This Privacy Notice explains how VinePath, Inc. (“VinePath,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our websites, desktop applications, products, and services, including DeskPath.
DeskPath is a desktop application for professional-service users, including CPA and accounting professionals. DeskPath helps users review client emails, identify client questions, gather relevant local context, and prepare draft responses for user review and approval.
This Privacy Notice applies to:
For purposes of this Privacy Notice, “Services” means VinePath websites, DeskPath, and related services.
DeskPath is a desktop application. It connects to VinePath servers only for limited operational purposes, including app authentication, billing, license management, LLM API-key or access-token vending, and limited telemetry.
VinePath servers are not designed to receive or store Gmail message content, local client file content, LLM prompts, LLM responses, or draft response content during normal DeskPath operation.
When a user connects a Google Workspace or Gmail mailbox, DeskPath checks the connected mailbox at regular intervals for new emails.
When DeskPath detects a new email, DeskPath may send the email content, together with an instruction prompt, to a third-party large language model provider (“LLM Provider”) to determine whether the email appears to be a client question.
If the email appears to be a client question, DeskPath may use local tools on the user’s device to identify the minimum relevant information needed to prepare a response. This may include information from local files, folders, or other local data sources that the user has connected to DeskPath.
DeskPath may then send selected relevant email content, selected local context, and related instructions to an LLM Provider to generate a draft response.
When the user opens DeskPath, the user may see a draft response. The user can review, edit, approve, discard, or otherwise manage the draft.
DeskPath does not send email replies automatically. If the user chooses to send a response from DeskPath, DeskPath uses Google Workspace or Gmail to reply in the original email thread using the content the user approved.
We may collect information you provide directly to us, including:
VinePath may collect and process information needed to operate user accounts, authenticate users, manage licenses, and administer subscriptions, including:
Payment information may be processed by a third-party payment processor. VinePath does not intentionally store full payment card numbers on its own servers.
DeskPath may send limited telemetry to VinePath to help us operate, secure, troubleshoot, and improve the app.
Telemetry is designed not to include personal information, Gmail message content, email subject lines, email bodies, client names, local file contents, prompts, LLM responses, or draft response content.
Telemetry may include:
If a support issue requires review of additional information, we will ask the user to provide that information separately.
DeskPath may allow users to connect Google Workspace or Gmail accounts through Google APIs. DeskPath only accesses Google user data after the user or an authorized administrator grants permission.
Depending on the permissions granted, DeskPath may access:
DeskPath uses Gmail data only to provide user-facing DeskPath features, including:
DeskPath does not use Gmail data for advertising, retargeting, interest-based advertising, credit decisions, data brokerage, or unrelated analytics.
If the user connects local files, folders, or other local data sources to DeskPath, the desktop app may access those local sources to gather relevant information needed to prepare a response to a client question.
This may include:
DeskPath is designed to gather and use only the relevant information needed to support the draft-response workflow.
Local file and folder content is not sent to VinePath servers during normal app operation. Selected relevant local context may be sent from the DeskPath desktop app to an LLM Provider to classify emails, identify needed context, or generate draft responses.
When DeskPath uses an LLM Provider, the desktop app may send the following information to the LLM Provider:
VinePath servers do not receive or store LLM prompts, email content, local client file content, or generated draft response content during normal DeskPath operation.
VinePath may provide API-key vending, temporary access-token vending, license checks, or related access-control functions that allow the desktop app to connect to an LLM Provider.
DeskPath uses third-party LLM Providers to provide user-facing features, including email classification, context extraction, and draft-response generation.
VinePath uses LLM Providers that are contractually committed not to use DeskPath-submitted Gmail data, local client file content, prompts, or outputs to train or improve generalized artificial intelligence or machine-learning models.
LLM Providers may process DeskPath-submitted information only to provide the requested DeskPath feature, maintain security, prevent abuse, comply with law, and perform other limited processing permitted by their agreement with VinePath.
VinePath does not permit LLM Providers to sell DeskPath-submitted data, use it for advertising, use it for data brokerage, or use it to train generalized AI or machine-learning models.
Unless expressly disclosed otherwise, VinePath configures LLM Provider processing to minimize retention where commercially reasonable. Any LLM Provider retention is for limited operational, security, abuse-monitoring, or legal purposes, not for generalized model training.
We use information to:
We do not use Gmail data, local client file content, prompts, or generated draft responses for advertising or generalized AI model training.
VinePath servers are used for app authentication, billing, license management, API-key or access-token vending, and limited telemetry.
VinePath servers are not designed to receive or store:
If a user chooses to send sensitive information to VinePath for support, we may process that information only to provide support, troubleshoot issues, maintain security, comply with law, or as otherwise authorized by the user.
DeskPath shares selected information with LLM Providers to provide user-facing AI features.
This may include email content, selected email metadata, selected local file context, prompts, tool-call results, and generated draft responses.
LLM Providers process this information to classify emails, identify needed context, and generate draft responses.
VinePath requires LLM Providers not to use Gmail data, local client file content, prompts, or outputs submitted through DeskPath to train or improve generalized AI or machine-learning models.
If a user connects Gmail, DeskPath uses Google APIs to read emails and, if the user approves, send a reply in the original email thread.
DeskPath does not send replies automatically. A user must review and approve the draft before DeskPath sends the email.
We may share billing and subscription information with payment processors and billing providers to process payments, invoices, subscriptions, taxes, and related account administration.
We may share limited information with vendors that help us operate VinePath and DeskPath, such as:
These providers may process information only to provide services to VinePath or DeskPath and may not use the information for their own unrelated purposes.
We may disclose information if we believe disclosure is reasonably necessary to:
If VinePath is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to applicable law and any required consent.
For Google user data, we will handle any such transfer in accordance with the Google API Services User Data Policy and applicable consent requirements.
VinePath’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
VinePath does not:
DeskPath sends Google user data to LLM Providers only as necessary to provide user-facing DeskPath features that the user has enabled, such as determining whether an email appears to be a client question and preparing a draft response for the user to review.
DeskPath is a desktop app. Gmail data, local file context, generated drafts, local configuration, and related workflow data may be processed or stored locally on the user’s device.
The user or the user’s organization is responsible for managing the device, local files, local backups, operating-system security, and local retention settings.
Depending on product settings and implementation, DeskPath may locally store:
Users can delete local DeskPath data by using available in-app deletion features, removing connected accounts, or uninstalling the app, subject to operating-system behavior and local backups.
VinePath retains account, billing, authentication, license, telemetry, and support information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.
VinePath does not retain Gmail content, local client file content, prompts, or generated draft response content on VinePath servers during normal DeskPath operation.
LLM Providers may process information sent by the DeskPath desktop app to provide email classification, context extraction, and draft-response functionality.
VinePath requires LLM Providers not to use Gmail data or local client file content submitted through DeskPath to train generalized AI or machine-learning models.
LLM Provider retention, if any, depends on the provider and configuration used by VinePath. VinePath configures LLM processing to minimize retention where commercially reasonable.
Users may revoke DeskPath’s access to their Google account through their Google Account permissions or through DeskPath settings where available.
After access is revoked, DeskPath will stop collecting new Google user data from that account. Previously processed information may remain on the user’s device until deleted by the user through DeskPath, the operating system, or local backup management.
We use reasonable technical, administrative, and organizational safeguards designed to protect information.
These safeguards may include:
Because DeskPath is a desktop app, users and organizations are responsible for securing the devices on which DeskPath is installed. We recommend using device encryption, strong passwords, operating-system updates, endpoint protection, and appropriate access controls.
No system is perfectly secure. We cannot guarantee absolute security.
Users and organizations are responsible for:
CPA firms, accounting firms, and other professional-service firms may have special confidentiality, ethics, and client-data obligations. Those organizations are responsible for determining whether their use of DeskPath is appropriate for their professional obligations.
DeskPath may generate draft responses using an LLM Provider.
AI-generated drafts may be inaccurate, incomplete, inappropriate, or unsuitable for a specific client situation.
Users must review, edit as needed, and approve any draft before sending.
VinePath does not provide tax, accounting, legal, investment, audit, attest, or other professional advice.
When users visit VinePath websites, we may collect standard website information, such as:
We may use cookies and similar technologies to operate our website, remember preferences, understand traffic, improve our website, and support security.
Users can control cookies through browser settings. Some website features may not work properly if cookies are disabled.
We may send product updates, educational content, or marketing communications where permitted by law.
Users may opt out of marketing emails by using the unsubscribe link or contacting us. Even after opting out, users may still receive transactional or service-related messages, such as account, security, billing, or support notices.
Depending on where you live, you may have rights to:
To make a request, contact us at:
Email: privacy@vinepath.ai
We may need to verify your identity before fulfilling certain requests.
If your information is controlled by your employer or organization, we may direct your request to that organization.
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
If we learn that we have collected personal information from a child under 13 without appropriate consent, we will take steps to delete it.
VinePath is based in the United States. If you use the Services from outside the United States, your information may be processed in the United States and other countries where our service providers operate.
DeskPath integrates with third-party services, including Google Workspace, Gmail, LLM Providers, payment processors, and other tools.
Your use of third-party services may be governed by those third parties’ own terms and privacy policies.
We may update this Privacy Notice from time to time.
If we make material changes, we will provide notice as required by law, such as by updating the effective date, posting a notice on our website, or providing notice through the app.
If we materially change how DeskPath accesses, uses, stores, or shares Google user data, we will update this Privacy Notice and obtain any required consent before using Google user data for the new purpose.
Questions about this Privacy Notice may be sent to:
VinePath, Inc.
Email: privacy@vinepath.ai
Address: 16185 Los Gatos Blvd Suite 205, Los Gatos CA, 95032