St John Automation Privacy

Last updated: September 28, 2026.

This policy describes the Gmail-connected St John Automation workflow used to prepare communications and worship materials for St. John Lutheran Church and School in Indianapolis.

Information accessed

With the account owner’s consent, Google grants the application read-only Gmail access. Although that permission allows mailbox reading, the application is configured to search for messages from with subjects beginning “St. John E-News for”. It reads the matching messages’ identifiers, sender, subject, dates, and text and HTML content. It also uses bulletin, prayer-list, and image links included in the newsletter.

The application stores Google OAuth client configuration and access and refresh tokens so that the authorized account can remain connected. It does not collect the account’s Google password.

How information is used

Matching newsletter content is used to prepare a church blog draft, prepare worship-presentation materials, identify content that needs review, and prevent duplicate processing. The application does not send, delete, label, or mark Gmail messages as read.

Storage and sharing

Captured newsletter content, working files, processing records, and Google authorization tokens are stored on the church’s Mac mini. Credential and token files use restricted filesystem permissions. Authorized operators may access working files and diagnostics while maintaining the workflow.

Prepared newsletter content is sent to Fishhook, the church’s website content-management provider, as a draft. Presentation materials are stored for use with ProPresenter. Google authorization tokens are used to communicate with Google and are not included in blog posts or presentations. Newsletter images and document links may remain hosted by the services used in the original newsletter.

The automation itself does not publish blog posts or display presentations. Authorized church operators decide whether to publish or display the resulting materials.

Limits on use

Google user data is not sold, used for advertising, or used to train generalized artificial-intelligence or machine-learning models. St John Automation’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Retention and deletion

No automatic deletion schedule is currently configured. Local working files and processing records remain until an authorized operator removes them. Drafts and published content remain in Fishhook until managed through that service. Removing local working files does not delete the original Gmail messages.

The account owner can revoke the application’s Google access through their Google Account’s third-party connections settings. Revocation stops further authorized Gmail access; it does not automatically remove previously prepared files or website drafts. Contact the operator to request removal of locally retained data or drafts.

Contact and changes

For support, access, deletion, or privacy questions, contact . This policy will be updated if the workflow’s data practices change.

Return to the St John Automation overview.