecting an account from Settings → Accounts revokes our access and removes its cached messages; you can also revoke access from your Google, Microsoft or Zoho account security page at any time. Leaving the company, or asking us at the address below, deletes your remaining data within 30 days, except where retention is required by law.
Your rights and contact
You may ask to see, correct, export or delete your data at any time. Contact: eugenegracious@gmail.com. We may update this policy; the date at the top shows the latest version.