Privacy
Privacy Policy
Last reviewed: August 29, 2026
1. Privacy Policy
This policy explains how Personal Orchestrator handles Google data used by its private, personal-use automation features.
2. About Personal Orchestrator
Personal Orchestrator is a private/local system operated for personal use. It is not a public hosted email service. The public support site that publishes this policy is static and does not itself access Gmail, process OAuth tokens, provide a login, expose an API, or host the Personal Orchestrator runtime. The public site is informational and privacy-support content only.
3. Google Account Data We Access
The dedicated Gmail synchronization authorization requests the exact scope:
https://www.googleapis.com/auth/gmail.readonly
Depending on the feature path, the system may access Gmail message IDs, thread IDs, timestamps, system labels, Inbox/Unread/Spam state, History API records and history IDs, sender name/email, subject, bounded snippet or minimal context where required for classification, and derived classifications. The standard read-only synchronization path uses bounded metadata; the documented canonical sync and Email Intelligence state do not store full message bodies or attachments.
The separate human-approved Gmail mutation path is not part of this read-only sync authorization and uses separate controls and credentials.
4. How We Use Google Data
We use Gmail data for synchronization, classification, digest and attention features, and maintaining current mailbox state. This includes avoiding reprocessing the same messages, classifying messages into Personal Email Intelligence categories, recording concise classification history, and preparing operator-facing summaries or read-only attention signals. The system does not send autonomous email based solely on AI output. Gmail content is treated as untrusted input and cannot authorize a Gmail change.
These uses are intended to provide personal productivity features for the operator. We do not use Google data for unrelated purposes.
5. Data Storage
- Local canonical Gmail sync state is stored in a local SQLite database.
- The current n8n Email Intelligence workflow stores bounded message and run history in an operator-controlled Google Sheet.
- A local action-audit database stores metadata about explicit human-approved Gmail actions, and a local feedback database stores bounded application feedback.
- Sanitized local diagnostic logs are stored locally and are pruned after 14 days by the current implementation.
The current implementation does not define one universal retention period across these stores. The system does not store full Gmail message bodies in the documented Gmail Intelligence state or canonical sync path.
6. AI-Assisted Classification / Service Providers
Some bounded Gmail-derived information may be processed by the AI service provider configured for a particular feature. For Gmail classification, this can include sender, subject, and limited snippet/minimal context. For a local dashboard attention summary, this can include bounded derived Gmail evidence such as sender, subject, classification, and concise reason.
The current implementation has configurable provider/model paths, so this policy does not promise one permanent provider. The current verified configuration uses an OpenAI-based Gmail classification path through n8n and an OpenRouter gateway with a controlled Google Vertex route for the separate dashboard attention feature. These settings may change and will be reviewed before a material change.
The described AI paths send bounded Gmail-derived information needed for the feature, such as sender, subject, bounded snippet/minimal context, or derived classification evidence; they are not a full-mailbox export. OAuth tokens and API keys are not part of the AI input. Provider retention, training, and other processing practices are not promised here and must be reviewed when the route changes.
7. Google Cloud Pub/Sub
The standard synchronization design uses Google Cloud Pub/Sub for Gmail change notifications. The local runtime pulls notifications rather than exposing a public webhook. Notifications contain change-identification metadata such as a Pub/Sub message ID, Gmail account identifier, and history ID; they do not carry full email message contents.
8. Data Sharing
Google data may be handled by Google Gmail, Google Sheets, and Google Cloud Pub/Sub as needed for the disclosed functions; by the local n8n workflow engine; and by the configured AI service provider for bounded classification or attention processing. These are distinct transport, storage, and processing boundaries. The system does not claim that no Google-derived information is handled by third parties.
Service providers may process bounded information only as needed to provide the disclosed functionality. We do not share Google user data for unrelated purposes. Any future service provider or processing purpose that materially changes this description must be reviewed and disclosed before use.
9. Advertising and Sale of Data
Personal Orchestrator does not sell Google user data and does not use it to serve advertising, including targeted or interest-based advertising. The initial support site is static and has no cookies, analytics, advertising, or user-data collection by default.
10. Data Retention
There is no single fixed retention period for all data. Local diagnostic logs are pruned after 14 days. Other local SQLite state and Google Sheet history remain until the operator removes them or a future retention policy changes that practice. AI-provider and workflow execution-history retention depends on the enabled configuration and has not been reduced to one universal promise.
We do not promise that all data is deleted within a specified number of days.
11. Security
Personal Orchestrator is designed for local operation with separate read-only and mutation credentials, loopback-only n8n access, a local pull-based Pub/Sub consumer, secret injection through the approved credential-management path, and sanitized diagnostic logging. These statements describe the current design; they are not a certification or guarantee of perfect security. This policy does not make an unverified encryption claim.
12. Your Choices and Revoking Google Access
The Google Account owner can review or remove the app's access through Google Account third-party access and security settings. Revoking access stops future authorized Google API access by the application. Revocation does not automatically delete local SQLite state, Google Sheet history, diagnostic records, or records already created by a service provider. The current system does not provide an automatic all-store deletion operation.
For deletion or other privacy questions, contact privacy@pokebandito.com.
13. Changes to This Policy
This policy must be updated before a material change to the Google data accessed, purpose, storage, sharing, AI/service-provider route, retention behavior, or support process. Users should be prompted for any consent required by the applicable Google policies when data use changes.
14. Contact
Privacy: privacy@pokebandito.com
Support: support@pokebandito.com
15. Google API Services User Data Policy
Personal Orchestrator's use and transfer of information received from Google APIs is designed to adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable. This is factual design-intent wording, not a claim that Google has approved, verified, endorsed, or certified the application.
Reference: Google API Services User Data Policy.