Last updated / Utolsó frissítés: 21 July 2026 / 2026. július 21.
EcoSynq Connect adathasználati nyilatkozat
Ez az oldal tételesen leírja a Connect aktuális szolgáltatásainak adatútját. A katalógusban látható művelet nem automatikusan végrehajtható: csak hivatalos API, érvényes fiók/scope, szükséges provider/tenant jóváhagyás, bekapcsolt felhasználói capability és futásidejű ellenőrzés után kerülhet a Codex eszközkatalógusába. Kizárólag a runtime által Executable állapotúnak jelölt művelet fut; az AdapterMissing vagy AdapterUnavailable elem látható lehet, de kikapcsolva marad.
- Provider-adatot nem értékesítünk, nem használunk reklámhoz, megfigyeléshez, hitelbírálathoz, adatbrókerhez vagy általános AI-modell tanításához.
- A tartós API/OAuth credential a Windows DPAPI credential-vaultban, a WebView cookie/session külön exact fiókhoz kötött elkülönített WebView2-profilban, a TDLib pedig külön adatbázisban marad. Az OAuth broker titkosított tranzakciója legfeljebb 10 percig, sikeres kézbesítés után legfeljebb további 120 másodperces retry-időig él. A WhatsApp titkosított relay-boríték nyugtázáskor törlődik, egyébként legfeljebb 24 óra után. A Meta HMAC-olt törlési nyugta legfeljebb 30 nap után lejár; a Meta callback nem törli az eszköz helyi adatait.
- A secretmentes állapot-helyreállítási backup 30 napig marad meg, és a rendszer legfeljebb 180 pillanatképet tart; a 180 a pillanatképek darabszámkorlátja, nem megőrzési idő. Az AGENTS/skill backup külön beállítás, alapértéke 30 nap; az értesítési előzmény külön beállítható, alapértéke 30 nap. A Connect-backup nem tartalmaz élő WebView2-profilt vagy DPAPI-vaultot; Windows-/vállalati backupért a felhasználó vagy admin felel.
- „Feltételes AI” azt jelenti, hogy a provider szabálya megengedi az adott, felhasználó felé látható funkciót, a felhasználó bekapcsolta, és a Connecthez kapcsolt egyetlen személyes ChatGPT/Codex-fiókban a felhasználó nyilatkozata szerint a ChatGPT és a használt Codex-környezet modelljavítási adatmegosztása ki van kapcsolva. A „Felhasználó által igazolt no-training” státusz csak dátummal rögzített felhasználói nyilatkozat; a Connect nem ellenőrzi technikailag vagy jogilag a külső fiók adatvezérlését, a szerződést vagy a Limited Use-megfelelést, ezért nem garancia. Ez nem enged általános tanítást, háttér-indexet vagy váratlan műveletet.
- A Connect nem tudja hitelesíteni a kiválasztott tartalom valós vagy kitalált jellegét, forrását vagy harmadik fél érintettségét. A felhasználó szavatolja a kért feldolgozáshoz szükséges és bizonyítható jogalapot, felhatalmazást vagy hozzájárulást; szóbeli hozzájárulás csak akkor elegendő, ha az alkalmazandó jog és provider-szabály megengedi, és megtörténte bizonyítható. Ez nem zárja ki az EcoSynq kötelező felelősségét, és nem ír felül provider-tilalmat vagy technikai kaput.
- „Nincs AI” fail-closed tiltás. Telegram API-adat esetén ez a Telegram írásos engedélyéig teljes tiltás.
- Az AI által megfogalmazott értesítési összefoglaló és fontossági címke tájékoztató, felülbírálható, és nem lehet kizárólag automatizált, joghatást vagy hasonlóan jelentős hatást kiváltó döntés alapja.
EcoSynq Connect Data Use Notice
This page describes the data path for Connect's current services. A catalogued operation is not automatically executable: only an official API operation with a valid account/scope, required provider/tenant approval, an enabled user capability and runtime validation may enter the Codex tool catalog. Only an operation marked Executable by the runtime can run; an AdapterMissing or AdapterUnavailable item may remain visible but disabled.
- Provider data is not sold or used for advertising, surveillance, credit decisions, data brokerage or training a general-purpose AI model.
- Durable API/OAuth credentials stay in the Windows DPAPI credential vault, WebView cookies/sessions in a separate isolated WebView2 profile bound to the exact account, and TDLib in a separate database. An encrypted OAuth broker transaction lasts at most ten minutes, with no more than 120 seconds of retry after successful delivery. An encrypted WhatsApp relay envelope is deleted on acknowledgement or after at most 24 hours. A Meta HMAC deletion receipt expires after at most 30 days; the Meta callback does not erase device-local data.
- Secret-free state-recovery backups are retained for 30 days and the system keeps at most 180 snapshots; 180 is a snapshot-count cap, not a retention period. AGENTS/skill backup retention is separate and defaults to 30 days; notification history is separately configurable and defaults to 30 days. Connect backups do not contain the live WebView2 profile or DPAPI vault. The user or administrator controls Windows/enterprise backups.
- “Conditional AI” means a visible user-requested feature allowed by provider rules and enabled by the user, where the user's declaration states that model-improvement data sharing is disabled in both ChatGPT and the Codex environment used by the single personal ChatGPT/Codex account linked to Connect. The “User-attested no-training” status is only a dated user declaration; Connect cannot technically or legally verify the external account controls, contract or Limited Use compliance and it is not a guarantee. It never means general training, a background index or an unexpected action.
- Connect cannot authenticate whether selected content is real or fictional, its source, or whether a third party is involved. The user warrants that every demonstrable legal basis, authority or consent required for the requested processing exists; oral consent is sufficient only where applicable law and provider rules permit it and the fact that it was given can be demonstrated. This does not exclude EcoSynq's mandatory liability and cannot override provider restrictions or technical gates.
- “No AI” is a fail-closed prohibition. For Telegram API data it remains absolute until Telegram grants written permission.
- An AI-written notification summary and importance label are advisory and user-overridable, and must not be the sole basis for a decision producing legal or similarly significant effects.
Complete service inventory / Teljes szolgáltatásleltár
Storage abbreviations / Tárolási rövidítések: Local = device-local data; only a row that explicitly says DPAPI credential means the protected credential vault; Broker = encrypted OAuth delivery for at most 10 minutes plus up to 120 seconds of post-delivery retry; Relay = device-encrypted WhatsApp event, acknowledgement or 24-hour expiry; WV = separate isolated WebView2 profile. Deletion also requires provider revocation wherever the provider issued a token.
Custom API boundary: only custom-website accepts a generic user-supplied API host/credential, bound to one exact local service instance. Provider-specific connection profiles never inherit that host, account or token. Their operations remain independently runtime-gated and expose only reviewed Executable contracts.
Standard mail/contact/calendar boundary: Fastmail uses an exact account-bound built-in JMAP adapter with 41 executable operations. Any other JMAP, IMAP4rev2/SMTP Submission, CardDAV or CalDAV connection is an account-level protocol profile, not a shared credential or automatic provider approval. Provider-specific OAuth/API remains first choice. Each connection needs its own validated server, identity, TLS, OAuth or explicitly enabled app password, policy acceptance and sync cursor; no normal account-password storage, credential reuse, cleartext/downgrade or unvalidated discovery target is permitted.
| Service | Data and use / Adat és cél | Storage / Tárolás | AI/Codex | Main access/review gate / Fő scope-review | Deletion / Törlés |
|---|---|---|---|---|---|
android-messagesAndroid Messages | Personal SMS/RCS shown for ordinary paired web use / személyes üzenetek kézi párosított webhasználatra | WV only | No API/Codex / nincs | No public personal automation API / nincs nyilvános személyes API | Delete WV profile, unpair in Google Messages / WV törlés és párosítás megszüntetése |
chatworkChatwork | Live exact account connection/credential profile plus isolated WebView; official operation catalog is runtime-gated / élő exact fiókprofil és elkülönített WebView | Local DPAPI credential; WV; exact account/host binding | Only runtime Executable operations; AdapterMissing disabled; provider data-use gate applies | x-chatworktoken or OAuth, form/multipart, webhook HMAC; organization-admin application except eligible personal-plan use | Delete local credential/profile, sign out/delete exact WV, revoke token/OAuth and ask the organization admin where applicable |
cisco-sparkWebex (legacy Cisco Spark) | Live exact account connection/credential profile plus isolated WebView; official operation catalog is runtime-gated | Local DPAPI credential; WV; exact account/host binding | Only runtime Executable operations; AdapterMissing disabled; exact scopes/roles/licences remain gates | Production integration/redirects, privacy/terms/support, test instructions and App Hub review; organization admin and Calling/Contact Center licences as applicable | Delete local credential/profile, sign out/delete exact WV and revoke the connected app/token through Webex/admin |
custom-websiteCustom Website | Only user-configured official REST/OpenAPI data on one exact HTTPS host and one exact service instance | Local key; exact account/service-instance/host binding; GET/HEAD only | Fail closed until the endpoint/provider has a reviewed, versioned AI data-use policy | User/tenant authorization; no redirects/private APIs; no credential inheritance across services | Remove the exact connection/key/cache and revoke the server key |
discordDiscord | Identity/guild data; bot-authorized channel data only if later approved | Local bot/OAuth token; minimal cache | No message content absent express Discord permission | Bot only; verification and privileged intents; no self-bot | Remove app from server, revoke grant, local delete |
ecosynq-desktopEcoSynq WinUI3 Desktop | Local reports, files, runtime state and user-requested native actions | Local only | User-controlled folders/tools/shell | Windows and Connect permission profile; no third-party review | Delete local profile/state/backups according to retention |
facebook-pagesFacebook Pages | Managed Pages, posts, comments, insights and exact user-requested Page actions | Local DPAPI token + transient Broker state; WV | Conditional; approved user-requested use only; a no-training checkbox is a user declaration, not provider verification | pages_show_list, read/manage scopes, Page tasks, Meta App Review/Business Verification | Disconnect/local delete, revoke Meta app; callback deletes only transient broker state and keeps a hashed receipt |
fastmailFastmail | Exact account-bound JMAP connection with 41 built-in executable JMAP/Masked Email operations plus isolated WebView | DPAPI credential; separate local session metadata; WV; exact session endpoint/account/capability binding; selected blobs only in the working folder | 41 built-in runtime Executable JMAP/Masked Email operations, still subject to discovered capabilities, scopes, user switches and approval gates | Fastmail manually registers distributed OAuth clients; app owner supplies identity, legal/support URLs, least scopes and redirects; user consent required | Delete local credential/session/cursors/blobs, sign out/delete exact WV, and revoke OAuth/token/app password at Fastmail |
google-tasksGoogle Tasks | Task lists/tasks for visible CRUD requested by user | Local token + Broker; WV | Conditional under Google Limited Use and no-training | Tasks OAuth scopes, Google brand/sensitive-scope review as applicable | Disconnect/local delete; revoke Google grant |
gadu-gaduGadu-Gadu | Manual web messaging only | WV only | No API/Codex | No selected stable public API contract | Sign out and delete WV profile |
githubGitHub | Repositories, issues, pull requests, notifications and explicit developer actions | Local OAuth/App token + Broker; WV | Conditional, repository/account scoped | Prefer GitHub App fine-grained permissions and short-lived tokens; Marketplace if listed | Uninstall/revoke GitHub App/OAuth grant and local delete |
gitterGitter | Manual WebView today; provider API is an inactive adapter candidate | WV only; this service accepts no API credential | No API/Codex until provider lifecycle and a typed adapter are reviewed | API lifecycle, authentication, operation manifest and policy gate require revalidation | Sign out and delete the WV profile |
glowing-bearGlowing Bear | Manual WeeChat relay UI | WV only | No central API/Codex | Automation would belong to user's WeeChat relay, not Glowing Bear | Delete WV and revoke/change relay password |
gmailGmail | Email/thread search/read, exact attachment read, draft/reply/send selected by user | Local token + Broker; WV | Conditional under Google Limited Use and no-training | Gmail sensitive/restricted scopes, verification, demo and potentially annual security assessment | Disconnect/local delete, revoke Google grant; delete drafts/messages in Gmail separately |
google-analyticsGoogle Analytics 4 | Selected property reports/metadata for visible analytics | Local token + Broker; WV; transient results | Conditional; no background profile/training | Analytics read scopes, property role, Google verification | Disconnect/local delete and revoke Google grant |
google-calendarGoogle Calendar | Calendars/events for user-requested read and CRUD | Local token + Broker; WV | Conditional under Limited Use/no-training | Calendar scopes; incremental consent and Google review | Disconnect/revoke; event deletion remains a separate confirmed provider action |
google-chatGoogle Chat | Spaces/members/messages and exact send where app/account permits | Local token + Broker; WV | Conditional; no general training | Chat scopes, Workspace/admin and Google app review/configuration | Disconnect/revoke; delete local cache; provider content remains per Workspace policy |
google-driveGoogle Drive | File/folder metadata and user-selected file content/actions | Local token + Broker; WV; files only as selected | Conditional under Limited Use/no-training | Narrow drive.file/metadata scopes where possible; restricted-scope review/assessment if broader | Disconnect/revoke, delete local copies; Drive items separately |
google-keepGoogle Keep | Manual personal notes | WV only | No API/Codex | No supported public consumer Keep API | Sign out/delete WV; notes deleted in Google Keep |
google-search-consoleGoogle Search Console | Verified site/search performance data | Local token + Broker; transient result cache | Conditional under Limited Use/no-training | Search Console scopes plus site ownership/permission and Google verification | Disconnect/revoke and remove local results |
google-voiceGoogle Voice | Manual personal voice/messages | WV only | No API/Codex | No selected general public consumer messaging API | Sign out/delete WV profile |
groupmeGroupMe | Live exact account connection/credential profile plus isolated WebView; official operation catalog is runtime-gated | Local DPAPI credential; WV; exact account binding | Only runtime Executable operations; AdapterMissing disabled | Developer app and per-user authorization; API uses X-Access-Token and forbids a query-string token; group-specific bot installation | Delete local credential/profile, sign out/delete exact WV, revoke the app/token and remove group bots |
hangoutsHangouts | Only supported Google Chat data; no retired personal Hangouts API claim | As Google Chat or WV redirect | Same as Google Chat | Legacy alias; Google Chat scopes/review | Same as Google Chat |
hangouts-chatHangouts Chat | Google Chat spaces/messages under legacy label | As Google Chat | Same as Google Chat | Legacy alias; Google Chat scopes/review | Same as Google Chat |
icloud-mailiCloud Mail | Manual mailbox use | WV only | No API/Codex | No Apple OAuth/mail API connector; future IMAP/app-password is separate | Sign out/delete WV; revoke app password if later used |
instagram | Professional-account media/comments/insights where reviewed; personal Direct remains manual | Local Meta token + Broker; WV | Conditional for approved professional data only | instagram_basic and product-specific permissions; Meta App Review/Business Verification | Disconnect/revoke Meta app and delete local data |
irccloudIRCCloud | Manual IRCCloud web client | WV only | No API/Codex | No centrally verified adapter selected | Sign out/delete WV and revoke IRCCloud sessions |
linkedin | OpenID/profile; organization publishing/marketing only after separate product approval | Local OAuth token + Broker; WV; minimal cache | Conditional only for approved product and no-training; no personal-message automation | OpenID self-service; Community Management/Marketing require LinkedIn approval and roles | Disconnect/revoke LinkedIn app and selectively delete cached data |
mailchimpMailchimp | Audiences/members/campaigns/reports and explicit campaign operations | Local OAuth token + Broker; data-center bound; WV | Conditional; marketing-law and no-training controls | OAuth, Integration Partner review, plan/role, consent/suppression requirements | Disconnect/revoke; delete local cache; contacts/campaigns separately with confirmation |
mailbox-orgmailbox.org | Manual webmail | WV only | No API/Codex | No central adapter; future IMAP/JMAP is user-owned | Sign out/delete WV; revoke app password if applicable |
mattermostMattermost | Live exact tenant/account connection/credential profile plus isolated WebView; official catalog is runtime-gated; the customer controls self-hosted end-user data | Local DPAPI credential; WV; exact tenant/account/host binding | Only runtime Executable operations; AdapterMissing disabled; tenant-owner AI/data-use approval remains mandatory | Tenant terms/privacy, owner approval, system-admin-enabled PAT or OAuth, and exact team/channel/file/integration roles | Delete local credential/profile and exact WV, revoke PAT/OAuth and request tenant-admin retention/deletion |
messengerMessenger | Manual personal Messenger inbox | WV only | No personal API/Codex | Page Messenger API cannot access personal inbox | Sign out/delete WV; use Meta account deletion tools separately |
meta-business-messengerMeta Business Messenger | Managed Page conversations/messages and webhook events | Local DPAPI Meta token + transient Broker state; WV; device-encrypted transient events | Conditional for approved Page use; no-training state is a user declaration, not provider verification | pages_messaging, Page roles, webhook fields, App Review/Advanced Access | Disconnect/revoke; separately delete local stores; callback deletes only transient broker state and keeps a hashed receipt |
meta-ads-managerMeta Ads Manager | Manual ads management plus an official provider operation inventory whose availability changes with SDK/API versions | WV plus local DPAPI Meta OAuth token; only exact reviewed contracts marked runtime Executable are callable | Conditional only for runtime Executable bounded contracts; all AdapterMissing inventory rows remain fail-closed | Marketing API access, Business Verification, App Review/Advanced Access where required, applicable ads_read, ads_management, business_management, leads_retrieval or catalog_management, and exact asset role | Disconnect/revoke the Meta app token, delete separate local stores and separately delete provider-side ads/assets where applicable |
meta-businessMeta Business Suite | Aggregate managed Pages, professional Instagram and Page Messenger data | Local DPAPI Meta token + transient Broker state; WV | Conditional per reviewed product/use case; user declaration is not provider/legal verification | Meta Business Verification, App Review, exact permissions/assets/tasks | Disconnect/revoke and separately delete local stores; signed callback deletes only transient broker state |
microsoft-teamsMicrosoft Teams | Joined teams/channels/messages and exact user-requested actions | Local Graph token + Broker; WV | Conditional under tenant policy and no-training | Delegated Graph Teams permissions, verified publisher, admin consent where required | Disconnect/revoke enterprise app, local delete; tenant retention remains |
mysmsMySMS | Manual WebView today; provider API is an inactive adapter candidate | WV only; this service accepts no API credential | No API/Codex until a reviewed provider-specific adapter exists | Developer credentials, exact operations and policy gate required | Sign out and delete the WV profile |
nextcloud-talkNextcloud Talk | Live exact instance/account connection/credential profile plus isolated WebView; OCS operation catalog is runtime-gated; instance operator controls tenant data | Local DPAPI credential; WV; exact instance/account/host binding | Only runtime Executable operations; AdapterMissing disabled; tenant approval applies | Instance terms/privacy; admin enables Talk/Login Flow and roles; bots require occ talk:bot:install; calling/signalling is separate | Delete local credential/profile and exact WV, revoke app password/session/bot and ask instance admin for retained data |
office-365-outlookOffice 365 - Outlook | Organizational mail/calendar and explicit draft/send/event operations | Local Graph token + Broker; WV | Conditional on tenant/no-training | Graph Mail/Calendars permissions, verified publisher/admin consent as applicable | Disconnect/revoke enterprise app, local delete; mailbox items separately |
onedriveOneDrive | Selected file/site metadata/content/actions | Local Graph token + Broker; WV | Conditional on tenant/no-training | Minimum Files permissions; tenant admin consent if broader | Disconnect/revoke, delete local copies; OneDrive items separately |
outlookOutlook | Consumer/organizational mail/calendar through Graph or manual WV | Local Graph token + Broker; WV | Conditional on account/tenant policy | Mail/Calendars scopes; consumer vs tenant consent; publisher verification | Disconnect/revoke and delete local data |
plurkPlurk | Official API catalog audited, but the Connect adapter is unavailable; isolated WebView remains available | WV only; no API credential accepted | AdapterUnavailable; no API/Codex execution | Owner registration and typed OAuth 1.0a/Comet/polling adapter plus provider-policy gate are still required | Sign out/delete exact WV; no Connect API credential exists to revoke |
proton-mailproton-mail | Manual encrypted mailbox | WV only | No API/Codex | No general cloud mailbox API; future local Bridge/IMAP requires plan/setup | Sign out/delete WV; remove Bridge credential if later used |
pulse-smsPulse SMS | Manual web SMS | WV only | No API/Codex | No selected stable public connector contract | Sign out/delete WV and provider sessions |
pushbulletPushbullet | Live exact account connection/credential profile plus isolated WebView; official operation catalog is runtime-gated | Local DPAPI credential; WV; exact account binding | Only runtime Executable operations; AdapterMissing disabled; uploads/streaming remain closed unless explicitly supported | Registered OAuth app and user consent/revocation; account plan/push limits and device availability are runtime gates; no public directory review is claimed | Delete local credential/profile and exact WV, revoke OAuth/token and delete local ephemerals |
rainloopRainLoop | Manual self-hosted webmail UI | WV only | No central API/Codex | Not a mail provider API; future IMAP belongs to configured server | Sign out/delete WV; revoke mail app password |
riotMatrix/Element (legacy Riot) | Live exact homeserver/account connection/credential profile plus isolated WebView; official catalog is runtime-gated; federated rooms may replicate to other homeservers/bridges | Local DPAPI credential; WV; exact homeserver/account binding; device/key material remains separately governed | Only runtime Executable operations; AdapterMissing disabled; encrypted-room/device handling and tenant disclosure remain gates | Exact homeserver terms/privacy and login/OAuth; user device verification; room-admin/participant permissions; matrix.org/Element policies apply only to their own services | Delete local credential/profile and exact WV, revoke token/device/key backup and request homeserver/room deletion where supported |
rocket-chatRocket.Chat | Live exact workspace/account connection/credential profile plus isolated WebView; the tenant's live specification is authoritative and the catalog is runtime-gated | Local DPAPI credential; WV; exact workspace/account/host binding | Only runtime Executable operations; AdapterMissing disabled; owner-approved data use applies | Workspace terms/privacy; owner/admin issues PAT/session, grants roles/modules/edition and approves AI transfer; cloud/marketplace features may add vendor terms | Delete local credential/profile and exact WV, revoke PAT/session and request workspace-admin retention/deletion |
roundcubeRoundcube | Manual self-hosted webmail UI | WV only | No central API/Codex | Not a provider API; future IMAP belongs to configured mail server | Sign out/delete WV; revoke mail app password |
skypeSkype | Legacy/manual web experience if reachable | WV only | No API/Codex | Skype Web SDK retired; use Teams/Azure Communication Services for new integrations | Sign out/delete WV and Microsoft sessions |
sharepointSharePoint | Selected sites/lists/files metadata/content/actions | Local Graph token + Broker; WV | Conditional on tenant/no-training | Minimum Sites/Files permissions; admin consent commonly required | Disconnect/revoke, local delete; tenant records remain per policy |
slackSlack | Authorized conversations, threads, users and exact posts; no bulk export/index | Local OAuth token + Broker; minimal transient cache; WV | Fail closed pending compliant approved Slack use; never training | Commercial Marketplace required; current hub/workflow/client shape may be ineligible; least scopes, signature checks | Uninstall/revoke Slack app, delete token/cache and backups |
steam-chatSteamChat | Manual personal chat | WV only | No API/Codex | No supported public personal-chat automation API | Sign out/delete WV and Steam web sessions |
tawk-toTawk.to | Manual WebView today; account API is an inactive adapter candidate | WV only; this service accepts no API credential | No API/Codex until a reviewed business adapter exists | Account auth, customer notice, typed operations/webhooks and policy gate required | Sign out and delete the WV profile |
teamwork-projectsTeamwork Projects | Live exact tenant/account connection/credential profile plus isolated WebView; versioned official catalog is runtime-gated | Local DPAPI credential; WV; exact tenant/account/host binding | Only runtime Executable operations; AdapterMissing disabled; file/webhook routes require explicit support | Owner-company user creates publisher/app and Product Scopes; Teamwork verification/go-live, site-admin roles and paid webhook plan as applicable | Delete local credential/profile and exact WV, revoke the app/token with the owner/site admin |
telegramTelegram | Messages/chats/contacts requested through TDLib/MTProto | Encrypted local TDLib database/session; WV | No AI/Codex under Telegram API Terms 1.5 | EcoSynq own api_id, unofficial-client disclosure, expected semantics, no spam | Log out TDLib, terminate session in Telegram, securely delete local database/WV |
the-loungeThe Lounge | Manual self-hosted IRC web client | WV only | No central API/Codex | Automation belongs to customer IRC/server; no typed adapter | Sign out/delete WV; rotate IRC/server credentials |
threemaThreema | Personal WebView remains manual; Threema Gateway is a separate business product and does not expose personal history | WV only; no Gateway credential accepted | AdapterUnavailable; no personal or Gateway API/Codex execution | An official-SDK cryptographic adapter, form/blob/callback handling, paid Gateway ID/secret/key/credit and provider-policy gate are still required | Sign out/delete exact WV; no Connect Gateway credential exists to revoke |
todoistTodoist | Projects/labels/tasks and explicit task CRUD | Local OAuth token + Broker; WV | Conditional/no-training | Unified API v1 OAuth or dynamic registration; certification/signed native app for listing | Disconnect/revoke Todoist app and delete local data |
togglToggl Track | Live exact workspace/account connection/credential profile plus isolated WebView; official operation catalog is runtime-gated | Local DPAPI API token; WV; exact workspace/account/host binding | Only runtime Executable operations; AdapterMissing disabled; reports/webhooks remain subject to plan and adapter support | User API token (never password), organization/workspace role, subscription quota and webhook-plan limits; no public marketplace review is claimed | Delete local credential/profile and exact WV, revoke/regenerate the API token and delete local data |
trelloTrello | Boards/lists/cards/members and exact card operations | Local user token/key; WV | Conditional/no-training | Trello key/token, allowed origins; Atlassian Marketplace/privacy/security review if distributed | Revoke token/Power-Up, disconnect, local delete |
twistTwist | Live exact workspace/account connection/credential profile plus isolated WebView; official operation catalog is runtime-gated | Local DPAPI credential; WV; exact workspace/account binding | Only runtime Executable operations; AdapterMissing disabled; multipart/webhook routes require explicit support | OAuth app/redirect/scopes; directory listing needs English metadata, HTTPS privacy/support/install links, screenshots, signed native app and Doist brand/data rules; personal tokens are testing-only | Delete local credential/profile and exact WV, revoke OAuth/token and delete local data |
twitchTwitch | Live exact account/channel connection/credential profile plus isolated WebView; Helix/EventSub catalog is runtime-gated | Local DPAPI credential; WV; exact account/channel/client binding; event cursor transient | Only runtime Executable operations; AdapterMissing disabled; verified EventSub transport and role/product gates apply | Developer Console app/secret/redirect/category plus broadcaster/moderator/bot consent; role/product/verification gates apply; modern chat uses EventSub + Helix | Delete local credential/profile and exact WV, revoke OAuth/app access, subscriptions and local cursors |
vkVK | Official API catalog audited, but the Connect adapter is unavailable; isolated WebView remains available | WV only; no API credential accepted | AdapterUnavailable; no API/Codex execution | Typed schema/token-kind/upload/Callback/Long Poll adapter, owner app/community, exact token rights and provider-policy gate are still required | Sign out/delete exact WV; no Connect API credential exists to revoke |
voxerVoxer | Manual personal messaging | WV only | No API/Codex | No selected stable public personal-account API | Sign out/delete WV and provider sessions |
wechat | Manual personal WeChat only | WV only | No personal API/Codex | Personal chat has no public automation API; WeCom/Official Account is separate business review | Sign out/delete WV; terminate provider sessions |
whatsapp | Business accounts/phone/templates, user-requested business messages/read status and signed webhook events; personal chats only WV | Local DPAPI Meta token + transient Broker state; device-encrypted Relay; WV | Conditional for Business data only, with opt-in/window/template/human-handoff; no-training is a user declaration, not provider verification | WABA/phone/business verification, Cloud API permissions, templates, webhook, App Review/Tech Provider path | Disconnect/revoke Meta app; separately delete local stores; relay expiry/ack; callback deletes only transient broker state |
xX | Profile/posts/search and exact previewed posts/actions allowed by paid plan | Local OAuth token + Broker; WV; short cache synchronized with deletes | Conditional on approved use/no-training | Registered use case, paid tier, explicit action consent, display rules; material changes may need approval | Disconnect/revoke X app, local delete; synchronize provider deletion/edit within 24h |
xing | Manual social/messaging use | WV only | No API/Codex | No selected public messaging API/product access path | Sign out/delete WV and provider sessions |
yammerYammer | Only supported Viva Engage/Microsoft Graph data under legacy alias | As Microsoft Graph or WV redirect | Conditional under tenant policy | Retired branding; Graph Viva Engage availability/permissions and admin consent | Same as Microsoft connection; delete WV redirect profile |
zendeskzendesk | Exact-customer tickets/users/search for individual user queries; no bulk export/background corpus | Local tenant OAuth/token; transient per-query data; WV | Conditional only when customer directs/disclosure/no-training; no general AI model | Customer admin/subdomain; global OAuth/Marketplace for multi-customer server app; possible security audit | Disconnect/revoke, promptly delete cache; customer/provider records follow Zendesk policy |
zoho-cliqZoho Cliq | Live exact data-centre/tenant/account connection/credential profile plus isolated WebView; official catalog is runtime-gated | Local DPAPI credential; WV; exact data-centre/tenant/account binding | Only runtime Executable operations; AdapterMissing disabled; file/handler routes require explicit support | Owner registers exact data-centre client/redirect/scopes; tenant admin roles/edition and public bot/extension/function handlers may be required | Delete local credential/profile and exact WV, revoke Zoho OAuth/app/handlers and delete local cursors/cache |
zulipZulip | Live exact organization/account connection/credential profile plus isolated WebView; official catalog is runtime-gated; organization owner/operator controls tenant exports, bots and policy | Local DPAPI credential; WV; exact organization/account/host binding | Only runtime Executable operations; AdapterMissing disabled; owner-approved data use applies | Exact organization terms/privacy, owner/admin approval, user/bot API key and channel/role access; no sale, ads, scraping/rate bypass or consent-free contact reuse | Delete local credential/profile and exact WV, revoke user/bot key and ask organization admin for exports/retained data |
Runtime-gated és nem elérhető providerek hivatalos feltételei
Az alábbi hivatkozások a kapcsolat, adapter és provider/tenant ellenőrzés kötelező forrásai. A kapcsolat-/credential-profil megléte nem jelent provider-jóváhagyást vagy minden katalógusművelet elérhetőségét. Mattermost, Matrix/Element, Rocket.Chat, Zulip, Nextcloud Talk, Webex, Chatwork, Toggl Track, Teamwork Projects, GroupMe, Pushbullet, Twist, Twitch és Zoho Cliq esetén csak a runtime Executable műveletei futnak, az AdapterMissing sorok kikapcsoltak. Fastmail 41 beépített végrehajtható JMAP-művelettel rendelkezik. Plurk, VK és Threema Gateway AdapterUnavailable.
- Webex: Developer Terms, Cisco Privacy, App Hub submission. PKCE, legkisebb scope, app privacy/terms/support, tesztelési leírás és adott esetben szervezeti admin/licenc szükséges.
- Chatwork: API Terms, Terms, Privacy, API docs. Az OAuth/app regisztráció mellett — az erre jogosult személyes csomagot kivéve — szervezeti admin API-kérelme szükséges lehet.
- GroupMe: API License, Privacy, Terms, Brand Standards. Az API
X-Access-Tokenheadert ír elő; query-string tokent nem használunk. - Pushbullet: Terms, Privacy, API docs. OAuth app és felhasználói engedély szükséges; nyilvános app-directory reviewt vagy univerzális numerikus kvótát az EcoSynq nem állít.
- Toggl Track: Terms, Privacy, Legal Center, API docs. Csak API-token használható, jelszó nem; a szerepkör, kvóta és webhook a csomagtól függ.
- Teamwork Projects: Terms, Privacy, Developer Portal. Owner-company felhasználó, publisher/app Product Scope, tesztelés, Teamwork verification/go-live és adott esetben site-admin/fizetős webhook szükséges.
- Twist: Doist Terms, Privacy, Developer docs. OAuth szükséges; a directory beadás külön HTTPS privacy/support/install oldalt, angol metaadatot, brandkövetést és aláírt natív alkalmazást kér.
- Fastmail: API docs, API Terms, Developer Policy. Terjesztett klienshez a Fastmail manuálisan regisztrált OAuth-kliense kell; az app ownernek legal/support URL-t, minimum scope-ot és redirectet, a usernek hozzájárulást kell adnia.
- Twitch: Helix, EventSub, Chat, scopes, Developer Agreement. Appregisztráció, exact token/scope és broadcaster/moderator/bot szerep/hozzájárulás szükséges; a szünetelő chatbot-review nem kerülhető meg.
- Threema Gateway: Gateway API, E2E. Ez fizetett üzleti gateway, nem személyes történet API; az owner választ módot, kezeli a Gateway ID/secret/key/kreditet/callbacket, E2E-hez hivatalos SDK szükséges.
- Zoho Cliq: Cliq v3/OpenAPI, OAuth/scopes. Data-center-specifikus app/redirect és scope kell; bot/extension/function/datastore/organization műveleteket tenant role/edition/admin és publikus handler korlátozhat.
- Plurk: API 2.0. Az owner app consumer key/secret/callbacket regisztrál, a user OAuth 1.0a tokent engedélyez; modern fine-grained scope hiányában a Connect műveletkapcsolója csak kiegészítő least-privilege kapu.
- VK: API Rules, official schema. App/community, exact user/group/service tokenjog, callback vagy Long Poll és adott esetben admin/2FA/provider-engedély szükséges; token nem kerül URL-be, naplóba vagy Codexhez.
- JMAP/IMAP/SMTP/CardDAV/CalDAV: nyílt szabványok, de az exact provider/tenant terms, privacy, OAuth/app-password és retention szabálya irányadó. Minden account külön endpointot, credentialt, consentet és cursort kap; a szabvány nem provider-jóváhagyás.
- Mattermost: Privacy, Terms, Licensing, tenant legal settings. Önhostolt telepítésnél az ügyfél/tenant kezeli a végfelhasználói adatot; PAT/OAuth és AI-adathasználat admin/owner kapu.
- Matrix/Element: matrix.org Terms, matrix.org Privacy, Element Privacy, Client-Server spec. Mindig a konkrét homeserver és a federált room/bridge szabálya az irányadó; a matrix.org/Element tájékoztató nem általános minden szerverre.
- Rocket.Chat: Privacy, Terms, Customer Terms. A konkrét workspace admin/ügyfél kezeli az adatot és jogosultságot; a tenant élő API-specifikációja, role/module/edition és 2FA az irányadó.
- Zulip: Rules, Terms, Privacy. Harmadik fél multi-service kliens megengedett a szabályok betartásával; tenant owner kezeli az exportot/botot, és tilos az adatértékesítés, reklám, scraping/rate-limit megkerülés vagy hozzájárulás nélküli kontakt-újrafelhasználás.
- Nextcloud Talk: Nextcloud Privacy, Compliance, Talk API, Login Flow v2. Az instance üzemeltetőjének saját terms/privacy/retention szabálya irányadó; Talk/Login Flow/bot engedélyezése adminfeladat.
Official terms for runtime-gated and unavailable providers
The links below are mandatory sources for connection, adapter and provider/tenant review. A connection/credential profile does not mean provider approval or availability of every catalogued operation. For Mattermost, Matrix/Element, Rocket.Chat, Zulip, Nextcloud Talk, Webex, Chatwork, Toggl Track, Teamwork Projects, GroupMe, Pushbullet, Twist, Twitch and Zoho Cliq, only runtime Executable operations can run and AdapterMissing rows remain disabled. Fastmail has 41 built-in executable JMAP operations. Plurk, VK and Threema Gateway are AdapterUnavailable.
- Webex: Developer Terms, Cisco Privacy, App Hub submission. PKCE, least scopes, app privacy/terms/support, test instructions and, where applicable, organization admin/licences are required.
- Chatwork: API Terms, Terms, Privacy, API docs. In addition to OAuth/app registration, an organization-admin API application may be required except for eligible personal-plan use.
- GroupMe: API License, Privacy, Terms, Brand Standards. The API requires the
X-Access-Tokenheader; Connect will not use a query-string token. - Pushbullet: Terms, Privacy, API docs. An OAuth app and user authorization are required; EcoSynq claims neither a public app-directory review nor a universal numeric quota.
- Toggl Track: Terms, Privacy, Legal Center, API docs. Only the API token—not a password—may be used; roles, quota and webhook capacity depend on the plan.
- Teamwork Projects: Terms, Privacy, Developer Portal. An owner-company user, publisher/app Product Scope, testing, Teamwork verification/go-live and, where applicable, site-admin/paid webhook access are required.
- Twist: Doist Terms, Privacy, Developer docs. OAuth is required; directory submission separately requires HTTPS privacy/support/install links, English metadata, brand compliance and a signed native app.
- Fastmail: API docs, API Terms, Developer Policy. A distributed client needs a manually registered Fastmail OAuth client; the app owner supplies legal/support URLs, least scopes and redirects, and the user consents.
- Twitch: Helix, EventSub, Chat, scopes, Developer Agreement. App registration, exact token/scope and broadcaster/moderator/bot role/consent are required; a paused chatbot review cannot be bypassed.
- Threema Gateway: Gateway API, E2E. This is a paid business gateway, not a personal-history API; the owner selects mode and controls Gateway ID/secret/key/credit/callback, and E2E requires an official SDK.
- Zoho Cliq: Cliq v3/OpenAPI, OAuth/scopes. Data-centre-specific app/redirect and scopes are required; bot/extension/function/datastore/organization operations may be limited by tenant role/edition/admin and public handlers.
- Plurk: API 2.0. The owner registers app consumer key/secret/callback and the user authorizes an OAuth 1.0a token; without modern fine-grained scopes, Connect operation switches are only an additional least-privilege gate.
- VK: API Rules, official schema. App/community, exact user/group/service token rights, callback or Long Poll and sometimes admin/2FA/provider approval are required; a token never enters URLs, logs or Codex.
- JMAP/IMAP/SMTP/CardDAV/CalDAV: these are open standards, but the exact provider/tenant terms, privacy, OAuth/app-password and retention rules control. Every account receives a separate endpoint, credential, consent and cursor; a standard is not provider approval.
- Mattermost: Privacy, Terms, Licensing, tenant legal settings. In self-hosted deployments the customer/tenant controls end-user data; PAT/OAuth and AI data use require owner/admin approval.
- Matrix/Element: matrix.org Terms, matrix.org Privacy, Element Privacy, Client-Server spec. The exact homeserver and federated room/bridge rules control; matrix.org/Element notices are not universal to every server.
- Rocket.Chat: Privacy, Terms, Customer Terms. The workspace administrator/customer controls data and authorization; the live tenant API specification, roles/modules/edition and 2FA control.
- Zulip: Rules, Terms, Privacy. Multi-service third-party clients are permitted subject to the rules; the tenant owner controls exports/bots, and data sale, third-party ads, scraping/rate bypass and consent-free contact reuse are prohibited.
- Nextcloud Talk: Nextcloud Privacy, Compliance, Talk API, Login Flow v2. The instance operator's terms/privacy/retention rules control; enabling Talk/Login Flow/bots is an administrator task.
Provider and AI safeguards / Provider- és AI-garanciák
- Google: EcoSynq Connect's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The Google Workspace API User Data and Developer Policy also applies. This is a data-use commitment; a Connect checkbox records only a user declaration and is not technical/legal compliance proof or a guarantee. Agentic use requires in-app data/AI disclosure, affirmative confirmation of the concrete external operation, least scopes and prompt-injection protection; otherwise it must fail closed. / Az adatkezelési vállalás irányadó, de a kapcsoló nem Limited Use-igazolás; agentic használathoz alkalmazáson belüli tájékoztatás, konkrét műveleti jóváhagyás, legkisebb scope és prompt-injection védelem kell.
- OpenAI: Connect operates exclusively with one linked personal ChatGPT/Codex account. Personal ChatGPT/Codex content may be used for model training unless the user opts out. The “User-attested no-training” status records only the user's dated declaration that model-improvement data sharing is disabled in both ChatGPT and the Codex environment used; Connect cannot verify the external account controls, contract or legal/provider eligibility. Official OpenAI explanation.
- Telegram: API data is excluded from all AI/ML use under Telegram API Terms section 1.5.
- Slack: commercial distribution and AI/history access remain blocked pending a Marketplace-compliant approved architecture. Slack Marketplace requirements.
- Discord: message content is not supplied to AI without Discord's express permission. Discord Developer Policy.
- Zendesk: no bulk export, background collection, persistent index or general-model training; AI processing must be customer-directed and disclosed. Zendesk Developer Terms.
- GDPR and automated notices: processing still needs a purpose-specific legal basis, transparent recipient/processor role and a valid transfer safeguard. AI importance labels are advisory and cannot be the sole basis of a legal or similarly significant decision. Official GDPR text.
Questions / Kérdések: info@e-co-inform.hu. Independent Hungarian/EU counsel review is required before paid/general public launch. / Fizetős vagy széles nyilvános indulás előtt független magyar/EU jogi felülvizsgálat szükséges.