DeskPath Join the waitlist
Privacy

Privacy Policy

Effective June 2026  ·  Last updated June 2026

This Privacy Notice explains how VinePath, Inc. (“VinePath,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our websites, desktop applications, products, and services, including DeskPath.

DeskPath is a desktop application for professional-service users, including CPA and accounting professionals. DeskPath helps users review client emails, identify client questions, gather relevant local context, and prepare draft responses for user review and approval.

This Privacy Notice applies to:

  • the VinePath website;
  • DeskPath desktop applications;
  • DeskPath-related websites, pages, and services;
  • VinePath authentication, billing, license-management, API-access, support, and telemetry services.

For purposes of this Privacy Notice, “Services” means VinePath websites, DeskPath, and related services.

1. Summary of how DeskPath works

DeskPath is a desktop application. It connects to VinePath servers only for limited operational purposes, including app authentication, billing, license management, LLM API-key or access-token vending, and limited telemetry.

VinePath servers are not designed to receive or store Gmail message content, local client file content, LLM prompts, LLM responses, or draft response content during normal DeskPath operation.

When a user connects a Google Workspace or Gmail mailbox, DeskPath checks the connected mailbox at regular intervals for new emails.

When DeskPath detects a new email, DeskPath may send the email content, together with an instruction prompt, to a third-party large language model provider (“LLM Provider”) to determine whether the email appears to be a client question.

If the email appears to be a client question, DeskPath may use local tools on the user’s device to identify the minimum relevant information needed to prepare a response. This may include information from local files, folders, or other local data sources that the user has connected to DeskPath.

DeskPath may then send selected relevant email content, selected local context, and related instructions to an LLM Provider to generate a draft response.

When the user opens DeskPath, the user may see a draft response. The user can review, edit, approve, discard, or otherwise manage the draft.

DeskPath does not send email replies automatically. If the user chooses to send a response from DeskPath, DeskPath uses Google Workspace or Gmail to reply in the original email thread using the content the user approved.

2. Information we collect

2.1 Information you provide to VinePath

We may collect information you provide directly to us, including:

  • name;
  • business email address;
  • company or firm name;
  • job title or role;
  • phone number;
  • login or account information;
  • billing and subscription information;
  • support requests;
  • demo requests;
  • feedback or survey responses;
  • messages you send to VinePath.

2.2 Account, authentication, billing, and license information

VinePath may collect and process information needed to operate user accounts, authenticate users, manage licenses, and administer subscriptions, including:

  • account identifiers;
  • organization or firm name;
  • user role or account permissions;
  • login and authentication events;
  • subscription status;
  • billing plan;
  • payment status;
  • device or installation identifiers;
  • license status.

Payment information may be processed by a third-party payment processor. VinePath does not intentionally store full payment card numbers on its own servers.

2.3 Desktop app telemetry

DeskPath may send limited telemetry to VinePath to help us operate, secure, troubleshoot, and improve the app.

Telemetry is designed not to include personal information, Gmail message content, email subject lines, email bodies, client names, local file contents, prompts, LLM responses, or draft response content.

Telemetry may include:

  • app version;
  • operating system;
  • device type;
  • performance information;
  • crash or error information;
  • feature usage events;
  • timing and reliability information;
  • API success or failure events;
  • token or usage counts;
  • diagnostic information needed to maintain the app.

If a support issue requires review of additional information, we will ask the user to provide that information separately.

2.4 Information from Google Workspace and Gmail

DeskPath may allow users to connect Google Workspace or Gmail accounts through Google APIs. DeskPath only accesses Google user data after the user or an authorized administrator grants permission.

Depending on the permissions granted, DeskPath may access:

  • Google account information, such as name and email address;
  • Gmail message identifiers and thread identifiers;
  • email headers and metadata, such as sender, recipient, subject line, labels, and timestamps;
  • email message content;
  • information needed to send a user-approved reply in the original email thread.

DeskPath uses Gmail data only to provide user-facing DeskPath features, including:

  • checking the connected mailbox for new emails;
  • determining whether a new email appears to be a client question;
  • identifying relevant context needed to prepare a draft response;
  • preparing a draft response for user review;
  • displaying the draft response in the desktop app;
  • sending a reply only after the user approves sending from the app;
  • maintaining local state needed for the user-facing email workflow.

DeskPath does not use Gmail data for advertising, retargeting, interest-based advertising, credit decisions, data brokerage, or unrelated analytics.

2.5 Information from local files and folders

If the user connects local files, folders, or other local data sources to DeskPath, the desktop app may access those local sources to gather relevant information needed to prepare a response to a client question.

This may include:

  • client records;
  • engagement information;
  • notes;
  • documents;
  • spreadsheets;
  • workpapers;
  • correspondence;
  • other local information the user makes available to DeskPath.

DeskPath is designed to gather and use only the relevant information needed to support the draft-response workflow.

Local file and folder content is not sent to VinePath servers during normal app operation. Selected relevant local context may be sent from the DeskPath desktop app to an LLM Provider to classify emails, identify needed context, or generate draft responses.

2.6 Prompts, LLM inputs, and LLM outputs

When DeskPath uses an LLM Provider, the desktop app may send the following information to the LLM Provider:

  • the email content being evaluated;
  • selected email metadata;
  • system instructions or prompts;
  • selected relevant information from local files, folders, or connected local data sources;
  • tool-call requests and tool-call results needed to gather local context;
  • generated draft responses.

VinePath servers do not receive or store LLM prompts, email content, local client file content, or generated draft response content during normal DeskPath operation.

VinePath may provide API-key vending, temporary access-token vending, license checks, or related access-control functions that allow the desktop app to connect to an LLM Provider.

3. LLM Provider commitments

DeskPath uses third-party LLM Providers to provide user-facing features, including email classification, context extraction, and draft-response generation.

VinePath uses LLM Providers that are contractually committed not to use DeskPath-submitted Gmail data, local client file content, prompts, or outputs to train or improve generalized artificial intelligence or machine-learning models.

LLM Providers may process DeskPath-submitted information only to provide the requested DeskPath feature, maintain security, prevent abuse, comply with law, and perform other limited processing permitted by their agreement with VinePath.

VinePath does not permit LLM Providers to sell DeskPath-submitted data, use it for advertising, use it for data brokerage, or use it to train generalized AI or machine-learning models.

Unless expressly disclosed otherwise, VinePath configures LLM Provider processing to minimize retention where commercially reasonable. Any LLM Provider retention is for limited operational, security, abuse-monitoring, or legal purposes, not for generalized model training.

4. How we use information

We use information to:

  • provide, operate, maintain, and secure DeskPath;
  • authenticate users;
  • manage subscriptions and billing;
  • issue or manage LLM API access;
  • check connected Gmail mailboxes for new messages;
  • classify whether emails appear to be client questions;
  • identify relevant local context needed to prepare draft responses;
  • generate draft responses for user review;
  • allow users to send approved replies through Gmail;
  • provide support;
  • troubleshoot errors;
  • monitor app performance and reliability;
  • prevent fraud, misuse, and abuse;
  • comply with legal obligations;
  • enforce our agreements and policies;
  • communicate with users about account, product, billing, and support matters.

We do not use Gmail data, local client file content, prompts, or generated draft responses for advertising or generalized AI model training.

5. How information is shared

5.1 VinePath servers

VinePath servers are used for app authentication, billing, license management, API-key or access-token vending, and limited telemetry.

VinePath servers are not designed to receive or store:

  • Gmail message bodies;
  • email subject lines;
  • local client file contents;
  • prompts sent to LLM Providers;
  • LLM-generated draft responses;
  • user-approved response content.

If a user chooses to send sensitive information to VinePath for support, we may process that information only to provide support, troubleshoot issues, maintain security, comply with law, or as otherwise authorized by the user.

5.2 LLM Providers

DeskPath shares selected information with LLM Providers to provide user-facing AI features.

This may include email content, selected email metadata, selected local file context, prompts, tool-call results, and generated draft responses.

LLM Providers process this information to classify emails, identify needed context, and generate draft responses.

VinePath requires LLM Providers not to use Gmail data, local client file content, prompts, or outputs submitted through DeskPath to train or improve generalized AI or machine-learning models.

5.3 Google Workspace and Gmail

If a user connects Gmail, DeskPath uses Google APIs to read emails and, if the user approves, send a reply in the original email thread.

DeskPath does not send replies automatically. A user must review and approve the draft before DeskPath sends the email.

5.4 Payment processors and billing providers

We may share billing and subscription information with payment processors and billing providers to process payments, invoices, subscriptions, taxes, and related account administration.

5.5 Service providers

We may share limited information with vendors that help us operate VinePath and DeskPath, such as:

  • authentication providers;
  • hosting providers for VinePath account services;
  • billing providers;
  • customer support tools;
  • telemetry infrastructure;
  • security and monitoring providers;
  • LLM Providers.

These providers may process information only to provide services to VinePath or DeskPath and may not use the information for their own unrelated purposes.

5.6 Legal and safety reasons

We may disclose information if we believe disclosure is reasonably necessary to:

  • comply with law, regulation, legal process, or governmental request;
  • protect the rights, property, or safety of VinePath, users, customers, or others;
  • investigate fraud, abuse, security incidents, or technical issues;
  • enforce our agreements and policies.

5.7 Business transfers

If VinePath is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and any required consent.

For Google user data, we will handle any such transfer in accordance with the Google API Services User Data Policy and applicable consent requirements.

6. Google API Limited Use disclosure

VinePath’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

VinePath does not:

  • sell Google user data;
  • use Google user data for advertising;
  • use Google user data for retargeting, personalized ads, or interest-based advertising;
  • transfer Google user data to advertising platforms, data brokers, or information resellers;
  • use Google user data to determine creditworthiness or for lending purposes;
  • use Google user data to train, improve, or develop generalized artificial intelligence or machine-learning models;
  • permit LLM Providers or other service providers to use Google user data submitted through DeskPath to train, improve, or develop generalized artificial intelligence or machine-learning models;
  • allow humans to read Google user data except with the user’s explicit consent, where necessary for security or abuse investigation, where required by law, or where data is aggregated and anonymized for internal operations;
  • access Google user data for surveillance or for purposes unrelated to DeskPath’s user-facing email workflow.

DeskPath sends Google user data to LLM Providers only as necessary to provide user-facing DeskPath features that the user has enabled, such as determining whether an email appears to be a client question and preparing a draft response for the user to review.

7. Data storage and retention

7.1 Local storage on the user’s device

DeskPath is a desktop app. Gmail data, local file context, generated drafts, local configuration, and related workflow data may be processed or stored locally on the user’s device.

The user or the user’s organization is responsible for managing the device, local files, local backups, operating-system security, and local retention settings.

Depending on product settings and implementation, DeskPath may locally store:

  • OAuth tokens or connection credentials;
  • mailbox processing state;
  • email IDs or thread IDs;
  • local indexes or caches;
  • generated draft responses;
  • user settings;
  • connected-folder configuration;
  • app logs that are designed not to include sensitive content.

Users can delete local DeskPath data by using available in-app deletion features, removing connected accounts, or uninstalling the app, subject to operating-system behavior and local backups.

7.2 VinePath server retention

VinePath retains account, billing, authentication, license, telemetry, and support information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.

VinePath does not retain Gmail content, local client file content, prompts, or generated draft response content on VinePath servers during normal DeskPath operation.

7.3 LLM Provider retention

LLM Providers may process information sent by the DeskPath desktop app to provide email classification, context extraction, and draft-response functionality.

VinePath requires LLM Providers not to use Gmail data or local client file content submitted through DeskPath to train generalized AI or machine-learning models.

LLM Provider retention, if any, depends on the provider and configuration used by VinePath. VinePath configures LLM processing to minimize retention where commercially reasonable.

7.4 Revoking Google access

Users may revoke DeskPath’s access to their Google account through their Google Account permissions or through DeskPath settings where available.

After access is revoked, DeskPath will stop collecting new Google user data from that account. Previously processed information may remain on the user’s device until deleted by the user through DeskPath, the operating system, or local backup management.

8. Data security

We use reasonable technical, administrative, and organizational safeguards designed to protect information.

These safeguards may include:

  • encrypted connections when transmitting data to Google, VinePath servers, LLM Providers, and other service providers;
  • account authentication;
  • access controls;
  • limited telemetry collection;
  • separation between VinePath server functions and local Gmail/content processing;
  • vendor review;
  • security monitoring;
  • internal confidentiality obligations.

Because DeskPath is a desktop app, users and organizations are responsible for securing the devices on which DeskPath is installed. We recommend using device encryption, strong passwords, operating-system updates, endpoint protection, and appropriate access controls.

No system is perfectly secure. We cannot guarantee absolute security.

9. User and customer responsibilities

Users and organizations are responsible for:

  • ensuring they have the right to connect Gmail accounts to DeskPath;
  • ensuring they have the right to process email content and local client information through DeskPath;
  • obtaining any required client, employee, contractor, or third-party consents;
  • complying with professional obligations, including confidentiality obligations;
  • reviewing all AI-generated drafts before sending;
  • deciding whether a response is accurate, complete, appropriate, and ready to send;
  • securing local devices and local files;
  • managing local data retention and deletion.

CPA firms, accounting firms, and other professional-service firms may have special confidentiality, ethics, and client-data obligations. Those organizations are responsible for determining whether their use of DeskPath is appropriate for their professional obligations.

10. AI-generated drafts

DeskPath may generate draft responses using an LLM Provider.

AI-generated drafts may be inaccurate, incomplete, inappropriate, or unsuitable for a specific client situation.

Users must review, edit as needed, and approve any draft before sending.

VinePath does not provide tax, accounting, legal, investment, audit, attest, or other professional advice.

11. Cookies and website data

When users visit VinePath websites, we may collect standard website information, such as:

  • IP address;
  • browser type;
  • device type;
  • referring URL;
  • pages viewed;
  • approximate location based on IP address;
  • cookie identifiers;
  • website analytics events.

We may use cookies and similar technologies to operate our website, remember preferences, understand traffic, improve our website, and support security.

Users can control cookies through browser settings. Some website features may not work properly if cookies are disabled.

12. Marketing communications

We may send product updates, educational content, or marketing communications where permitted by law.

Users may opt out of marketing emails by using the unsubscribe link or contacting us. Even after opting out, users may still receive transactional or service-related messages, such as account, security, billing, or support notices.

13. Your choices and rights

Depending on where you live, you may have rights to:

  • access personal information;
  • correct personal information;
  • delete personal information;
  • object to or restrict certain processing;
  • request portability of personal information;
  • opt out of certain marketing communications;
  • withdraw consent where processing is based on consent.

To make a request, contact us at:

Email: privacy@vinepath.ai

We may need to verify your identity before fulfilling certain requests.

If your information is controlled by your employer or organization, we may direct your request to that organization.

14. Children’s privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

If we learn that we have collected personal information from a child under 13 without appropriate consent, we will take steps to delete it.

15. International users

VinePath is based in the United States. If you use the Services from outside the United States, your information may be processed in the United States and other countries where our service providers operate.

16. Third-party services

DeskPath integrates with third-party services, including Google Workspace, Gmail, LLM Providers, payment processors, and other tools.

Your use of third-party services may be governed by those third parties’ own terms and privacy policies.

17. Changes to this Privacy Notice

We may update this Privacy Notice from time to time.

If we make material changes, we will provide notice as required by law, such as by updating the effective date, posting a notice on our website, or providing notice through the app.

If we materially change how DeskPath accesses, uses, stores, or shares Google user data, we will update this Privacy Notice and obtain any required consent before using Google user data for the new purpose.

18. Contact us

Questions about this Privacy Notice may be sent to:

VinePath, Inc.
Email: privacy@vinepath.ai
Address: 16185 Los Gatos Blvd Suite 205, Los Gatos CA, 95032