SPY JUMP Email

Application data practices

Privacy Policy

Last updated: 2026-10-03

This policy covers SPY JUMP Email, a personal desktop application operated by Justin Slaughter, and this application-information website. It does not describe other websites, businesses, or products that may use the same parent domain. The application is currently for its operator's own account, with no public registration.

1. Information accessed and used

The local application uses the Gmail address entered by its operator, a locally generated report, Google OAuth access and refresh credentials, and the metadata returned when Google accepts a send request. It requests the gmail.send permission only.

The report may contain an experimental SPY monitoring score, its observation date, configuration identifiers, and operational status. The address is used as the sender, sole recipient, and Gmail mailbox identifier. Credentials are used to authenticate sending and obtain replacement access tokens.

The application does not retrieve existing Gmail messages, mailbox attachments, contacts, profile information, or calendar events. It does not ask the operator to type a Google password into the application.

2. Purpose and permitted use

Information is used only to authorize the described sending function, deliver a private report, and record whether a submission was accepted or encountered an error. The developer does not sell Google user data, use it for advertising or credit decisions, give it to data brokers, or use it to train general-purpose AI models.

SPY JUMP Email follows the Google API Services User Data Policy, including its Limited Use requirements, for its use and transfer of Google user data.

3. Storage and safeguards

OAuth access and refresh credentials are stored in an encrypted file protected by Windows current-user Data Protection API (DPAPI). They are decrypted in local process memory when needed. The desktop OAuth client configuration is also stored locally, but is not encrypted by this application.

Reports and submission receipts are ordinary local files, not encrypted by the application. Receipts include message identifiers, timestamps, report identifiers, submission status, and a hash of the account address. A hash is not a promise of anonymity. These files should be protected by the operator's computer and backup security.

The Gmail API connection uses HTTPS with certificate and hostname checks. These measures do not make the computer or credentials immune to compromise; software running as the same Windows user may be able to access local information.

4. Information sent to others

Google receives authorization requests, credential-refresh requests, and the outgoing message with its addressing information to perform authentication and email delivery. Google stores sent and received email according to the account's settings and Google's policies. The current sender limits delivery to the operator's own authorized Gmail address.

The public website host does not receive the application's tokens, model files, or report contents through the application. They are not uploaded to this site. The application does not send Google user data to advertising, analytics, or AI services.

Google's services are also governed by Google's Privacy Policy. Local backups or copies made independently by the operator are outside the application's control.

5. Retention, revocation, and deletion

Local credentials, reports, and receipts remain until the operator deletes them; the current implementation has no automatic deletion schedule. Revoking access or allowing credentials to expire does not automatically delete those local files.

To stop Google access, stop running the application, disable any subsequently configured schedule, and remove its access in Google Account connections. The operator can then delete local token files, unnecessary client configuration, reports, receipts, and copies in backups or the Recycle Bin as appropriate.

Deleting a local token alone is not the same as revoking Google's authorization. Deleting local reports does not delete messages already held in Gmail; those can be managed separately in Gmail. This policy does not promise irreversible erasure from independent backups or Google's systems.

6. This public website

The information pages contain no application login, data-entry form, report upload, or advertising/analytics scripts added by the developer. Cloudflare Pages hosts the pages and may process connection information, such as IP addresses and request metadata, to deliver and secure the site. See Cloudflare's Privacy Policy for its practices.

Using the contact email shares your address and message with the operator and the email providers involved. Correspondence remains until the operator removes it. Do not send credentials or confidential investment materials to request support.

7. Changes and contact

These disclosures will be updated before materially different Google-data practices are introduced. Any additional access requires the appropriate disclosure and consent. Public user onboarding, expanded recipients, or new data uses are not part of the current application.

Operator: Justin Slaughter
Privacy and application questions: jslaught@gmail.com