Last updated September 8, 2026

Privacy Policy

Appropriate Authorities is a personal AI orchestration system operated for the owner’s own use. This policy explains how the system accesses, uses, stores, and shares information, including Google user data.

Information the system may access

When the owner explicitly authorizes a supported service, Appropriate Authorities may access information needed to provide the requested function. For Gmail, the current production integration requests only https://www.googleapis.com/auth/gmail.readonly.

Depending on the task, read-only Gmail access may include message and thread identifiers, sender and recipient information, timestamps, subject lines, snippets, message bodies, authentication metadata, labels or state needed for retrieval, and attachment metadata. The current Gmail integration does not retrieve attachment file contents.

How Google user data is used

Google user data is used only to provide owner-requested functionality, such as searching for relevant messages, summarizing or classifying communications, identifying obligations, routing information to the appropriate Authority, and supplying bounded context for a task the owner has requested or previously authorized.

Email content is treated as untrusted data, not as a privileged control channel. Content from a message cannot expand system permissions, alter Authority policy, or grant credentials.

Storage and retention

OAuth refresh credentials are stored in Google Secret Manager within an isolated Email credential gateway. They are not provided to the core orchestration service, persisted in application evidence, or exposed to AI model context.

Appropriate Authorities does not maintain a general-purpose archive of complete Gmail mailboxes. The system is designed to retrieve task-relevant content on demand and minimize persisted content. It may retain bounded operational evidence, metadata, provenance, security events, obligation state, and other records necessary to perform and verify requested functions. Sensitive content may be redacted or withheld according to system policy.

AI processing and service providers

Some owner-requested functions may use AI model service providers to analyze bounded content. Google user data is sent to an AI provider only when the system’s data-handling policy permits that disclosure and the content is necessary for the requested function. The system is designed to minimize the amount disclosed, redact credential material, and withhold content when the applicable provider or account handling guarantees are insufficient.

Google user data is not sold, is not used for advertising, and is not used to train generalized AI or machine-learning models. Appropriate Authorities does not transfer Google user data except as necessary to provide or secure owner-requested functionality, comply with law, or protect against abuse or security threats.

Google API Limited Use

Appropriate Authorities’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Security

The system uses least-privilege service identities, isolated credential gateways, encrypted secret storage, private service-to-service authentication, bounded retrieval, deterministic policy checks, provenance, and security telemetry. No security control can eliminate every risk, but the architecture is designed to limit credential exposure and the consequences of untrusted content.

Revocation and deletion

The owner may revoke Google account access through Google’s account security controls. Revocation prevents future token refreshes. The owner may also request deletion of Appropriate Authorities operational records and credentials that are not required to be retained for security, legal, or system-integrity purposes.

Changes to this policy

This policy will be updated if the system materially changes how it accesses, uses, stores, or shares Google user data. The current version will remain publicly available at this URL.

Contact

Questions about this policy or the Appropriate Authorities system may be sent to rgrayav@gmail.com.