Skip to Content

Privacy Policy

Ottometric Chrome Extensions Suite

Effective Date: August 3, 2026 | Version 2.6

📋 Executive Summary

Ottometric's Chrome Extensions integrate your business email, calendar, meetings, and work productivity data with your company's Odoo CRM platform. Our extensions help streamline sales workflows, automate record-keeping, and provide productivity insights for internal business operations.

Key Principles: Your data is processed solely for business operations within Ottometric. We do not sell data, share with third-party advertisers, or use it for purposes unrelated to CRM and productivity management.

1. Scope and Applicability

This Privacy Policy governs the collection, use, storage, and disclosure of data through the following Ottometric Chrome Extensions:

Ottometric Gmail Extension (v2.5.3) — CRM integration for Gmail with email logging, tracking, and AI assistance capabilities.

Ottometric Outlook Extension — CRM integration for Outlook Web App, enabling automatic email logging and contact management.

Ottometric Meet Extension — Meeting recording and transcription for Google Meet with CRM integration.

These extensions connect to your organization's Odoo CRM instance hosted at odoo.ottometric.com.

🔒 Important: These extensions are designed exclusively for use by authorized Ottometric employees and business partners. They are not consumer-facing products and should only be installed by individuals with explicit authorization from Ottometric management.

2. Extension Descriptions

📧 Gmail Extension

Integrates Gmail with Odoo CRM to automatically log business emails, track communication history, and provide AI-powered email assistance. The extension adds a sidebar to Gmail displaying CRM information for email contacts and allows one-click logging of emails to deals and opportunities.

Key Features: Automatic email-to-CRM logging, contact and deal matching, email open and click tracking via Odoo Marketing, reply detection and notification, AI email composition assistant (optional), and work time tracking with active/idle monitoring.

đŸ“Ŧ Outlook Extension

Provides similar CRM integration functionality for Outlook Web App (OWA), enabling automatic email logging and contact management for Outlook users.

đŸŽĨ Meet Extension

Enables recording, transcription, and CRM integration for Google Meet video conferences. Recordings are saved to your Google Drive and optionally linked to Odoo contacts and opportunities.

3. Data We Collect

The data we collect varies by extension. Below is a comprehensive breakdown of data types collected by each extension.

📧 Gmail Extension

Data Type What We Collect Purpose
Email Content Subject lines, message bodies, draft text, attachments metadata CRM logging, AI analysis, deal association
Email Metadata From/To addresses, CC/BCC, timestamps, thread IDs, message IDs, labels Contact matching, reply tracking, thread organization
Contact Information Email addresses, display names, profile photos CRM record matching and enrichment
Thread Context Complete email conversation history AI context analysis, reply detection
Work Time Data Active vs. idle status, session timestamps Accurate work hour calculation for productivity reporting
Authentication Tokens OAuth 2.0 access tokens (Gmail API, Odoo API) Secure API access without storing passwords

đŸ“Ŧ Outlook Extension

Email content: Subject lines and message bodies for CRM logging purposes.

Email metadata: Sender information, recipients, timestamps, and conversation IDs for thread organization and tracking.

Contact information: Email addresses and display names for CRM record matching.

Authentication tokens: OAuth tokens for Microsoft Graph API and Odoo API secure access.

đŸŽĨ Meet Extension

Meeting recordings: Audio and video streams captured only when manually initiated by the user through explicit recording activation.

Meeting metadata: Meeting title, participant names and email addresses, start and end times, and meeting URL for organizational purposes.

Calendar data: Event details retrieved from Google Calendar for automatic recording file naming and organization.

Transcriptions: AI-generated meeting transcripts produced via AWS Bedrock speech-to-text processing.

Authentication tokens: OAuth tokens for secure access to Google Drive, Calendar, and Odoo APIs.

âš ī¸ Sensitive Data Notice:

Email content may contain sensitive business information, personal identifiable information (PII), or confidential communications. We treat all collected data with appropriate security controls and access restrictions as outlined in Section 8 (Security Measures).

4. How We Use Your Data

We use collected data solely for legitimate business purposes related to customer relationship management and operational efficiency. Data is never used for advertising, marketing to external parties, or purposes unrelated to business operations.

✅ Permitted Uses

Data may be used for CRM record creation and updating, sales pipeline management, customer communication tracking, internal productivity analytics, email quality improvement through AI analysis, reply detection and notifications, meeting documentation, and operational reporting purposes.

❌ Prohibited Uses

Data will never be used for third-party advertising, selling to data brokers, training external AI models, social media integration, marketing to competitors, public data aggregation, surveillance beyond legitimate work scope, or unauthorized data mining activities.

Specific Use Cases by Extension

Gmail & Outlook Extensions:

The Gmail and Outlook extensions facilitate CRM Logging by automatically creating Odoo activity records for business emails; Contact Matching to link email addresses with existing Odoo partner records; Deal Association connecting emails to active CRM opportunities based on participants; Reply Tracking through Gmail API monitoring to detect customer responses; AI Email Assistant for analyzing draft emails regarding tone, clarity, and grammar (Gmail only, opt-in feature); Email Tracking via Odoo Email Marketing pixel and click URL generation; and Work Time Analytics calculating active work hours versus idle periods for productivity insights.

Meet Extension:

The Meet extension provides Recording Storage capabilities to save meeting recordings to your personal Google Drive; Transcription services generating searchable text transcripts using AWS Bedrock AI; CRM Integration linking meeting records to Odoo contacts and opportunities; and Meeting Documentation maintaining a searchable archive of business meetings.

5. Data Collection Methods

Data collection occurs through multiple mechanisms, both automated and user-initiated. Understanding these methods helps clarify when and how your data is accessed.

A Automatic Collection

  • Email monitoring: Extensions continuously monitor your Gmail/Outlook mailbox for new sent/received emails
  • Work time tracking: When connected to Odoo, the extension tracks active vs. idle status via Chrome's idle detection API
  • Reply detection: Background polling checks Gmail threads every 1 minute for new replies
  • Token refresh: OAuth tokens are automatically renewed before expiration

M Manual/On-Demand Collection

  • Meeting recordings: Only collected when you explicitly click "Start Recording" in Google Meet
  • AI email assistance: Only activated when you click the AI assistant button in Gmail compose window
  • Manual email logging: When you click "Log to Odoo" button in email sidebar

API API-Based Collection

Data is accessed through official platform APIs with your explicit OAuth consent:

  • Gmail API: gmail.readonly scope for reading email threads
  • Microsoft Graph API: Mail.Read scope for Outlook data
  • Google Calendar API: Calendar.ReadOnly for meeting metadata
  • Google Drive API: Drive.File scope (limited to files created by the extension)
â„šī¸ Collection Trigger:

Most data collection begins only after you authenticate with Odoo via the extension options page. Before authentication, the extensions remain dormant and do not access your email or other data.

6. Data Storage and Retention

6.1 Storage Locations

đŸĸ Odoo CRM Server

Location: odoo.ottometric.com

Data Stored:

  • Email logs and content
  • Contact associations
  • Meeting metadata
  • Work time records
  • Activity timestamps

â˜ī¸ Google Drive

Location: Your personal Google Drive

Data Stored:

  • Meeting video recordings
  • Meeting transcripts (text files)
  • Recording metadata

đŸ’ģ Local Browser Storage

Location: Chrome secure storage on your device

Data Stored:

  • OAuth access tokens (encrypted)
  • Extension preferences
  • Temporary cache
  • Tracked thread mappings

🤖 AWS Bedrock (Temporary)

Location: Amazon Web Services AI service

Data Stored:

  • Meeting audio (temporary processing only)
  • Not retained after transcription
  • No permanent storage

6.2 Data Retention Periods

Data Category Retention Period Deletion Method
CRM Logs & Emails Indefinite (per company policy) Admin request to IT
Work Time Data Indefinite (historical reporting) Admin request to IT
Meeting Recordings Until manually deleted from Drive User deletes from Google Drive
Local Settings & Tokens Until extension uninstalled Automatic on uninstall
OAuth Tokens Until sign-out or expiration Sign out or uninstall
AWS Transcription Audio Immediately after processing Automatic deletion
📝 Data Retention Notice:

CRM data in Odoo is retained indefinitely as part of business records for historical reporting, audit trails, and regulatory compliance. If you require data deletion, please contact your Ottometric administrator who can submit a formal data deletion request to the IT department.

7. Data Sharing and Third Parties

7.1 Parties With Data Access

✅ Authorized Recipients

1. Odoo CRM Server (odoo.ottometric.com)

Receives: Email content, metadata, contact info, meeting metadata, work time data

Purpose: CRM operations, business intelligence, productivity analytics

2. Google APIs

Receives: OAuth authentication requests only (no business data shared)

Purpose: User authentication and authorization

3. Microsoft Graph API (Outlook extension only)

Receives: OAuth authentication requests only

Purpose: User authentication for Outlook data access

4. AWS Bedrock (Amazon AI Services)

Receives: Meeting audio for transcription (temporary processing only)

Purpose: AI-powered speech-to-text transcription

5. Ottometric Employees & Authorized Personnel

Access Level: Based on Odoo role permissions (managers, administrators, IT staff)

Purpose: CRM management, technical support, system administration, business analytics

❌ Parties We DO NOT Share With

  • Third-party analytics services (e.g., Google Analytics, Mixpanel)
  • Advertising networks or ad tech platforms
  • Data brokers or list aggregators
  • Social media platforms
  • Marketing automation platforms (external)
  • AI training services (beyond AWS Bedrock transcription)
  • Cloud storage providers (except Google Drive for recordings)
  • Any external party not explicitly listed above

7.2 Legal Disclosures

We may disclose collected data if required by law, legal process, or government request, including:

  • Court orders or subpoenas
  • Regulatory investigations
  • Law enforcement requests with proper legal authority
  • Protection of legal rights, safety, or property of Ottometric or others

In such cases, we will make reasonable efforts to notify affected users unless prohibited by law.

8. Security Measures

We implement industry-standard security controls to protect collected data from unauthorized access, disclosure, alteration, or destruction.

🔒 Encryption

  • In Transit: All data transmission uses HTTPS/TLS 1.3 encryption
  • At Rest: OAuth tokens encrypted in Chrome secure storage
  • API Calls: All API requests use secure HTTPS endpoints

🔑 Authentication

  • OAuth 2.0: Industry-standard secure authentication (no passwords stored)
  • Token Rotation: Automatic refresh of expired tokens
  • Scope Limitation: Request minimum necessary API permissions

đŸ‘Ĩ Access Controls

  • Role-Based Access: Odoo permissions limit data visibility
  • Least Privilege: Users see only data needed for their role
  • Audit Logs: Odoo tracks data access and modifications

đŸ›Ąī¸ Infrastructure Security

  • Network Isolation: Odoo CRM on secure internal network
  • Firewall Protection: Access restricted to authorized IP ranges
  • Regular Updates: Security patches applied promptly

Additional Security Practices

  • Minimal Permissions: Extensions request only necessary Chrome permissions for core functionality
  • Secure Storage: Chrome's secure storage API protects locally stored credentials
  • No Plaintext Passwords: All authentication uses OAuth tokens, never passwords
  • Regular Security Reviews: Code audits and vulnerability assessments conducted periodically
  • Incident Response: Documented procedures for security breach response
âš ī¸ User Responsibility:

Users are responsible for securing their own devices, using strong passwords for Google/Microsoft accounts, and reporting suspicious activity. Do not share OAuth tokens or install extensions from untrusted sources.

9. Chrome Extension Permissions Explained

Chrome extensions require explicit permissions to access certain browser features and web APIs. Below is a detailed explanation of each permission requested by Ottometric extensions and why it's necessary.

Permission What It Allows Why We Need It
storage Store data locally in Chrome's secure storage Save login credentials (OAuth tokens), user preferences, extension settings, and temporary cache
identity Use Chrome Identity API for OAuth 2.0 authentication Securely authenticate with Google/Microsoft APIs without storing passwords
scripting Inject JavaScript into web pages (Gmail, Outlook) Add CRM sidebar interface to Gmail/Outlook pages; required for InboxSDK integration
alarms Schedule periodic background tasks Periodically check for email replies, refresh OAuth tokens, poll Gmail API
idle Detect when user is active, idle, or locked Calculate accurate work hours by distinguishing active work time from idle periods for productivity analytics
tabCapture Capture audio/video from browser tabs Record Google Meet meetings (Meet extension only, user-initiated)
desktopCapture Capture screen/window content Enable screen sharing in meeting recordings (Meet extension only)
Host Permissions Access specific websites and APIs
  • â€ĸ mail.google.com - Gmail access
  • â€ĸ outlook.office.com - Outlook access
  • â€ĸ meet.google.com - Meet recording
  • â€ĸ odoo.ottometric.com - Odoo CRM API
  • â€ĸ googleapis.com - Google API calls
  • â€ĸ graph.microsoft.com - Microsoft API
  • â€ĸ amazonaws.com - AWS transcription
✅ Minimal Permissions Policy:

We follow the principle of least privilege and request only permissions strictly necessary for core functionality. Permissions are reviewed with each extension update to ensure continued necessity.

10. Google API Services User Data Policy Compliance

Our extensions comply with the Google API Services User Data Policy, including the Limited Use requirements that restrict how we handle data obtained from Google APIs.

Limited Use Disclosure

Ottometric Chrome Extensions' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

API Scopes and Usage

📧 Gmail API (gmail.readonly)

Scope Purpose: Monitor email threads for replies to tracked business emails

Data Accessed: Thread metadata, message headers, message bodies, attachment metadata

Usage: Auto-log business communications to Odoo CRM, detect replies, provide AI email composition assistance

Limited Use Compliance: Data used ONLY for CRM logging and email management features. Not used for:

  • Advertising or targeting
  • Training external AI models (beyond AWS Bedrock for transcription)
  • Selling to data brokers
  • Creditworthiness or lending purposes

â˜ī¸ Google Drive API (drive.file)

Scope Purpose: Save meeting recordings created by the extension

Data Accessed: Only files created by this extension (limited scope)

Usage: Write-only access to store meeting videos and transcripts in user's personal Google Drive

📅 Google Calendar API (calendar.readonly)

Scope Purpose: Fetch meeting details for recording file naming

Data Accessed: Event titles, start/end times, participant names

Usage: Read-only access to automatically name meeting recordings with event details

Data Handling Commitments

  • ✅ Gmail data is accessed ONLY for features clearly visible to the user (email logging, AI assistant)
  • ✅ No data transfer to third parties except Odoo CRM (internal business system)
  • ✅ No use of Gmail data for serving advertisements
  • ✅ No sale or transfer of user data to data brokers or information resellers
  • ✅ Human readable data (emails, calendar events) used only for stated business purposes
  • ✅ Compliance with all other Google API Services User Data Policy requirements

11. Your Rights and Controls

You have several options to control your data and manage how the extensions function. Below are the actions you can take to exercise your rights.

11.1 Data Control Actions

🔌 Disable Extension

How: Navigate to chrome://extensions/, find Ottometric extension, toggle OFF or click "Remove"

Effect: Stops all data collection immediately; local data deleted

🔓 Disconnect from Odoo

How: Open extension options page, click "Disconnect" or "Sign Out"

Effect: Stops CRM logging and work time tracking; OAuth tokens revoked

🔑 Revoke OAuth Access

How: Visit Google Account Permissions or Microsoft App Permissions

Effect: Extension can no longer access Gmail/Outlook data until re-authorized

đŸ—‘ī¸ Delete Local Data

How: Uninstall the extension completely

Effect: All browser-stored data (tokens, settings, cache) permanently deleted

📂 Delete CRM Data

How: Contact your Ottometric administrator to submit data deletion request

Effect: Email logs and work time data removed from Odoo CRM

🤖 Opt Out of AI Features

How: Simply don't click AI assistant buttons in Gmail compose window

Effect: AI analysis not performed unless explicitly requested

11.2 Data Access and Portability

As an Ottometric employee, you can access all your logged data directly in the Odoo CRM system at odoo.ottometric.com. To request a data export or deletion, contact your administrator.

Data Export Requests:

  1. Email your request to: admin@ottometric.com
  2. Include: Your name, email address, data types requested (email logs, work time data, etc.)
  3. Response time: 14 business days
  4. Format: CSV or JSON export from Odoo

12. Internal Use Policy

âš ī¸ IMPORTANT: Internal Business Tools Only

These Chrome extensions are designed exclusively for use by authorized Ottometric employees and business partners as internal business productivity tools. They are NOT intended for consumer use, public distribution, or installation by the general public.

Who Should Use These Extensions:

  • Current Ottometric employees with active company email accounts
  • Authorized contractors or consultants with Odoo CRM access
  • Business partners explicitly approved by Ottometric management

If You Are NOT an Ottometric Employee:

  • ❌ Do not install these extensions
  • ❌ Do not attempt to connect to odoo.ottometric.com
  • ❌ Do not use these extensions for personal purposes
  • ❌ Do not distribute or share these extensions publicly

Internal Data Governance

All data collected by these extensions is subject to Ottometric's internal data governance, security policies, and employee handbook provisions. By using these extensions, you acknowledge:

  • Your work email communications may be logged to CRM for business purposes
  • Work time data is collected for productivity reporting and operational insights
  • Authorized managers and administrators can access logged data via Odoo
  • Data handling complies with applicable employment laws and company policies
  • Extensions are provided for business use during working hours

13. Legal and Regulatory Compliance

Ottometric Chrome Extensions are developed and operated in compliance with relevant laws, regulations, and industry standards.

✅ Compliance Frameworks

  • ✅ Chrome Web Store Developer Program Policies - Adheres to all Chrome extension guidelines
  • ✅ Google API Services User Data Policy - Including Limited Use requirements for Gmail/Calendar/Drive APIs
  • ✅ OAuth 2.0 Security Best Practices - Secure authentication and token management
  • ✅ Microsoft Graph API Terms of Service - Compliant use of Outlook/Office 365 data
  • ✅ Ottometric Internal Data Governance Policies - Aligns with company security and privacy standards
  • ✅ Applicable Employment Laws - Work time tracking complies with labor regulations

Privacy Regulations

While these extensions are internal business tools (not consumer-facing products), we recognize the importance of data protection principles:

  • GDPR Principles: Data minimization, purpose limitation, transparency (applicable to EU employees)
  • CCPA Awareness: California employees have rights to data access and deletion
  • Employment Privacy: Work-related data collection disclosed to employees

Security Standards

  • HTTPS/TLS 1.3 encryption for data in transit
  • OAuth 2.0 secure authentication (no password storage)
  • Regular security code reviews and vulnerability assessments
  • Incident response procedures for security breaches

14. Contact Information

For questions, concerns, or requests related to this Privacy Policy or data handling practices, please contact:

📧 Privacy Inquiries

Email: privacy@ottometric.com
For: Privacy policy questions, data access/deletion requests

đŸ› ī¸ Technical Support

Email: support@ottometric.com
For: Extension issues, bugs, feature requests

🔒 Security Issues

Email: security@ottometric.com
For: Vulnerability reports, security incidents

đŸĸ General Inquiries

Email: admin@ottometric.com
For: General questions, authorization requests

Response Time: We aim to respond to all inquiries within 5 business days. For urgent security issues, contact security@ottometric.com immediately.

15. Policy Updates and Changes

We may update this Privacy Policy periodically to reflect changes in our extensions, data practices, regulatory requirements, or company policies. Material changes will be communicated to users through appropriate channels.

How We Notify Users of Changes

  • Material Changes: Email notification to all active users + in-extension notification banner
  • Minor Updates: Updated "Last Updated" date on this page + changelog in extension release notes
  • Compliance Changes: Immediate notification if required by law or regulatory guidance

What Constitutes a Material Change

  • New types of data collection (e.g., adding browsing history tracking)
  • Changes to data sharing practices (e.g., new third-party recipients)
  • Significant changes to data retention periods
  • New purposes for using collected data
  • Changes to security practices that may affect user privacy
📌 Your Continued Use:

Continued use of the extensions after a Privacy Policy update constitutes acceptance of the revised terms. If you do not agree with changes, you may discontinue use and uninstall the extension.

Version History

Version Date Changes
2.5 July 30, 2026 Added additional features like AI enhancement and analysis and much more; updated permissions section
2.0 July 21, 2026 Major update for Gmail extension v2.5 features
1.0 January 15, 2026 Initial policy release

✅ Acknowledgment and Consent

By installing and using Ottometric Chrome Extensions, you acknowledge that you have read, understood, and agree to this Privacy Policy. You confirm that you are an authorized Ottometric employee or business partner with permission to use these internal business tools.

Last Updated: August 3, 2026 | Version: 2.6 | Effective Date: August 3, 2026