Legal and Data Protection

Privacy Policy

Last updated: 10 August 2026 · Version 1.0

This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails.

Google API Limited Use Disclosure / Google API Limited Use Disclosure

Madrugo's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Madrugo's use of data received through Google APIs strictly complies with the Google API Services User Data Policy, including the Limited Use requirements. Google data is never used for advertising, sold to third parties, or used to train general artificial intelligence models.

1. Data controller

The controller of the personal data collected on this platform is Madrugo (operated through the main domain https://madrugo.com/en).

  • Official domain: https://madrugo.com/en
  • Privacy and support contact: privacidad@madrugo.com / soporte@madrugo.com
  • Main purpose: to provide a visual personal operating system and Mission Control assistant for unified management of mail, calendar, tasks and weather.

2. Data collected and purposes of processing

Madrugo only collects the information strictly necessary to deliver the features you explicitly request, through a progressive permission model (OAuth):

Google Workspace APIs (Gmail, Calendar, Tasks, Contacts)

  • gmail.readonly: reading messages to extract pending tasks, daily summaries and events.
  • gmail.modify: archiving, moving to bin or marking mail as read on your explicit instruction.
  • gmail.send & gmail.compose: creating drafts and sending replies you have written or approved.
  • calendar.readonly & calendar.events: showing the 24-hour timeline in Mission Control and creating events and reminders.
  • tasks.readonly & tasks: two-way sync and management of pending tasks.
  • contacts.readonly, contacts.other.readonly and directory.readonly: resolving sender names and avatars.

iCloud Mail / IMAP accounts

For users who connect iCloud Mail, app-specific password credentials are stored securely, encrypted with AES-256-GCM, and used solely to connect over secure IMAP in order to aggregate messages in Mission Control.

Apple ecosystem (iPhone, Mac, Watch & Live Activities)

APNs push notification tokens and WatchConnectivity sessions are processed solely to update widgets, the Dynamic Island and the Apple Watch companion app in real time.

3. Artificial intelligence processing

Madrugo uses artificial intelligence models to analyse email, suggest replies and categorise tasks. Processing takes place through local components and the secure Sinergia gateway.

No-training guarantee:No user data (emails, events, contacts or tasks) obtained through Google APIs or Apple services is used to train, retrain or improve foundation AI models from OpenAI, Anthropic, Google or any third party. Data is processed ephemerally in memory, only for as long as your request is being executed.

4. Data security and AES-256-GCM encryption

We apply enterprise-grade technical and organisational security measures to protect information against unauthorised access, alteration or destruction:

  • Encryption at rest: all OAuth access tokens and derived memory items are encrypted at field level using AES-256-GCM with segregated cryptographic keys (MADRUGO_MEMORY_ENCRYPTION_KEY and GOOGLE_TOKEN_ENCRYPTION_KEY).
  • Secret management: protected storage in Google Cloud Secret Manager.
  • Encryption in transit: all communications over HTTPS / TLS 1.3 with HSTS enabled.
  • No unauthorised intermediary servers: communication with external APIs goes through secure, authenticated endpoints.

5. User control and erasure rights

You retain full and absolute control over your personal data at all times:

One-click immediate total wipe: in the app's settings section (/app/settings) there is an immediate purge button that deletes, in a single click, every token, memory item, sync log and associated record in the Madrugo database.
Revoking Google OAuth permissions: you can revoke the permissions granted to Madrugo at any time from your Google security panel at myaccount.google.com/permissions.
Data subject rights: you may exercise your rights of access, rectification, erasure, restriction of processing, portability and objection by sending a request to privacidad@madrugo.com.

6. Retention policy

Madrugo applies the data minimisation principle. We keep information only for as long as strictly necessary to provide the service, or until you request its erasure.

For the detailed retention schedule by data category (OAuth tokens, derived memory items, sync logs and push notification tokens), see our Data Retention and Erasure Policy.

7. Changes to this policy

We reserve the right to update this Privacy Policy to reflect legislative changes or operational improvements. Any significant change will be notified on this page and through a prominent notice in the app.