Privacy Policy
Effective date: August 27, 2026 · Version 1.1
This Privacy Policy explains how OhMyLabs LLC handles personal data in connection with Bekap, our email backup and recovery platform for Google Workspace. It is written for the businesses that subscribe to Bekap, for the people who use it, and for the individuals whose mailboxes those businesses back up.
1. Who we are
OhMyLabs LLC is a limited liability company organized under the laws of the State of Wyoming, United States, with its registered address at 75 E 3rd St, Sheridan, WY 82801, EIN 32-0850248 ("we", "us", "our"). We operate the Bekap platform ("Bekap" or the "Service").
Bekap is supplied to businesses. It is not offered to consumers, and we do not knowingly collect personal data directly from members of the public.
2. The two roles we play, and why the distinction matters
We handle two different categories of personal data, under two different legal roles.
As a controller, we decide how and why we process the personal data of the people who administer and use Bekap on behalf of a subscribing business: account holders, invited users, billing contacts and prospective customers. Sections 4, 7 and 8 describe that processing.
As a processor, we handle the personal data contained in a customer's mailboxes and in the backup index that describes them. We do so only on the instructions of the subscribing business, which is the controller of that data. Section 5 describes that processing. If your employer or a managed service provider backs up your mailbox using Bekap, that organization, not us, decides that your mailbox is backed up, for how long, and to where. Please direct requests about that data to them in the first instance.
Where a managed service provider ("MSP") uses Bekap to serve its own customers, the MSP typically acts as processor for its customer and we act as sub-processor.
3. What Bekap does with email, in plain terms
Bekap copies email from a connected Google Workspace domain and writes it to storage that the subscribing business itself supplies and controls. Three points follow from the way the product is built, and they shape everything else in this policy:
Email bodies are never stored in our databases. Backed-up messages, including their content and attachments, are written to the customer's own S3 or S3-compatible bucket. We do not operate or host a storage tier of our own for that content.
We keep an index, not the mail. Our systems hold metadata describing what has been backed up. That metadata does include personal data, and is described in section 5.2.
Where a customer enables customer-held encryption, we cannot read the backups at all. The private key is generated in the customer's browser and is never transmitted to or stored by us. For backup connections created before July 12, 2026 under the older scheme, and for connections where encryption is not enabled, this does not apply. Section 11 explains the difference.
4. Personal data we process as controller
4.1 Account and user data
- Name, email address, avatar image URL where one is supplied, and email-verification status.
- Password, stored only as a cryptographic hash. We never store passwords in readable form.
- Multi-factor authentication data where enabled: an encrypted time-based one-time-password secret and hashed backup codes.
- Account status information, including active, locked and last-seen indicators, and failed authentication counters.
- Terms acceptance flag and, separately, marketing opt-in status.
4.2 Session and security data
- IP address, user agent string, and session creation, activity and expiry timestamps for each login session.
- Audit records of security-relevant events, described in section 4.5.
- We do not derive or record geolocation from IP addresses.
4.3 Organization and billing data
- Organization name, identifier, plan tier and seat entitlement.
- Billing email address, billing postal address and tax identification number. These fields are encrypted at the application layer before they are written to our database.
- Payment processor customer and subscription identifiers, and subscription status.
- Periodic usage snapshots, such as the number of mailboxes under backup, used for metered billing.
- We do not receive or store payment card details. Card data, where used, is handled entirely by our payment processor.
4.4 MSP tenant and branding data
- MSP tenant identifier and slug, custom domain, company name and support email address.
- Branding assets such as logos, colors and custom styling, stored separately from the primary database.
4.5 Audit records
We record security and administrative events, each with the acting user's email address, IP address, user agent, request identifier, outcome, timestamp and event-specific metadata. Recorded categories include authentication events (login, logout, failed login, multi-factor changes, session revocation), organization and membership changes, invitations, Google Workspace connection events, mailbox changes, backup and restore job events, encryption key events, and administrative settings changes.
5. Personal data we process as processor
5.1 Mailbox content
The bodies, headers and attachments of backed-up messages are written to the customer's own storage bucket. They are not held in our databases and are not visible in any interface we operate. Their content may contain any personal data that happens to appear in the customer's email, and the customer, as controller, determines what that is.
5.2 Backup metadata
We maintain, in a database schema isolated per organization, an index of what has been backed up. That index contains: the message and thread identifiers assigned by Google, subject line, sender address, recipient addresses, timestamp, message size, labels, an attachment indicator, and the storage key identifying where the message was written. Subject lines, sender and recipient addresses are personal data and, taken together with timestamps, can reveal a great deal about a person's correspondence. We treat this index accordingly.
5.3 Workspace connection and mailbox records
The email address and Workspace domain of the administrator who authorizes the connection; connection status and last verification timestamp; and, per mailbox, the mailbox address, display name, status, last synchronization and backup timestamps and assigned backup location.
5.4 Job telemetry
Per backup or restore job: status, job type, start and end times, message counts, bytes transferred, error messages, retry count and worker identifier.
6. The scope of access the Google connection grants
This is the single most important disclosure in this policy, and we set it out plainly.
When a Google Workspace administrator connects a domain to Bekap, the authorization is granted using domain-wide delegation. It is not limited to the administrator's own mailbox. It permits Bekap to read, and for the purpose of restores to write to, every mailbox in that Workspace domain, and to read the Workspace directory. In practice Bekap then processes each mailbox the customer has configured for backup.
If you are an employee of an organization that uses Bekap: one administrator at your organization, acting on your employer's behalf, has authorized this access. Your employer decides which mailboxes are backed up. Your employer is responsible for telling you about that and for having a lawful basis for it. If you have questions about the backup of your mailbox, please raise them with your employer.
We use the access strictly to perform the backup and restore functions the customer has requested. We do not use it to read, mine, profile or analyze the content of anyone's email, and we do not use Google Workspace data to develop, improve or train generalized artificial intelligence or machine-learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. How we collect personal data
- Directly from you, when you accept an invitation, register, configure the Service, contact support or complete billing details.
- From the organization that invited you, where it supplies your name and email address in order to invite you.
- Automatically, when you use the Service, through session, security and audit logging.
- From Google, through the Workspace connection your organization authorizes.
- From our payment processor, in the form of subscription and invoice status.
8. Why we process personal data, and on what legal basis
Where the GDPR applies to our processing as controller, we rely on the following bases.
- Providing and administering the Service, creating and managing accounts and organizations - performance of a contract (Art. 6(1)(b)); legitimate interests where the individual is not the contracting party (Art. 6(1)(f)).
- Authentication, multi-factor authentication, session management, lockouts and abuse prevention - legitimate interests in securing the Service (Art. 6(1)(f)); legal obligation to implement appropriate security (Art. 32).
- Audit logging and incident investigation - legitimate interests (Art. 6(1)(f)); legal obligation (Art. 32).
- Billing, invoicing, usage metering, tax and accounting records - performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)).
- Support and service communications - performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)).
- Marketing communications - consent, recorded through a separate opt-in (Art. 6(1)(a)).
- Establishing, exercising or defending legal claims - legitimate interests (Art. 6(1)(f)).
Where we act as processor, our legal basis for processing is the customer's documented instruction, and the customer is responsible for having a lawful basis of its own.
You may object to processing based on legitimate interests, and may withdraw consent to marketing at any time without affecting the lawfulness of processing before withdrawal.
9. Cookies
In the application at app.bekap.io, we set two first-party cookies in your browser. Both are strictly necessary for authentication, security or remembering which organization you last worked in. We do not use analytics, advertising or cross-site tracking cookies in the application, and we do not set third-party tracking cookies there.
On the marketing site at bekap.io, we use Google Analytics to understand how visitors find and use the public pages, but only where you accept it through the consent banner shown there - nothing is set and no data reaches Google until you do. This does not apply to the application. Full details, including the specific cookies involved and a bot-mitigation service that runs in your browser on our sign-up and password-reset pages, are in our Cookie Policy.
10. Who we share personal data with
We do not sell personal data and we do not share it for cross-context behavioral advertising. We disclose it only as follows.
10.1 Sub-processors and service providers
| Provider | Purpose | Data it receives |
|---|---|---|
| Stripe, Inc. | Subscription billing, invoicing, usage metering | Billing email, billing address, tax ID, subscription and usage data. Card data, where used, is handled by Stripe and not by us. |
| Resend | Transactional email (verification, password reset, invitations) | Recipient email address, name, organization name, invitation links. No backed-up email content is ever sent through this service. |
| Google LLC | Access to Google Workspace mailboxes for backup and restore | OAuth tokens; mailbox content is read and, for restores, written, via the Gmail API and Admin SDK. |
| Cloudflare, Inc. | Content delivery network, DNS and network-level security (TLS termination, DDoS protection, routing) in front of bekap.io and app.bekap.io; bot mitigation on sign-up and password-reset pages; storage of MSP branding assets | IP address and standard HTTP request metadata (user agent, referrer, timestamps) for every request, processed transiently to route and secure traffic; standard bot-mitigation client-side signals on sign-up/password-reset pages; non-personal branding assets. We plan to enable additional Cloudflare bot-management features (Bot Fight Mode / Super Bot Fight Mode and Managed Challenge) across both properties; these are not yet active. Once enabled, Cloudflare will additionally process device and behavioral signals needed to distinguish legitimate visitors from automated abuse. See our Cookie Policy for the specific cookies involved. |
| Google LLC (Google Analytics) | Usage analytics on the bekap.io marketing site only, active solely for visitors who accept our cookie banner | IP address (anonymized), device and browser information, pages viewed, referral source and general usage behavior on the marketing site. Never active on app.bekap.io or on white-labelled deployments. |
| Customer's own storage provider | Storage of backed-up email content | Full email messages. This is the customer's own account under the customer's own contract, not ours. |
We operate our own database, secrets store and job queue infrastructure. Those are components of our system rather than external recipients of data.
10.2 Other disclosures
- Professional advisers - lawyers, auditors and accountants, under duties of confidentiality.
- Legal and regulatory - where disclosure is required by law, court order or a competent authority, or is necessary to establish, exercise or defend legal claims. Where we are lawfully permitted to do so, we will notify the affected customer before disclosing data held on its behalf.
- Corporate transactions - a prospective or actual acquirer in connection with a merger, reorganization or sale of assets, subject to confidentiality and to this policy continuing to apply.
11. Encryption and security
11.1 Encryption of backed-up content
Encryption of backups is an optional, per-connection setting and is not on by default. Two schemes exist:
- Customer-held key, for connections created on or after July 12, 2026. An asymmetric keypair is generated in the customer's browser. Only the public key reaches us. The private key is never transmitted to or stored by us, other than transiently in memory when the customer supplies it to authorize a specific restore. Under this scheme we cannot decrypt the customer's backups.
- Provider-held key, for connections created before that date. A passphrase-derived key is retained on our systems, itself encrypted under a platform master key. Under this scheme we retain the technical ability to decrypt those backups. Existing connections are not migrated automatically.
11.2 Other measures
- Passwords hashed with a modern memory-hard algorithm; multi-factor secrets and backup codes stored encrypted or hashed.
- Credentials, OAuth tokens and encryption keys held in a dedicated secrets store and additionally encrypted by the application before being written to it.
- Billing address and tax identification data encrypted at the application layer before storage.
- HTTPS enforced in production; server-side session expiry checked on every request; cross-site request forgery protection on state-changing requests.
- Rate limiting on authentication endpoints; account lockout after repeated failures; self-service review and revocation of active sessions.
- Per-organization database schema isolation for backup metadata.
- Audit logging across authentication, organization, invitation, connection, mailbox, backup and encryption events.
No system is perfectly secure. We do not represent that the Service is immune from compromise, and we ask customers to enable multi-factor authentication, use customer-held encryption keys, and review roles and sessions regularly.
12. Access by our own personnel
We maintain internal administrative interfaces used for provisioning, account administration and support. Through those interfaces, authorized personnel can see account and organization records - names, email addresses, account and organization status, plan tier and seat limits, organization membership, connected Workspace domains and administrator addresses, and counts of mailboxes and connections - and can take administrative actions such as locking or unlocking an account, changing a plan or seat limit, provisioning an organization, and correcting billing linkage records.
Those interfaces do not display the content of anyone's email, and the Service contains no facility for our personnel to log in as, or impersonate, a user. Email content is not in our databases at all.
Billing address and tax identification fields are stored encrypted, and are not displayed in readable form in those interfaces. Personnel with access both to the production database and to the application encryption key have the technical means to decrypt them; that access is restricted to personnel with an operational need.
Separately, because we operate the infrastructure on which the Service runs, personnel with a legitimate operational need have technical access to the systems holding account data, backup metadata and encrypted credentials. That is inherent in operating a hosted service. It is limited to those who need it and is subject to confidentiality obligations and to our data processing agreement.
We are candid about one current limitation: not every administrative action taken through those interfaces is written to a persisted audit record today. We are improving that coverage. We mention it here rather than imply an audit trail that is more complete than it is.
13. International transfers
We are established in the United States and our infrastructure is operated from the United States. Personal data processed by us is therefore transferred to and processed in the United States, and may be accessible from other locations where our personnel or sub-processors operate.
Where we transfer personal data out of the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organizational measures, including the encryption measures described in section 11. Our data processing agreement incorporates those clauses. A copy of the transfer mechanism is available on request.
The location of backed-up email content is determined by the customer, because that content is written to storage the customer supplies. A customer that requires its email content to remain in a particular region must configure a bucket in that region. We do not currently offer, and therefore cannot guarantee, an EU-region hosting option of our own for backed-up content.
We have not, as at the date of this policy, appointed a representative in the European Union under Article 27 of the GDPR. We will update this policy when we do. Nothing here should be read as a representation that such an appointment currently exists.
14. How long we keep personal data
| Category | Retention |
|---|---|
| Audit records - general | One year |
| Audit records - administrative and compliance categories | Seven years |
| Backed-up email content | Determined by the customer, per backup connection. Where a retention period is configured, messages older than that period are deleted in accordance with the configuration. Content also remains subject to the customer's own storage lifecycle rules. |
| Backup metadata | For the life of the organization, then deleted with the organization record |
| Account and organization records | For the life of the account, then deleted or anonymized within a reasonable period after termination, subject to legal retention requirements |
| Billing and tax records | As required by applicable tax and accounting law, typically seven years |
| Email verification link | 24 hours |
| Password reset link | 1 hour |
| Account activation link | 7 days |
| Organization invitation link | 7 days by default |
| Multi-factor verification window | 5 minutes |
| Login session | Configurable per organization, from 30 minutes to 24 hours, defaulting to 2 hours |
We may retain data for longer where necessary to comply with a legal obligation or to establish, exercise or defend legal claims.
15. Your rights under the GDPR
If the GDPR applies to you, you have the right to request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; portability; and to object to processing based on legitimate interests or to direct marketing. You may also withdraw consent where we rely on it.
Where we process data as a processor on behalf of a customer, please direct your request to that customer, who is the controller. If you send it to us, we will forward it and assist the customer in responding, rather than acting on it ourselves.
We respond to requests addressed to us as controller within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. We may need to verify your identity first.
You have the right to lodge a complaint with a supervisory authority in the EU or EEA member state of your habitual residence, place of work, or the place of the alleged infringement.
We do not currently offer self-service account deletion or data export within the Service. Requests of that kind are handled manually by our team. We say so plainly rather than describe a self-service function that does not yet exist.
16. Your rights under California law
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives California residents rights over their personal information. Those rights extend to employees and business contacts, because California does not exempt business-to-business or employment-context personal information. If you are a California resident whose mailbox is backed up by your employer using Bekap, or who uses Bekap on behalf of a business, these rights apply to you.
Subject to verification and to exceptions in the statute, you may request: to know the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of recipients; deletion of your personal information; correction of inaccurate personal information; and to limit use of sensitive personal information. You may not be discriminated against for exercising these rights.
We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months, including in respect of anyone under 16.
The categories we collect are: identifiers; commercial information; internet or network activity; professional or employment-related information; and, in the case of backed-up mailboxes, the contents of electronic mail, which the statute treats as sensitive personal information where we are not the intended recipient. We use that content solely to provide the backup and restore service requested by the business customer and for no other purpose, which is within the permitted purposes for which use need not be limited on request.
You may make a request through an authorized agent, with proof of authorization. Where the request concerns data we hold as a service provider for a business customer, we will refer it to that customer.
17. Rights under other US state laws
Residents of states with comprehensive privacy statutes, including Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana and others, may have rights of access, correction, deletion, portability and opt-out. Several of those statutes exempt personal data processed in a business-to-business or employment context, so their application to Bekap may be narrower than California's. We will honor verified requests to the extent the applicable statute requires. Where a statute provides a right of appeal against our decision, we will tell you how to exercise it when we respond.
Wyoming, where we are incorporated, does not currently have a comprehensive consumer privacy statute.
18. Automated decision-making and profiling
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals. Automated processing in the Service is limited to operational functions such as scheduling backup jobs, enforcing retention configuration, rate limiting and account lockout.
19. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 directly. Where a customer's mailbox happens to contain correspondence with a minor, that content is handled as part of the backup on the customer's instruction and under the customer's responsibility as controller.
20. Data breaches
We maintain an incident response process covering detection, containment, assessment and notification. Where we act as processor, we will notify the affected customer without undue delay after becoming aware of a personal data breach affecting its data, and will provide the information reasonably required for the customer to meet its own notification obligations, including under Article 33 of the GDPR. Where we act as controller, we will notify the competent supervisory authority and, where required, affected individuals in accordance with applicable law.
21. Changes to this policy
We may update this policy. Where a change is material, we will give notice by email to registered account contacts or by in-product notification before it takes effect. The effective date at the top of this policy shows when it was last revised. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
22. How to contact us
For any question about this policy, or to exercise a right described in it:
OhMyLabs LLC
75 E 3rd St, Sheridan, WY 82801, United States
Privacy contact: legal@bekap.io
We have not appointed a data protection officer, as we are not required to do so under Article 37 of the GDPR. Privacy enquiries are handled by the contact above.