Strimy
FonctionnalitésFonctionnementPour quiTarifsFAQ
AccompagnementEssayer gratuitement
Mentions légalesConfidentialitéCGUConfiance

Strimy · Google & Microsoft API disclosure

Privacy Policy (English summary)

This page summarizes how Strimy handles Google (Gmail) and Microsoft (Outlook / Microsoft 365) user data for OAuth verification. The full French GDPR policy is at /confidentialite. Terms: /cgu (/terms).

1. Who we are

RETIF Benjamin, entrepreneur individuel, nom commercial Strimy Website: https://strimy.fr Support: support@strimy.fr Contact: benjamin@strimy.fr

2. Google API Services User Data Policy

Strimy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. What we request (Gmail connection)

When a paid Strimy user connects Gmail in Settings → Connections, we request only: • https://www.googleapis.com/auth/gmail.send — send prospecting emails from the user's own mailbox • https://www.googleapis.com/auth/gmail.readonly — read messages needed to detect replies and delivery failures for Strimy campaigns • https://www.googleapis.com/auth/userinfo.email — identify the connected address We do not request Google Drive, Calendar, Contacts (outside email), Docs, or full mailbox export scopes. Sign-In with Google (account creation) is separate and uses only openid / email / profile.

4. How we use Google user data

Google user data is used only to provide and improve user-facing Strimy features that are prominent in the product UI: • send outbound prospecting emails from the user's Gmail address • detect and classify campaign replies for follow-up workflows • show connection status in Settings We do not sell Google user data. We do not use it for advertising, retargeting, interest-based ads, or creditworthiness / lending.

5. Storage and security

• OAuth refresh tokens (Google and Microsoft) are encrypted at rest with AES-256-GCM before storage in our database (Supabase). Access tokens are obtained on demand and not stored long-term. • The auth_tokens table is restricted to service_role / Edge Functions (not exposed to browser clients). • Transport uses HTTPS / TLS. The site sends HSTS and a Content-Security-Policy. • Publisher domain for Microsoft Entra is verified via https://strimy.fr/.well-known/microsoft-identity-association.json • Users can disconnect mailboxes in Strimy Settings or revoke at https://myaccount.google.com/permissions or their Microsoft account / Entra portal.

5 bis. Microsoft Graph (Outlook)

When a paid Strimy user connects Outlook / Microsoft 365, the Entra app "Strimy Workspace" requests only delegated Graph permissions: • Mail.Send — send prospecting emails from the user's mailbox • Mail.Read — read messages needed to detect campaign replies • openid, profile, email, offline_access — identify the account and refresh tokens We do not request OneDrive, Teams, Calendar, or SharePoint. Microsoft mailbox data is used only for the same user-facing prospecting features as Gmail. We do not sell it or use it for advertising. Reply excerpts may be classified by Mistral AI solely for in-product follow-up UI.

6. Sharing / processors

We share Google- or Microsoft-derived mailbox data only as needed to operate the product: • Supabase — hosting and encrypted token storage • Mistral AI — only short excerpts of campaign-related replies, solely to classify reply intent for the in-product follow-up UI (not for ads, not to train unrelated models for resale) No transfer to ad platforms, data brokers, or information resellers. Human access to message content is limited to user-consented support, security investigations, legal obligations, or aggregated internal operations.

7. Full policy

Binding GDPR policy (French): https://strimy.fr/confidentialite Last updated: 21 juillet 2026

Dernière mise à jour : 21 juillet 2026

Strimy

Prospection B2B française. Des prospects à haut potentiel, une approche personnalisée et plus de clients, sans processus manuel.

benjamin@strimy.fr

Produit

  • Fonctionnalités
  • Comment ça marche
  • Pour qui
  • À propos
  • Tarifs

Ressources

  • FAQ
  • Tarifs détaillés
  • Prospection artisans
  • Prospection agences
  • Prospection cabinets
  • Accompagnement personnalisé

Légal

  • Mentions légales
  • Confidentialité
  • Privacy (EN)
  • Confiance & sécurité
  • CGU

© 2026 Strimy. Tous droits réservés.

Conçu en France · Approche RGPD-friendly