Privacy Policy

kabu-station-gmail-otp-helper-site

Effective date: 2026-05-21

Contact: harutotanaka0323@gmail.com

Overview

kabu-station-gmail-otp-helper-site is a personal local desktop helper for kabu Station login support. It uses Gmail read-only access only to find and read matching authentication emails on the user's local PC.

This tool does not make trading decisions, create orders, call broker order APIs, or submit orders.

Information Collected

The tool handles the following information only for local login support:

Gmail API Data Access

The tool uses only this Gmail API scope:

https://www.googleapis.com/auth/gmail.readonly

It reads:

The tool does not send, delete, modify, or mark Gmail messages as read.

Purpose of Use

Gmail data is used only to extract an email two-factor authentication code locally and support the kabu Station login helper flow.

Gmail data is not used for advertising, marketing, user tracking, trading decisions, model scoring, scraping, order planning, or broker API calls.

Sensitive Data Protection Mechanisms

The following security and data protection measures are used to protect Google user data and other sensitive data:

The implementation policy is to keep sensitive Gmail data local, minimize access, avoid persistent storage of email content or authentication codes, and prevent sensitive values from being written to logs or artifacts.

Data Storage

Stored:

Not stored:

No Third-Party Sharing

This tool does not sell, share, transfer, or disclose Gmail data to third parties. The current design is a personal local desktop tool and does not send Gmail data to a third-party server.

Credential Storage and Deletion

OAuth authorized user credentials JSON is stored on the user's local PC in the configured secrets directory. Default example:

C:\kabu\secrets\gmail_token.json

To delete it, close the tool and remove that local file. The OAuth grant flow can be run again later if access is needed.

Revoking Google Account Access

Users can remove this app's access from Google Account third-party access settings:

https://myaccount.google.com/permissions

Users should also delete the local OAuth credentials JSON file from their PC.

Google API Services User Data Policy

This tool is designed to comply with the Google API Services User Data Policy. Gmail data is used only for the disclosed purpose of local two-factor authentication code extraction and login support.

Gmail data is not used for advertising, is not sold to third parties, and is not intended for human review. Troubleshooting must not include email bodies, authentication codes, login information, OAuth credential content, or other sensitive values in logs or reports.