Reid Google Data Privacy Policy

Last updated: September 2, 2026

This policy explains how Reid AI Chief of Staff (“Reid”) accesses, uses, stores, protects, and deletes information received through Google APIs. Reid is a private personal assistant operated by Wess Burgner and is not offered as a public service.

Google Data Reid Accesses

Depending on the permissions authorized through Google’s consent screen, Reid may access:

  • Google account identity information needed to confirm the authorized mailbox

  • Gmail message identifiers, sender and recipient headers, dates, subjects, snippets, and bounded plain-text content from messages specifically searched or selected by the authorized user

  • Attachment filenames, without downloading attachment contents

  • Google Calendar event information

  • Google Tasks lists and task information

For Gmail, Reid uses only gmail.readonly and gmail.send. Reid does not request permission to delete or modify email, manage labels, access contacts or Google Drive, or download attachments.

How Google Data Is Used

Google data is used only to provide features requested by the authorized user, including:

  • Searching and summarizing selected email

  • Reading a selected message

  • Sending a new email to a preapproved recipient after an explicit request

  • Viewing or managing authorized calendar events

  • Viewing or managing authorized Google Tasks

Reid does not automatically monitor the Gmail inbox, automatically reply or forward, follow instructions contained inside email, open links, render email HTML, or use email content to authorize other actions.

Email content and metadata are treated as untrusted data.

AI Processing and Service Providers

When the authorized user asks Reid to work with selected Google data, relevant portions may be processed through the OpenAI API to generate the requested response. OpenAI states that API data is not used to train its models by default unless the customer explicitly opts in. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring unless different approved data controls apply.

Reid may also use infrastructure providers, including Railway for application hosting and Cloudflare R2 for encrypted off-site backups. These providers are used only to operate, secure, and preserve Reid’s authorized functionality.

Google user data is not sold, rented, used for advertising, or used by Reid to train or improve a generalized artificial-intelligence model.

Storage and Retention

OAuth credential and token files are stored separately in protected locations and are excluded from Git and unencrypted application backups.

Selected Google data may appear in Reid’s durable conversation history when needed to answer the authorized user’s request. That history may be included in authenticated, encrypted backups for continuity and disaster recovery. Encrypted off-site backups are retained until the owner manually deletes them.

Reid does not create a separate permanent copy of the entire Gmail mailbox and does not automatically poll or archive the inbox.

Security

Reid uses restricted OAuth permissions, protected credential files, HTTPS connections, authenticated encryption for off-site backups, recipient restrictions for outgoing Gmail, bounded email reads, and controls designed to prevent email content from authorizing tools or actions.

No security system can guarantee absolute protection, but reasonable technical and operational safeguards are used to prevent unauthorized access, disclosure, alteration, or destruction.

Sharing and Human Access

Google user data is disclosed only:

  • To service providers necessary to operate Reid

  • At the direction of the authorized user

  • When required for security, fraud prevention, legal compliance, or protection of rights

Human access is limited to the authorized owner and, when strictly necessary, authorized service-provider personnel operating under applicable confidentiality and security obligations.

User Control and Deletion

The authorized user may revoke Reid’s Google access at any time through Google Account security settings:

https://myaccount.google.com/permissions

Revoking access prevents future Google API access but does not automatically erase information already stored in Reid’s conversation history or encrypted backups.

The authorized user may request deletion of stored Google-derived conversation data, OAuth tokens, and associated backups through the support contact shown on Reid’s Google OAuth consent screen. Deletion requests will be handled subject to legitimate security, legal, and backup-integrity requirements.

Google Limited Use Disclosure

Reid’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements:

https://developers.google.com/terms/api-services-user-data-policy

Changes to This Policy

This policy will be updated before Reid materially changes how it accesses, uses, stores, or shares Google user data. The authorized user will be notified and asked to provide any required new consent before materially different use begins.