Privacy Policy
Ottometric Chrome Extensions Suite
Effective Date: August 3, 2026 | Version 2.6
đ Executive Summary
Ottometric's Chrome Extensions integrate your business email, calendar, meetings, and work productivity data with your company's Odoo CRM platform. Our extensions help streamline sales workflows, automate record-keeping, and provide productivity insights for internal business operations.
Key Principles: Your data is processed solely for business operations within Ottometric. We do not sell data, share with third-party advertisers, or use it for purposes unrelated to CRM and productivity management.
đ Table of Contents
- Scope and Applicability
- Extension Descriptions
- Data We Collect
- How We Use Your Data
- Data Collection Methods
- Data Storage and Retention
- Data Sharing and Third Parties
- Security Measures
- Chrome Extension Permissions
- Google API Compliance
- Your Rights and Controls
- Internal Use Policy
- Legal and Regulatory Compliance
- Contact Information
- Policy Updates
1. Scope and Applicability
This Privacy Policy governs the collection, use, storage, and disclosure of data through the following Ottometric Chrome Extensions:
Ottometric Gmail Extension (v2.5.3) â CRM integration for Gmail with email logging, tracking, and AI assistance capabilities.
Ottometric Outlook Extension â CRM integration for Outlook Web App, enabling automatic email logging and contact management.
Ottometric Meet Extension â Meeting recording and transcription for Google Meet with CRM integration.
These extensions connect to your organization's Odoo CRM instance hosted at odoo.ottometric.com.
2. Extension Descriptions
đ§ Gmail Extension
Integrates Gmail with Odoo CRM to automatically log business emails, track communication history, and provide AI-powered email assistance. The extension adds a sidebar to Gmail displaying CRM information for email contacts and allows one-click logging of emails to deals and opportunities.
Key Features: Automatic email-to-CRM logging, contact and deal matching, email open and click tracking via Odoo Marketing, reply detection and notification, AI email composition assistant (optional), and work time tracking with active/idle monitoring.
đŦ Outlook Extension
Provides similar CRM integration functionality for Outlook Web App (OWA), enabling automatic email logging and contact management for Outlook users.
đĨ Meet Extension
Enables recording, transcription, and CRM integration for Google Meet video conferences. Recordings are saved to your Google Drive and optionally linked to Odoo contacts and opportunities.
3. Data We Collect
The data we collect varies by extension. Below is a comprehensive breakdown of data types collected by each extension.
đ§ Gmail Extension
| Data Type | What We Collect | Purpose |
|---|---|---|
| Email Content | Subject lines, message bodies, draft text, attachments metadata | CRM logging, AI analysis, deal association |
| Email Metadata | From/To addresses, CC/BCC, timestamps, thread IDs, message IDs, labels | Contact matching, reply tracking, thread organization |
| Contact Information | Email addresses, display names, profile photos | CRM record matching and enrichment |
| Thread Context | Complete email conversation history | AI context analysis, reply detection |
| Work Time Data | Active vs. idle status, session timestamps | Accurate work hour calculation for productivity reporting |
| Authentication Tokens | OAuth 2.0 access tokens (Gmail API, Odoo API) | Secure API access without storing passwords |
đŦ Outlook Extension
Email content: Subject lines and message bodies for CRM logging purposes.
Email metadata: Sender information, recipients, timestamps, and conversation IDs for thread organization and tracking.
Contact information: Email addresses and display names for CRM record matching.
Authentication tokens: OAuth tokens for Microsoft Graph API and Odoo API secure access.
đĨ Meet Extension
Meeting recordings: Audio and video streams captured only when manually initiated by the user through explicit recording activation.
Meeting metadata: Meeting title, participant names and email addresses, start and end times, and meeting URL for organizational purposes.
Calendar data: Event details retrieved from Google Calendar for automatic recording file naming and organization.
Transcriptions: AI-generated meeting transcripts produced via AWS Bedrock speech-to-text processing.
Authentication tokens: OAuth tokens for secure access to Google Drive, Calendar, and Odoo APIs.
Email content may contain sensitive business information, personal identifiable information (PII), or confidential communications. We treat all collected data with appropriate security controls and access restrictions as outlined in Section 8 (Security Measures).
4. How We Use Your Data
We use collected data solely for legitimate business purposes related to customer relationship management and operational efficiency. Data is never used for advertising, marketing to external parties, or purposes unrelated to business operations.
â Permitted Uses
Data may be used for CRM record creation and updating, sales pipeline management, customer communication tracking, internal productivity analytics, email quality improvement through AI analysis, reply detection and notifications, meeting documentation, and operational reporting purposes.
â Prohibited Uses
Data will never be used for third-party advertising, selling to data brokers, training external AI models, social media integration, marketing to competitors, public data aggregation, surveillance beyond legitimate work scope, or unauthorized data mining activities.
Specific Use Cases by Extension
Gmail & Outlook Extensions:
The Gmail and Outlook extensions facilitate CRM Logging by automatically creating Odoo activity records for business emails; Contact Matching to link email addresses with existing Odoo partner records; Deal Association connecting emails to active CRM opportunities based on participants; Reply Tracking through Gmail API monitoring to detect customer responses; AI Email Assistant for analyzing draft emails regarding tone, clarity, and grammar (Gmail only, opt-in feature); Email Tracking via Odoo Email Marketing pixel and click URL generation; and Work Time Analytics calculating active work hours versus idle periods for productivity insights.
Meet Extension:
The Meet extension provides Recording Storage capabilities to save meeting recordings to your personal Google Drive; Transcription services generating searchable text transcripts using AWS Bedrock AI; CRM Integration linking meeting records to Odoo contacts and opportunities; and Meeting Documentation maintaining a searchable archive of business meetings.
5. Data Collection Methods
Data collection occurs through multiple mechanisms, both automated and user-initiated. Understanding these methods helps clarify when and how your data is accessed.
A Automatic Collection
- Email monitoring: Extensions continuously monitor your Gmail/Outlook mailbox for new sent/received emails
- Work time tracking: When connected to Odoo, the extension tracks active vs. idle status via Chrome's idle detection API
- Reply detection: Background polling checks Gmail threads every 1 minute for new replies
- Token refresh: OAuth tokens are automatically renewed before expiration
M Manual/On-Demand Collection
- Meeting recordings: Only collected when you explicitly click "Start Recording" in Google Meet
- AI email assistance: Only activated when you click the AI assistant button in Gmail compose window
- Manual email logging: When you click "Log to Odoo" button in email sidebar
API API-Based Collection
Data is accessed through official platform APIs with your explicit OAuth consent:
- Gmail API:
gmail.readonlyscope for reading email threads - Microsoft Graph API: Mail.Read scope for Outlook data
- Google Calendar API: Calendar.ReadOnly for meeting metadata
- Google Drive API: Drive.File scope (limited to files created by the extension)
Most data collection begins only after you authenticate with Odoo via the extension options page. Before authentication, the extensions remain dormant and do not access your email or other data.
6. Data Storage and Retention
6.1 Storage Locations
đĸ Odoo CRM Server
Location: odoo.ottometric.com
Data Stored:
- Email logs and content
- Contact associations
- Meeting metadata
- Work time records
- Activity timestamps
âī¸ Google Drive
Location: Your personal Google Drive
Data Stored:
- Meeting video recordings
- Meeting transcripts (text files)
- Recording metadata
đģ Local Browser Storage
Location: Chrome secure storage on your device
Data Stored:
- OAuth access tokens (encrypted)
- Extension preferences
- Temporary cache
- Tracked thread mappings
đ¤ AWS Bedrock (Temporary)
Location: Amazon Web Services AI service
Data Stored:
- Meeting audio (temporary processing only)
- Not retained after transcription
- No permanent storage
6.2 Data Retention Periods
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| CRM Logs & Emails | Indefinite (per company policy) | Admin request to IT |
| Work Time Data | Indefinite (historical reporting) | Admin request to IT |
| Meeting Recordings | Until manually deleted from Drive | User deletes from Google Drive |
| Local Settings & Tokens | Until extension uninstalled | Automatic on uninstall |
| OAuth Tokens | Until sign-out or expiration | Sign out or uninstall |
| AWS Transcription Audio | Immediately after processing | Automatic deletion |
CRM data in Odoo is retained indefinitely as part of business records for historical reporting, audit trails, and regulatory compliance. If you require data deletion, please contact your Ottometric administrator who can submit a formal data deletion request to the IT department.
7. Data Sharing and Third Parties
7.1 Parties With Data Access
â Authorized Recipients
1. Odoo CRM Server (odoo.ottometric.com)
Receives: Email content, metadata, contact info, meeting metadata, work time data
Purpose: CRM operations, business intelligence, productivity analytics
2. Google APIs
Receives: OAuth authentication requests only (no business data shared)
Purpose: User authentication and authorization
3. Microsoft Graph API (Outlook extension only)
Receives: OAuth authentication requests only
Purpose: User authentication for Outlook data access
4. AWS Bedrock (Amazon AI Services)
Receives: Meeting audio for transcription (temporary processing only)
Purpose: AI-powered speech-to-text transcription
5. Ottometric Employees & Authorized Personnel
Access Level: Based on Odoo role permissions (managers, administrators, IT staff)
Purpose: CRM management, technical support, system administration, business analytics
â Parties We DO NOT Share With
- Third-party analytics services (e.g., Google Analytics, Mixpanel)
- Advertising networks or ad tech platforms
- Data brokers or list aggregators
- Social media platforms
- Marketing automation platforms (external)
- AI training services (beyond AWS Bedrock transcription)
- Cloud storage providers (except Google Drive for recordings)
- Any external party not explicitly listed above
7.2 Legal Disclosures
We may disclose collected data if required by law, legal process, or government request, including:
- Court orders or subpoenas
- Regulatory investigations
- Law enforcement requests with proper legal authority
- Protection of legal rights, safety, or property of Ottometric or others
In such cases, we will make reasonable efforts to notify affected users unless prohibited by law.
8. Security Measures
We implement industry-standard security controls to protect collected data from unauthorized access, disclosure, alteration, or destruction.
đ Encryption
- In Transit: All data transmission uses HTTPS/TLS 1.3 encryption
- At Rest: OAuth tokens encrypted in Chrome secure storage
- API Calls: All API requests use secure HTTPS endpoints
đ Authentication
- OAuth 2.0: Industry-standard secure authentication (no passwords stored)
- Token Rotation: Automatic refresh of expired tokens
- Scope Limitation: Request minimum necessary API permissions
đĨ Access Controls
- Role-Based Access: Odoo permissions limit data visibility
- Least Privilege: Users see only data needed for their role
- Audit Logs: Odoo tracks data access and modifications
đĄī¸ Infrastructure Security
- Network Isolation: Odoo CRM on secure internal network
- Firewall Protection: Access restricted to authorized IP ranges
- Regular Updates: Security patches applied promptly
Additional Security Practices
- Minimal Permissions: Extensions request only necessary Chrome permissions for core functionality
- Secure Storage: Chrome's secure storage API protects locally stored credentials
- No Plaintext Passwords: All authentication uses OAuth tokens, never passwords
- Regular Security Reviews: Code audits and vulnerability assessments conducted periodically
- Incident Response: Documented procedures for security breach response
Users are responsible for securing their own devices, using strong passwords for Google/Microsoft accounts, and reporting suspicious activity. Do not share OAuth tokens or install extensions from untrusted sources.
9. Chrome Extension Permissions Explained
Chrome extensions require explicit permissions to access certain browser features and web APIs. Below is a detailed explanation of each permission requested by Ottometric extensions and why it's necessary.
| Permission | What It Allows | Why We Need It |
|---|---|---|
storage |
Store data locally in Chrome's secure storage | Save login credentials (OAuth tokens), user preferences, extension settings, and temporary cache |
identity |
Use Chrome Identity API for OAuth 2.0 authentication | Securely authenticate with Google/Microsoft APIs without storing passwords |
scripting |
Inject JavaScript into web pages (Gmail, Outlook) | Add CRM sidebar interface to Gmail/Outlook pages; required for InboxSDK integration |
alarms |
Schedule periodic background tasks | Periodically check for email replies, refresh OAuth tokens, poll Gmail API |
idle |
Detect when user is active, idle, or locked | Calculate accurate work hours by distinguishing active work time from idle periods for productivity analytics |
tabCapture |
Capture audio/video from browser tabs | Record Google Meet meetings (Meet extension only, user-initiated) |
desktopCapture |
Capture screen/window content | Enable screen sharing in meeting recordings (Meet extension only) |
| Host Permissions | Access specific websites and APIs |
|
We follow the principle of least privilege and request only permissions strictly necessary for core functionality. Permissions are reviewed with each extension update to ensure continued necessity.
10. Google API Services User Data Policy Compliance
Our extensions comply with the Google API Services User Data Policy, including the Limited Use requirements that restrict how we handle data obtained from Google APIs.
Limited Use Disclosure
Ottometric Chrome Extensions' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
API Scopes and Usage
đ§ Gmail API (gmail.readonly)
Scope Purpose: Monitor email threads for replies to tracked business emails
Data Accessed: Thread metadata, message headers, message bodies, attachment metadata
Usage: Auto-log business communications to Odoo CRM, detect replies, provide AI email composition assistance
Limited Use Compliance: Data used ONLY for CRM logging and email management features. Not used for:
- Advertising or targeting
- Training external AI models (beyond AWS Bedrock for transcription)
- Selling to data brokers
- Creditworthiness or lending purposes
âī¸ Google Drive API (drive.file)
Scope Purpose: Save meeting recordings created by the extension
Data Accessed: Only files created by this extension (limited scope)
Usage: Write-only access to store meeting videos and transcripts in user's personal Google Drive
đ
Google Calendar API (calendar.readonly)
Scope Purpose: Fetch meeting details for recording file naming
Data Accessed: Event titles, start/end times, participant names
Usage: Read-only access to automatically name meeting recordings with event details
Data Handling Commitments
- â Gmail data is accessed ONLY for features clearly visible to the user (email logging, AI assistant)
- â No data transfer to third parties except Odoo CRM (internal business system)
- â No use of Gmail data for serving advertisements
- â No sale or transfer of user data to data brokers or information resellers
- â Human readable data (emails, calendar events) used only for stated business purposes
- â Compliance with all other Google API Services User Data Policy requirements
11. Your Rights and Controls
You have several options to control your data and manage how the extensions function. Below are the actions you can take to exercise your rights.
11.1 Data Control Actions
đ Disable Extension
How: Navigate to chrome://extensions/, find Ottometric extension, toggle OFF or click "Remove"
Effect: Stops all data collection immediately; local data deleted
đ Disconnect from Odoo
How: Open extension options page, click "Disconnect" or "Sign Out"
Effect: Stops CRM logging and work time tracking; OAuth tokens revoked
đ Revoke OAuth Access
How: Visit Google Account Permissions or Microsoft App Permissions
Effect: Extension can no longer access Gmail/Outlook data until re-authorized
đī¸ Delete Local Data
How: Uninstall the extension completely
Effect: All browser-stored data (tokens, settings, cache) permanently deleted
đ Delete CRM Data
How: Contact your Ottometric administrator to submit data deletion request
Effect: Email logs and work time data removed from Odoo CRM
đ¤ Opt Out of AI Features
How: Simply don't click AI assistant buttons in Gmail compose window
Effect: AI analysis not performed unless explicitly requested
11.2 Data Access and Portability
As an Ottometric employee, you can access all your logged data directly in the Odoo CRM system at odoo.ottometric.com. To request a data export or deletion, contact your administrator.
Data Export Requests:
- Email your request to: admin@ottometric.com
- Include: Your name, email address, data types requested (email logs, work time data, etc.)
- Response time: 14 business days
- Format: CSV or JSON export from Odoo
12. Internal Use Policy
â ī¸ IMPORTANT: Internal Business Tools Only
These Chrome extensions are designed exclusively for use by authorized Ottometric employees and business partners as internal business productivity tools. They are NOT intended for consumer use, public distribution, or installation by the general public.
Who Should Use These Extensions:
- Current Ottometric employees with active company email accounts
- Authorized contractors or consultants with Odoo CRM access
- Business partners explicitly approved by Ottometric management
If You Are NOT an Ottometric Employee:
- â Do not install these extensions
- â Do not attempt to connect to odoo.ottometric.com
- â Do not use these extensions for personal purposes
- â Do not distribute or share these extensions publicly
Internal Data Governance
All data collected by these extensions is subject to Ottometric's internal data governance, security policies, and employee handbook provisions. By using these extensions, you acknowledge:
- Your work email communications may be logged to CRM for business purposes
- Work time data is collected for productivity reporting and operational insights
- Authorized managers and administrators can access logged data via Odoo
- Data handling complies with applicable employment laws and company policies
- Extensions are provided for business use during working hours
13. Legal and Regulatory Compliance
Ottometric Chrome Extensions are developed and operated in compliance with relevant laws, regulations, and industry standards.
â Compliance Frameworks
- â Chrome Web Store Developer Program Policies - Adheres to all Chrome extension guidelines
- â Google API Services User Data Policy - Including Limited Use requirements for Gmail/Calendar/Drive APIs
- â OAuth 2.0 Security Best Practices - Secure authentication and token management
- â Microsoft Graph API Terms of Service - Compliant use of Outlook/Office 365 data
- â Ottometric Internal Data Governance Policies - Aligns with company security and privacy standards
- â Applicable Employment Laws - Work time tracking complies with labor regulations
Privacy Regulations
While these extensions are internal business tools (not consumer-facing products), we recognize the importance of data protection principles:
- GDPR Principles: Data minimization, purpose limitation, transparency (applicable to EU employees)
- CCPA Awareness: California employees have rights to data access and deletion
- Employment Privacy: Work-related data collection disclosed to employees
Security Standards
- HTTPS/TLS 1.3 encryption for data in transit
- OAuth 2.0 secure authentication (no password storage)
- Regular security code reviews and vulnerability assessments
- Incident response procedures for security breaches
14. Contact Information
For questions, concerns, or requests related to this Privacy Policy or data handling practices, please contact:
đ§ Privacy Inquiries
Email: privacy@ottometric.com
For: Privacy policy questions, data access/deletion requests
đ ī¸ Technical Support
Email: support@ottometric.com
For: Extension issues, bugs, feature requests
đ Security Issues
Email: security@ottometric.com
For: Vulnerability reports, security incidents
đĸ General Inquiries
Email: admin@ottometric.com
For: General questions, authorization requests
Response Time: We aim to respond to all inquiries within 5 business days. For urgent security issues, contact security@ottometric.com immediately.
15. Policy Updates and Changes
We may update this Privacy Policy periodically to reflect changes in our extensions, data practices, regulatory requirements, or company policies. Material changes will be communicated to users through appropriate channels.
How We Notify Users of Changes
- Material Changes: Email notification to all active users + in-extension notification banner
- Minor Updates: Updated "Last Updated" date on this page + changelog in extension release notes
- Compliance Changes: Immediate notification if required by law or regulatory guidance
What Constitutes a Material Change
- New types of data collection (e.g., adding browsing history tracking)
- Changes to data sharing practices (e.g., new third-party recipients)
- Significant changes to data retention periods
- New purposes for using collected data
- Changes to security practices that may affect user privacy
Continued use of the extensions after a Privacy Policy update constitutes acceptance of the revised terms. If you do not agree with changes, you may discontinue use and uninstall the extension.
Version History
| Version | Date | Changes |
|---|---|---|
| 2.5 | July 30, 2026 | Added additional features like AI enhancement and analysis and much more; updated permissions section |
| 2.0 | July 21, 2026 | Major update for Gmail extension v2.5 features |
| 1.0 | January 15, 2026 | Initial policy release |
â Acknowledgment and Consent
By installing and using Ottometric Chrome Extensions, you acknowledge that you have read, understood, and agree to this Privacy Policy. You confirm that you are an authorized Ottometric employee or business partner with permission to use these internal business tools.
Last Updated: August 3, 2026 | Version: 2.6 | Effective Date: August 3, 2026
Privacy Policy
Ottometric Chrome Extensions Suite
Effective Date: August 3, 2026 | Version 2.6
đ Executive Summary
Ottometric's Chrome Extensions integrate your business email, calendar, meetings, and work productivity data with your company's Odoo CRM platform. Our extensions help streamline sales workflows, automate record-keeping, and provide productivity insights for internal business operations.
Key Principles: Your data is processed solely for business operations within Ottometric. We do not sell data, share with third-party advertisers, or use it for purposes unrelated to CRM and productivity management.
đ Table of Contents
- Scope and Applicability
- Extension Descriptions
- Data We Collect
- How We Use Your Data
- Data Collection Methods
- Data Storage and Retention
- Data Sharing and Third Parties
- Security Measures
- Chrome Extension Permissions
- Google API Compliance
- Your Rights and Controls
- Internal Use Policy
- Legal and Regulatory Compliance
- Contact Information
- Policy Updates
1. Scope and Applicability
This Privacy Policy governs the collection, use, storage, and disclosure of data through the following Ottometric Chrome Extensions:
Ottometric Gmail Extension (v2.5.3) â CRM integration for Gmail with email logging, tracking, and AI assistance capabilities.
Ottometric Outlook Extension â CRM integration for Outlook Web App, enabling automatic email logging and contact management.
Ottometric Meet Extension â Meeting recording and transcription for Google Meet with CRM integration.
These extensions connect to your organization's Odoo CRM instance hosted at odoo.ottometric.com.
2. Extension Descriptions
đ§ Gmail Extension
Integrates Gmail with Odoo CRM to automatically log business emails, track communication history, and provide AI-powered email assistance. The extension adds a sidebar to Gmail displaying CRM information for email contacts and allows one-click logging of emails to deals and opportunities.
Key Features: Automatic email-to-CRM logging, contact and deal matching, email open and click tracking via Odoo Marketing, reply detection and notification, AI email composition assistant (optional), and work time tracking with active/idle monitoring.
đŦ Outlook Extension
Provides similar CRM integration functionality for Outlook Web App (OWA), enabling automatic email logging and contact management for Outlook users.
đĨ Meet Extension
Enables recording, transcription, and CRM integration for Google Meet video conferences. Recordings are saved to your Google Drive and optionally linked to Odoo contacts and opportunities.
3. Data We Collect
The data we collect varies by extension. Below is a comprehensive breakdown of data types collected by each extension.
đ§ Gmail Extension
| Data Type | What We Collect | Purpose |
|---|---|---|
| Email Content | Subject lines, message bodies, draft text, attachments metadata | CRM logging, AI analysis, deal association |
| Email Metadata | From/To addresses, CC/BCC, timestamps, thread IDs, message IDs, labels | Contact matching, reply tracking, thread organization |
| Contact Information | Email addresses, display names, profile photos | CRM record matching and enrichment |
| Thread Context | Complete email conversation history | AI context analysis, reply detection |
| Work Time Data | Active vs. idle status, session timestamps | Accurate work hour calculation for productivity reporting |
| Authentication Tokens | OAuth 2.0 access tokens (Gmail API, Odoo API) | Secure API access without storing passwords |
đŦ Outlook Extension
Email content: Subject lines and message bodies for CRM logging purposes.
Email metadata: Sender information, recipients, timestamps, and conversation IDs for thread organization and tracking.
Contact information: Email addresses and display names for CRM record matching.
Authentication tokens: OAuth tokens for Microsoft Graph API and Odoo API secure access.
đĨ Meet Extension
Meeting recordings: Audio and video streams captured only when manually initiated by the user through explicit recording activation.
Meeting metadata: Meeting title, participant names and email addresses, start and end times, and meeting URL for organizational purposes.
Calendar data: Event details retrieved from Google Calendar for automatic recording file naming and organization.
Transcriptions: AI-generated meeting transcripts produced via AWS Bedrock speech-to-text processing.
Authentication tokens: OAuth tokens for secure access to Google Drive, Calendar, and Odoo APIs.
Email content may contain sensitive business information, personal identifiable information (PII), or confidential communications. We treat all collected data with appropriate security controls and access restrictions as outlined in Section 8 (Security Measures).
4. How We Use Your Data
We use collected data solely for legitimate business purposes related to customer relationship management and operational efficiency. Data is never used for advertising, marketing to external parties, or purposes unrelated to business operations.
â Permitted Uses
Data may be used for CRM record creation and updating, sales pipeline management, customer communication tracking, internal productivity analytics, email quality improvement through AI analysis, reply detection and notifications, meeting documentation, and operational reporting purposes.
â Prohibited Uses
Data will never be used for third-party advertising, selling to data brokers, training external AI models, social media integration, marketing to competitors, public data aggregation, surveillance beyond legitimate work scope, or unauthorized data mining activities.
Specific Use Cases by Extension
Gmail & Outlook Extensions:
The Gmail and Outlook extensions facilitate CRM Logging by automatically creating Odoo activity records for business emails; Contact Matching to link email addresses with existing Odoo partner records; Deal Association connecting emails to active CRM opportunities based on participants; Reply Tracking through Gmail API monitoring to detect customer responses; AI Email Assistant for analyzing draft emails regarding tone, clarity, and grammar (Gmail only, opt-in feature); Email Tracking via Odoo Email Marketing pixel and click URL generation; and Work Time Analytics calculating active work hours versus idle periods for productivity insights.
Meet Extension:
The Meet extension provides Recording Storage capabilities to save meeting recordings to your personal Google Drive; Transcription services generating searchable text transcripts using AWS Bedrock AI; CRM Integration linking meeting records to Odoo contacts and opportunities; and Meeting Documentation maintaining a searchable archive of business meetings.
5. Data Collection Methods
Data collection occurs through multiple mechanisms, both automated and user-initiated. Understanding these methods helps clarify when and how your data is accessed.
A Automatic Collection
- Email monitoring: Extensions continuously monitor your Gmail/Outlook mailbox for new sent/received emails
- Work time tracking: When connected to Odoo, the extension tracks active vs. idle status via Chrome's idle detection API
- Reply detection: Background polling checks Gmail threads every 1 minute for new replies
- Token refresh: OAuth tokens are automatically renewed before expiration
M Manual/On-Demand Collection
- Meeting recordings: Only collected when you explicitly click "Start Recording" in Google Meet
- AI email assistance: Only activated when you click the AI assistant button in Gmail compose window
- Manual email logging: When you click "Log to Odoo" button in email sidebar
API API-Based Collection
Data is accessed through official platform APIs with your explicit OAuth consent:
- Gmail API:
gmail.readonlyscope for reading email threads - Microsoft Graph API: Mail.Read scope for Outlook data
- Google Calendar API: Calendar.ReadOnly for meeting metadata
- Google Drive API: Drive.File scope (limited to files created by the extension)
Most data collection begins only after you authenticate with Odoo via the extension options page. Before authentication, the extensions remain dormant and do not access your email or other data.
6. Data Storage and Retention
6.1 Storage Locations
đĸ Odoo CRM Server
Location: odoo.ottometric.com
Data Stored:
- Email logs and content
- Contact associations
- Meeting metadata
- Work time records
- Activity timestamps
âī¸ Google Drive
Location: Your personal Google Drive
Data Stored:
- Meeting video recordings
- Meeting transcripts (text files)
- Recording metadata
đģ Local Browser Storage
Location: Chrome secure storage on your device
Data Stored:
- OAuth access tokens (encrypted)
- Extension preferences
- Temporary cache
- Tracked thread mappings
đ¤ AWS Bedrock (Temporary)
Location: Amazon Web Services AI service
Data Stored:
- Meeting audio (temporary processing only)
- Not retained after transcription
- No permanent storage
6.2 Data Retention Periods
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| CRM Logs & Emails | Indefinite (per company policy) | Admin request to IT |
| Work Time Data | Indefinite (historical reporting) | Admin request to IT |
| Meeting Recordings | Until manually deleted from Drive | User deletes from Google Drive |
| Local Settings & Tokens | Until extension uninstalled | Automatic on uninstall |
| OAuth Tokens | Until sign-out or expiration | Sign out or uninstall |
| AWS Transcription Audio | Immediately after processing | Automatic deletion |
CRM data in Odoo is retained indefinitely as part of business records for historical reporting, audit trails, and regulatory compliance. If you require data deletion, please contact your Ottometric administrator who can submit a formal data deletion request to the IT department.
7. Data Sharing and Third Parties
7.1 Parties With Data Access
â Authorized Recipients
1. Odoo CRM Server (odoo.ottometric.com)
Receives: Email content, metadata, contact info, meeting metadata, work time data
Purpose: CRM operations, business intelligence, productivity analytics
2. Google APIs
Receives: OAuth authentication requests only (no business data shared)
Purpose: User authentication and authorization
3. Microsoft Graph API (Outlook extension only)
Receives: OAuth authentication requests only
Purpose: User authentication for Outlook data access
4. AWS Bedrock (Amazon AI Services)
Receives: Meeting audio for transcription (temporary processing only)
Purpose: AI-powered speech-to-text transcription
5. Ottometric Employees & Authorized Personnel
Access Level: Based on Odoo role permissions (managers, administrators, IT staff)
Purpose: CRM management, technical support, system administration, business analytics
â Parties We DO NOT Share With
- Third-party analytics services (e.g., Google Analytics, Mixpanel)
- Advertising networks or ad tech platforms
- Data brokers or list aggregators
- Social media platforms
- Marketing automation platforms (external)
- AI training services (beyond AWS Bedrock transcription)
- Cloud storage providers (except Google Drive for recordings)
- Any external party not explicitly listed above
7.2 Legal Disclosures
We may disclose collected data if required by law, legal process, or government request, including:
- Court orders or subpoenas
- Regulatory investigations
- Law enforcement requests with proper legal authority
- Protection of legal rights, safety, or property of Ottometric or others
In such cases, we will make reasonable efforts to notify affected users unless prohibited by law.
8. Security Measures
We implement industry-standard security controls to protect collected data from unauthorized access, disclosure, alteration, or destruction.
đ Encryption
- In Transit: All data transmission uses HTTPS/TLS 1.3 encryption
- At Rest: OAuth tokens encrypted in Chrome secure storage
- API Calls: All API requests use secure HTTPS endpoints
đ Authentication
- OAuth 2.0: Industry-standard secure authentication (no passwords stored)
- Token Rotation: Automatic refresh of expired tokens
- Scope Limitation: Request minimum necessary API permissions
đĨ Access Controls
- Role-Based Access: Odoo permissions limit data visibility
- Least Privilege: Users see only data needed for their role
- Audit Logs: Odoo tracks data access and modifications
đĄī¸ Infrastructure Security
- Network Isolation: Odoo CRM on secure internal network
- Firewall Protection: Access restricted to authorized IP ranges
- Regular Updates: Security patches applied promptly
Additional Security Practices
- Minimal Permissions: Extensions request only necessary Chrome permissions for core functionality
- Secure Storage: Chrome's secure storage API protects locally stored credentials
- No Plaintext Passwords: All authentication uses OAuth tokens, never passwords
- Regular Security Reviews: Code audits and vulnerability assessments conducted periodically
- Incident Response: Documented procedures for security breach response
Users are responsible for securing their own devices, using strong passwords for Google/Microsoft accounts, and reporting suspicious activity. Do not share OAuth tokens or install extensions from untrusted sources.
9. Chrome Extension Permissions Explained
Chrome extensions require explicit permissions to access certain browser features and web APIs. Below is a detailed explanation of each permission requested by Ottometric extensions and why it's necessary.
| Permission | What It Allows | Why We Need It |
|---|---|---|
storage |
Store data locally in Chrome's secure storage | Save login credentials (OAuth tokens), user preferences, extension settings, and temporary cache |
identity |
Use Chrome Identity API for OAuth 2.0 authentication | Securely authenticate with Google/Microsoft APIs without storing passwords |
scripting |
Inject JavaScript into web pages (Gmail, Outlook) | Add CRM sidebar interface to Gmail/Outlook pages; required for InboxSDK integration |
alarms |
Schedule periodic background tasks | Periodically check for email replies, refresh OAuth tokens, poll Gmail API |
idle |
Detect when user is active, idle, or locked | Calculate accurate work hours by distinguishing active work time from idle periods for productivity analytics |
tabCapture |
Capture audio/video from browser tabs | Record Google Meet meetings (Meet extension only, user-initiated) |
desktopCapture |
Capture screen/window content | Enable screen sharing in meeting recordings (Meet extension only) |
| Host Permissions | Access specific websites and APIs |
|
We follow the principle of least privilege and request only permissions strictly necessary for core functionality. Permissions are reviewed with each extension update to ensure continued necessity.
10. Google API Services User Data Policy Compliance
Our extensions comply with the Google API Services User Data Policy, including the Limited Use requirements that restrict how we handle data obtained from Google APIs.
Limited Use Disclosure
Ottometric Chrome Extensions' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
API Scopes and Usage
đ§ Gmail API (gmail.readonly)
Scope Purpose: Monitor email threads for replies to tracked business emails
Data Accessed: Thread metadata, message headers, message bodies, attachment metadata
Usage: Auto-log business communications to Odoo CRM, detect replies, provide AI email composition assistance
Limited Use Compliance: Data used ONLY for CRM logging and email management features. Not used for:
- Advertising or targeting
- Training external AI models (beyond AWS Bedrock for transcription)
- Selling to data brokers
- Creditworthiness or lending purposes
âī¸ Google Drive API (drive.file)
Scope Purpose: Save meeting recordings created by the extension
Data Accessed: Only files created by this extension (limited scope)
Usage: Write-only access to store meeting videos and transcripts in user's personal Google Drive
đ
Google Calendar API (calendar.readonly)
Scope Purpose: Fetch meeting details for recording file naming
Data Accessed: Event titles, start/end times, participant names
Usage: Read-only access to automatically name meeting recordings with event details
Data Handling Commitments
- â Gmail data is accessed ONLY for features clearly visible to the user (email logging, AI assistant)
- â No data transfer to third parties except Odoo CRM (internal business system)
- â No use of Gmail data for serving advertisements
- â No sale or transfer of user data to data brokers or information resellers
- â Human readable data (emails, calendar events) used only for stated business purposes
- â Compliance with all other Google API Services User Data Policy requirements
11. Your Rights and Controls
You have several options to control your data and manage how the extensions function. Below are the actions you can take to exercise your rights.
11.1 Data Control Actions
đ Disable Extension
How: Navigate to chrome://extensions/, find Ottometric extension, toggle OFF or click "Remove"
Effect: Stops all data collection immediately; local data deleted
đ Disconnect from Odoo
How: Open extension options page, click "Disconnect" or "Sign Out"
Effect: Stops CRM logging and work time tracking; OAuth tokens revoked
đ Revoke OAuth Access
How: Visit Google Account Permissions or Microsoft App Permissions
Effect: Extension can no longer access Gmail/Outlook data until re-authorized
đī¸ Delete Local Data
How: Uninstall the extension completely
Effect: All browser-stored data (tokens, settings, cache) permanently deleted
đ Delete CRM Data
How: Contact your Ottometric administrator to submit data deletion request
Effect: Email logs and work time data removed from Odoo CRM
đ¤ Opt Out of AI Features
How: Simply don't click AI assistant buttons in Gmail compose window
Effect: AI analysis not performed unless explicitly requested
11.2 Data Access and Portability
As an Ottometric employee, you can access all your logged data directly in the Odoo CRM system at odoo.ottometric.com. To request a data export or deletion, contact your administrator.
Data Export Requests:
- Email your request to: admin@ottometric.com
- Include: Your name, email address, data types requested (email logs, work time data, etc.)
- Response time: 14 business days
- Format: CSV or JSON export from Odoo
12. Internal Use Policy
â ī¸ IMPORTANT: Internal Business Tools Only
These Chrome extensions are designed exclusively for use by authorized Ottometric employees and business partners as internal business productivity tools. They are NOT intended for consumer use, public distribution, or installation by the general public.
Who Should Use These Extensions:
- Current Ottometric employees with active company email accounts
- Authorized contractors or consultants with Odoo CRM access
- Business partners explicitly approved by Ottometric management
If You Are NOT an Ottometric Employee:
- â Do not install these extensions
- â Do not attempt to connect to odoo.ottometric.com
- â Do not use these extensions for personal purposes
- â Do not distribute or share these extensions publicly
Internal Data Governance
All data collected by these extensions is subject to Ottometric's internal data governance, security policies, and employee handbook provisions. By using these extensions, you acknowledge:
- Your work email communications may be logged to CRM for business purposes
- Work time data is collected for productivity reporting and operational insights
- Authorized managers and administrators can access logged data via Odoo
- Data handling complies with applicable employment laws and company policies
- Extensions are provided for business use during working hours
13. Legal and Regulatory Compliance
Ottometric Chrome Extensions are developed and operated in compliance with relevant laws, regulations, and industry standards.
â Compliance Frameworks
- â Chrome Web Store Developer Program Policies - Adheres to all Chrome extension guidelines
- â Google API Services User Data Policy - Including Limited Use requirements for Gmail/Calendar/Drive APIs
- â OAuth 2.0 Security Best Practices - Secure authentication and token management
- â Microsoft Graph API Terms of Service - Compliant use of Outlook/Office 365 data
- â Ottometric Internal Data Governance Policies - Aligns with company security and privacy standards
- â Applicable Employment Laws - Work time tracking complies with labor regulations
Privacy Regulations
While these extensions are internal business tools (not consumer-facing products), we recognize the importance of data protection principles:
- GDPR Principles: Data minimization, purpose limitation, transparency (applicable to EU employees)
- CCPA Awareness: California employees have rights to data access and deletion
- Employment Privacy: Work-related data collection disclosed to employees
Security Standards
- HTTPS/TLS 1.3 encryption for data in transit
- OAuth 2.0 secure authentication (no password storage)
- Regular security code reviews and vulnerability assessments
- Incident response procedures for security breaches
14. Contact Information
For questions, concerns, or requests related to this Privacy Policy or data handling practices, please contact:
đ§ Privacy Inquiries
Email: privacy@ottometric.com
For: Privacy policy questions, data access/deletion requests
đ ī¸ Technical Support
Email: support@ottometric.com
For: Extension issues, bugs, feature requests
đ Security Issues
Email: security@ottometric.com
For: Vulnerability reports, security incidents
đĸ General Inquiries
Email: admin@ottometric.com
For: General questions, authorization requests
Response Time: We aim to respond to all inquiries within 5 business days. For urgent security issues, contact security@ottometric.com immediately.
15. Policy Updates and Changes
We may update this Privacy Policy periodically to reflect changes in our extensions, data practices, regulatory requirements, or company policies. Material changes will be communicated to users through appropriate channels.
How We Notify Users of Changes
- Material Changes: Email notification to all active users + in-extension notification banner
- Minor Updates: Updated "Last Updated" date on this page + changelog in extension release notes
- Compliance Changes: Immediate notification if required by law or regulatory guidance
What Constitutes a Material Change
- New types of data collection (e.g., adding browsing history tracking)
- Changes to data sharing practices (e.g., new third-party recipients)
- Significant changes to data retention periods
- New purposes for using collected data
- Changes to security practices that may affect user privacy
Continued use of the extensions after a Privacy Policy update constitutes acceptance of the revised terms. If you do not agree with changes, you may discontinue use and uninstall the extension.
Version History
| Version | Date | Changes |
|---|---|---|
| 2.5 | July 30, 2026 | Added additional features like AI enhancement and analysis and much more; updated permissions section |
| 2.0 | July 21, 2026 | Major update for Gmail extension v2.5 features |
| 1.0 | January 15, 2026 | Initial policy release |
â Acknowledgment and Consent
By installing and using Ottometric Chrome Extensions, you acknowledge that you have read, understood, and agree to this Privacy Policy. You confirm that you are an authorized Ottometric employee or business partner with permission to use these internal business tools.
Last Updated: August 3, 2026 | Version: 2.6 | Effective Date: August 3, 2026