1. Overview
HaoClaw (the “Application”) is a privately operated application that provides approved users access to Gmail and Google Calendar features. The Application processes Google user data only to provide features requested by the authenticated user.
2. Google user data we access
Depending on the permissions a user grants, the Application may access:
- Basic account information: Google account identifier, email address, and basic profile information used to identify the connected account.
- Gmail data: message metadata, labels, sender and recipient details, message bodies, attachments, drafts, and mailbox state needed to search, read, summarize, organize, draft, send, or otherwise manage email at the user’s direction.
- Google Calendar data: calendars, events, attendees, availability, event descriptions, locations, and related metadata needed to view, create, update, or delete events at the user’s direction.
- Authorization data: OAuth access and refresh tokens needed to maintain the connection authorized by the user.
The Application requests only the permissions required for enabled features. Google’s consent screen identifies the specific scopes requested before access is granted.
3. How we use Google user data
Google user data is used solely to authenticate the connected account and fulfill user-requested features, including:
- finding, reading, summarizing, labeling, drafting, sending, or organizing email;
- checking calendars and availability;
- creating, updating, or deleting calendar events; and
- providing the user with results, confirmations, and relevant context inside the Application.
Google user data is not used for advertising, sold to third parties, used to build marketing profiles, or used by the Application operator to train general-purpose artificial intelligence models.
4. Service processing and data sharing
When an enabled feature requires language processing, the Application may send the minimum relevant portions of a request and connected Google data to the processing provider configured by the Application operator. This processing is performed only to provide the feature requested by the user.
Information may also be shared with Google to operate OAuth and the Gmail and Calendar APIs, and with infrastructure providers only as necessary to host, secure, and operate the Application. Information is not transferred to unrelated third parties except when required by law, to protect users or the service, or with the user’s explicit consent.
5. Storage and retention
OAuth credentials are stored on the host running the Application so it can maintain the connection authorized by the user. Gmail and Calendar content is generally retrieved and processed as needed for a request. Relevant content may appear in application history, operational logs, or locally stored application state, depending on the operator’s configuration.
Data is retained only for as long as needed to provide the Application, maintain security, resolve errors, or satisfy legal obligations. Following a valid deletion request, active local data associated with the requesting account will be deleted within 30 days, except where limited retention is required for security, backup integrity, or legal compliance.
6. Security
The Application uses reasonable administrative and technical safeguards designed to protect credentials and user data, including access controls, encrypted HTTPS connections, and restricted server access. No method of storage or transmission is completely secure, and absolute security cannot be guaranteed.
7. Your choices and controls
Users may decline requested permissions, stop using the Application, or revoke access at any time from Google Account permissions. Revoking access prevents future API access but does not automatically remove information already retained in local conversation history, logs, or backups.
To request access to or deletion of retained data, contact the Application administrator through the same channel by which access to this private Application was provided.
8. Google API Limited Use
The Application’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Children’s privacy
The Application is not directed to children under 13 and is not intended to knowingly collect their personal information.
10. Changes to this policy
This policy may be updated when the Application’s features or data practices change. The effective date above will be revised, and material changes will be communicated to affected users before Google user data is used for a new purpose.
11. Contact
For privacy questions or data requests, contact the Application administrator through the channel by which access to this private Application was provided.