Fiverr Agent Studio
Last updated 27 August 2026

Privacy policy

Fiverr Agent Studio is a private, single-owner productivity application. It is not offered as a public service.

Information processed

The application may process Gmail message identifiers, sender details, subjects, snippets and message content for emails matching the owner's configured Fiverr search query. It may also process buyer requirements, owner-entered notes, uploaded assets, generated drafts, quality-assurance results and API usage information.

Purpose and legal basis

Information is processed only to monitor the owner's business notifications, prepare internal work, notify the owner and maintain the requested workflow. The owner is responsible for establishing an appropriate lawful basis before entering or processing personal information belonging to another person.

Google user data

Google user data is used only to provide the Gmail-monitoring and email-alert functions described here. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising or used to train a general-purpose model.

Service providers and transfers

Data may be transmitted to Google for Gmail API operations, Railway for application hosting and storage, OpenAI for requested AI processing, and Telegram for alerts when configured. These providers may process information in other countries under their respective terms and safeguards.

Storage and retention

Application workspaces and monitoring state are stored on the owner's private Railway volume. Information remains until the owner removes it or deletes the associated storage or service. Gmail credentials and service tokens are stored as private Railway environment variables and are not displayed in the dashboard.

Security

The application uses HTTPS, a password-protected owner dashboard and private environment variables. No internet-connected system can guarantee absolute security. The owner must keep all passwords, OAuth credentials and service tokens confidential.

Control and deletion

The owner can revoke Google access from their Google Account permissions, rotate or delete OAuth credentials in Google Cloud, and delete application data or the Railway service. Revoking access stops future Gmail API access but does not automatically delete information already stored in the private application.

Contact

Privacy enquiries should be directed to the user-support email displayed on the Google OAuth consent screen.