Privacy Policy
This policy is published by Levantics LLC. It covers two things: the Levantics app that asks for permission to use your Google account, and this website, levantics.io.
Levantics is a software platform for life insurance agencies and their agents. Agencies use it under their own name. Cornerstone Account, at www.cornerstoneaccount.com, is the Levantics platform under the Cornerstone name. When you connect a Google account from inside Cornerstone Account, Google shows you a permission screen for an app named Levantics. That is this app.
Everything the platform does with information that does not come from your Google account is described in the Cornerstone Account Privacy Notice. For information from your Google account, this policy is the one that applies. If the two ever differ about Google account information, this policy controls.
Information from your Google account
Connecting a Google account is optional. There are two separate connections, and you can make either one, both, or neither:
- Google Calendar, so that appointments you make in the platform appear on your Google calendar, and so that the platform knows when you are already busy.
- Gmail, so that email you send to your clients from the platform goes out from your own Gmail address.
This section describes all of the Google account information the app accesses, uses, stores, shares or deletes, and every action it takes for you.
What we ask Google for, and why
| Permission (Google scope) | Asked for when you connect | What we use it for |
|---|---|---|
| Your email address (openid, email) | Calendar or Gmail | To know which Google account you connected and show it to you in Settings. For Gmail we also read whether Google has verified the address. |
| See your calendars (https://www.googleapis.com/auth/calendar.readonly) | Calendar | To read the list of calendars in your account (each calendar's name, its identifier, and which one is your primary calendar) so that you can choose the one calendar the platform works with. |
| View and edit events (https://www.googleapis.com/auth/calendar.events) | Calendar | To read events on the calendar you chose, so the platform can mark those times as busy, and to add, change and remove the appointments you make in the platform. |
| Send email on your behalf (https://www.googleapis.com/auth/gmail.send) | Gmail | To send email from your Gmail address when you send it from the platform, or when a feature you turned on sends it for you. |
We do not ask for permission to read, search, change or delete your email, and the app cannot do any of those things. We do not ask for your contacts, your files, or anything else in your Google account. We never see or store your Google password.
Google Calendar: what we read
The platform checks the calendar you chose about every five minutes while your connection is on. The first time, it reads events from now to 90 days ahead. After that, Google sends only what changed on that calendar, and those changes can include events outside the 90 days.
For each event we use its title, start and end time, whether it is an all-day event, its status (for example, cancelled), when it was last changed, and Google's identifiers for the event. For appointments that the platform itself put on your calendar, we also read the location and description, so that an edit you make in Google carries back to the platform.
For events the platform did not create, Google's response also contains the description, the location and the guest list. The platform does not use them and does not store them.
Google Calendar: what we store
- Your connection. The email address of the connected Google account, the identifier and name of the calendar you chose, your settings for the connection, the permissions Google granted, the time of the last sync, a sync position marker from Google, and the most recent sync error, if any.
- Busy blocks. For each event on the chosen calendar that the platform did not create, we store a busy block: the event's title, start time, end time, all-day flag, Google's identifiers for the event and the calendar, and Google's version tag for the event. All-day events are skipped unless the title marks time off (for example "vacation" or "out of office"). When an event is cancelled in Google, its busy block is deleted.
- Private mode. You can turn on private mode in Settings. While it is on, the platform stores the word "Busy" in place of each event title. Private mode is off unless you turn it on. Private mode applies to events synced after you turn it on. Titles stored before then stay as they are until the event changes in Google or you ask us to delete them. The Settings screen lets only you change private mode and your chosen calendar. The underlying access rule would also allow an agency administrator to change them.
- Your platform appointments. Appointments you create in the platform are platform records. When you edit one of them in Google Calendar, the new title, time, location and description are copied back into the appointment. We also store Google's identifiers for the event, the sync status, and the text of the most recent sync error, if any.
- Your authorization. An authorization from Google (a refresh token) that lets the platform keep syncing without asking you each time. It is stored encrypted. Short-lived access tokens are used and then discarded. They are not stored.
Google Calendar: what we do for you
- When you create an appointment in the platform, we create an event on your chosen calendar with the appointment's title, time, location and notes.
- When you change that appointment in the platform, we update that event. When you cancel or delete the appointment, we delete that event.
- We do not change or delete any event that the platform did not create. We do not add guests to events.
- Busy blocks are used to show your day on your platform calendar, to warn about conflicts when an appointment is being scheduled, and to leave busy times out of the open slots offered on your booking page. The booking page offers open times only. It does not show event titles.
Gmail: what we access and store
The Gmail connection is send-only. Nothing is read from your mailbox: not your inbox, not your sent mail, not your drafts, labels or contacts.
We store:
- The email address of the connected account, the permissions Google granted, the status of the connection, and the most recent error, if any.
- A history of the connection: when it was connected, reconnected, used, and disconnected, and who did it.
- For a message sent through the connection, the fact and time that it was sent and the identifier Google gives the sent message.
- An encrypted authorization from Google (a refresh token), as with Calendar.
The text of an email you write in the platform is written in the platform. It is not obtained from Google, and it is handled under the Cornerstone Account Privacy Notice.
Gmail: what we do for you
We send an email from your Gmail address only when you send it from the platform, or when a feature that you turned on sends it for you, such as a confirmation to a client who books time with you. The message is sent by you, from your own mailbox, and it appears in your Sent folder. Replies go to you. Levantics is not the sender.
At the effective date of this policy, the only message the app sends through a connected Gmail account is a connection test, which is addressed to that same account. Sending to clients uses the same permission and follows the rules in this section.
If you do not grant the send permission on Google's screen, the app revokes whatever was granted and no connection is made.
Who can see it inside the platform
The platform is an agency's shared workspace, and some of this information is shown to other people in your agency. Please read this list before you connect.
- You.
- Your agency's administrators can see your calendar connection (the connected address, the chosen calendar's name, and its status), your busy blocks, including event titles unless private mode is on, and your appointments. They can also see your Gmail connection record and its history.
- Your upline, meaning the people above you in your agency's reporting hierarchy, can see your calendar connection, your busy blocks, including event titles unless private mode is on, and your appointments. Your upline cannot see your Gmail connection record.
- Agents who share a client record with you can see your appointments with that client.
If you do not want the titles of your personal calendar events to be visible to these people, choose a calendar that holds only work events, or turn on private mode as soon as you connect. The first sync can run within a few minutes, and titles stored before private mode is on stay stored.
Nobody in the platform can see or copy your stored Google authorization. It is not readable from the web application at all.
Who we share it with outside the platform
We share Google account information only with the service providers that run the platform for us, and only so that they can do that:
- Supabase, which hosts the platform's database, the encrypted secret storage that holds your authorization, and the server functions that talk to Google.
- Vercel, which hosts the web application, including the page Google returns you to after you approve the connection.
We do not share Google account information with anyone else. We do not sell it. We do not send it to any artificial intelligence model or AI provider.
We may disclose information where the law requires it, or where it is necessary for security purposes such as investigating abuse. If Levantics were ever part of a merger, acquisition or sale of assets, we would ask for your explicit consent before your Google account information was transferred.
What we do not do with it
We use Google account information only to provide and improve the calendar and email features described above, which you can see and control in the platform. We do not use it for anything else. In particular:
- We do not use it for advertising of any kind, including targeted, personalized, retargeted or interest-based advertising.
- We do not sell it or transfer it to advertising platforms, data brokers or information resellers.
- We do not use it to determine credit-worthiness or for lending purposes.
- We do not use it to build databases for any purpose other than providing these features to you.
- We do not use it to create, train or improve any artificial intelligence or machine learning model. Google Workspace APIs are not used to develop, improve, or train non-personalized AI or ML models.
When Levantics staff can look at it
Apart from the agency visibility described above, which is a feature of the product, Levantics personnel do not read your Google account information unless one of these is true:
- You have asked us for help and agreed, in writing, to our looking at specific information.
- It is necessary for security purposes, such as investigating a bug or abuse.
- It is necessary to comply with applicable laws or regulations.
- The information has been aggregated and anonymized and is used for internal operations.
Limited Use. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
How we protect it
- Your Google authorization is stored encrypted in Supabase Vault. The web application and the people who use it cannot read it. Only the platform's server functions can.
- Connections between your browser, the platform and Google use HTTPS.
- Access rules in the database limit each stored record to the people listed under "Who can see it inside the platform".
- The address Google returns you to carries a one-time code. The page removes it from your browser's address bar as soon as it has been used.
No system is perfectly secure. If you believe your connection has been misused, disconnect it and write to privacy@levantics.io.
How long we keep it, and how to delete it
Disconnecting. You can disconnect either connection at any time in the platform's Settings. You can also remove the app's access from your Google account at myaccount.google.com/connections. What disconnecting does:
| Removed when you disconnect in Settings | Kept after you disconnect | |
|---|---|---|
| Calendar | We ask Google to revoke the authorization. We delete our stored authorization and the connection record. Syncing stops. | Busy blocks already stored, and your platform appointments. Events the platform already put on your Google calendar stay on your Google calendar. |
| Gmail | We ask Google to revoke the authorization. We delete our stored authorization. Sending stops. | A record that the connection existed, with the email address, and the history of when it was connected, used and disconnected. |
If you remove access on Google's side instead, the platform stops being able to sync or send, but nothing is deleted from the platform: the connection record and the stored authorization, which no longer works, stay until you also disconnect in Settings or ask us to delete them.
Asking us to delete. To have stored busy blocks or other Google account information deleted, email privacy@levantics.io from the address on your platform account and tell us which Google account it concerns. We respond within 45 days. We do not apply a minimum retention period to busy blocks copied from your Google Calendar. We delete them when you ask.
What we may keep. The Gmail connection history is an audit record of who connected which mailbox and when. It holds no message content. We keep it. Your platform appointments are your agency's business records, and they are kept and deleted under the Cornerstone Account Privacy Notice. If we cannot delete something you ask us to delete, we will tell you what and why.
While connected. Busy blocks stay stored while your calendar is connected, except that a block is deleted when its event is cancelled in Google.
Changes to how we use Google account information
If we want to use Google account information in a new way or for a different purpose than this policy describes, we will tell you first and ask you to agree to the updated policy before we do. If you do not agree, the new use will not apply to your information.
This website
levantics.io is a small set of static pages. It has no accounts, no sign-in, no forms, no analytics, and it sets no cookies.
The site is hosted by Vercel. Like any web host, Vercel processes standard request logs when a page is loaded, which include your IP address, the page requested, and basic browser information. We do not use those logs to identify visitors.
If you email us, we receive your email address and whatever you write, and we use it to answer you.
The platform itself
If you use Cornerstone Account, the Cornerstone Account Privacy Notice describes the other information the platform handles, your rights, and how to exercise them. The Cornerstone Account Terms govern use of the product.
Children
The platform and this website are for adults. We do not knowingly collect information from anyone under 18.
Changes to this policy
We will post any change to this policy on this page and update the effective date. Changes to how we use Google account information follow the stricter rule above: notice and your agreement first.
Contact
Levantics LLC, 2222 W Grand River Ave, STE A, Okemos, MI 48864, United States
Privacy questions and deletion requests: privacy@levantics.io
Legal notices: legal@levantics.io