Your information

Privacy Policy

Last updated: September 2026

This policy describes the handling of information by GBB One Personal Assistant, a private personal automation application.

1. Scope

This policy applies to GBB One Personal Assistant and its informational website at gbbone.com. The application is operated by its owner for private personal use and explicitly authorized accounts. It is not a public commercial service and does not accept public registrations.

The public website describes the application. Visiting this website does not connect a Google account or grant the assistant permission to access Google data.

2. Google account information and access

The application may request authorization to access Google services needed for features explicitly requested by an authorized user. Depending on the feature and permissions granted, this may include:

  • Gmail: relevant message content, sender and recipient information, labels, and attachments when needed for an email task.
  • Google Calendar: event details, schedules, participants, and calendar information needed to manage requested events.
  • Google Drive: selected file contents, names, metadata, and folder information needed to find or organize files.
  • Google Docs and Google Sheets: document text, spreadsheet contents, and related metadata needed for requested work.
  • Google Contacts: names, email addresses, and other contact details needed for a requested action.
  • Account and authorization information: account identifiers and OAuth credentials needed to connect and distinguish authorized accounts.

Not every service or data category is accessed for every task. The actual authorization request determines the permissions granted. Permissions should be limited to implemented features and requested only when needed, rather than collected for possible future features.

3. How Google user data is used

Authorized Google data is used only as needed to perform actions or provide results requested by the authorized user. Examples include retrieving relevant emails, creating or updating calendar events, reading or organizing selected files, working with documents or spreadsheets, and finding contact information for a requested action.

A request may require sending relevant content to the configured processing services and returning the resulting answer to the authorized user's interface. Requested actions, such as sharing a file or inviting an event participant, may disclose the selected information to the intended recipients. The user remains responsible for reviewing consequential actions.

Any new data use outside the disclosed purpose requires updated disclosures and the affected user's consent before that use begins.

4. Sharing, infrastructure, and AI providers

The assistant may use third-party infrastructure, integration services, and AI or model providers configured by its owner. Relevant prompts, selected content, attachments, task results, or derived information may be processed by those providers solely as necessary to deliver functionality requested by the authorized user, with that user's consent and subject to applicable terms and privacy protections.

Depending on configuration, processing may include model inference, request routing, or retrieval and embedding services. Provider terms do not override the applicable Google data-use restrictions. Only the information necessary for a task should be included in a provider request.

Google user data is not sold, rented, used for advertising, provided to data brokers, or used to build advertising profiles.

TODO before production: confirm the complete provider and intermediary list, account types, training and human-review settings, retention and deletion controls, and processing locations. Record which providers receive Google data, including any derived text or embeddings. This draft does not assert that every configured provider has a verified no-training policy.

Google Workspace policy restricts using or transferring its user data to create, train, or improve AI or machine-learning models beyond the specific user's personalized model for an appropriate user-facing feature. Any provider route that cannot meet the applicable restrictions must not receive Google user data. Broad consent or a provider's default terms alone do not establish compliance.

Access by other people must remain limited to circumstances permitted by Google's policies, such as the user's affirmative agreement to review specific data, necessary security investigations, or legal obligations. A provider's unrelated human review is not automatically permitted.

5. Storage, retention, and deletion

Application credentials, configuration, and task-related information may be stored where necessary to operate the assistant. The deployment materials for this application describe owner-controlled storage of conversation sessions, attachments, preferences, and persistent memories. Task information may therefore remain after a response is delivered.

Retention depends on the active configuration and the services involved. This policy does not promise a fixed deletion period or immediate removal from backups. The owner must verify whether Google content or derived information enters conversation history, logs, archives, memory, or retrieval indexes, and apply the relevant Google API storage and caching restrictions. Configuration is not permission to retain Google data indefinitely.

OAuth credentials must be protected as secrets and kept out of public website files and repositories. Revoking Google access prevents future authorized access through the revoked grant; it does not automatically erase copies already stored by the application or providers.

The authorized user can ask the owner to disconnect an account and remove its stored credentials, task records, attachments, and derived memory or index entries where applicable. Deletion from provider systems and backups depends on available controls, applicable service requirements, and any legal obligations. Original data in Google services is not deleted merely by disconnecting the assistant.

TODO before production: confirm the actual retention and deletion process for all of these storage locations, including provider logs and backups.

6. Security

The application is intended to use safeguards appropriate to its private use, including restricted access, protected OAuth credentials, limited permissions, and secure connections. The owner is responsible for maintaining the host, integrations, and provider settings and for checking that data is protected in transit and at rest as required by applicable Google policies.

No system or transmission method can guarantee perfect security. This policy does not claim that an independent security assessment has been completed. The public informational website does not handle OAuth tokens or account authorization callbacks.

7. Your control

An authorized user can decline a permission request, stop using the assistant, or revoke its access from Google Account third-party connections. Select the application's connection and follow Google's instructions to remove access.

After access is revoked, features relying on that authorization will no longer be able to make new authorized requests unless access is granted again. For deletion of previously stored application information, contact the owner using the address below.

8. Google API Services and Limited Use

The Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their applicable Limited Use requirements, govern the application's handling of information received from Google APIs.

These requirements cover permitted user-facing uses, transfers, human access, and prohibited uses, including applicable restrictions on AI training. They also apply to relevant data derived from Google user data.

TODO before production: validate the configured application and all providers against these requirements. Only after that review should this draft be finalized with the affirmative commitment: “GBB One Personal Assistant's use of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.”

9. Website visits and contact messages

This static website contains no analytics, advertising, tracking scripts, third-party fonts, or application cookies. Its hosting provider may process ordinary connection information, such as IP addresses and request details, to deliver and secure the site. This differs from accessing data through Google APIs.

If you email the contact address, the owner and the email delivery providers process your message and reply details to handle your request. The contact address forwards messages through Cloudflare Email Routing to the owner's mailbox. Do not send passwords, OAuth tokens, or other account secrets.

10. Changes and contact

This policy may be updated as the application or its integrations change. The latest version will be posted here with a revised update date. Material changes to the use of Google data require notice and any consent required by Google's policies before the new use begins.

For privacy questions, access concerns, or deletion requests, contact the application owner at webmaster@gbbone.com.