PAI Coach

Privacy Policy

Effective 4 September 2026 · Last updated 4 September 2026

PAI Coach ("the application") is a private, self-hosted personal automation tool operated by a single individual ("the operator") for their own use. It is not offered to the public, has no user accounts, and processes no other person's data.

1. Who this policy covers

The only person who authorizes PAI Coach, and the only person whose data it touches, is the operator. If you are reading this because you were shown a Google consent screen, that consent screen was shown to the operator's own Google Account.

2. What Google user data the application accesses

With the operator's explicit OAuth consent, the application requests these Google API scopes:

No other Google scopes are requested. The application does not access Drive, Photos, Contacts, Calendar, location, or any Google product beyond Gmail and Google Tasks as described above.

3. How that data is used

Solely to provide the features the operator asked for: keeping the mailbox organized, sending mail the operator composed or approved, and keeping one task list consistent across devices. The data is not used for any other purpose.

Limited Use disclosure

PAI Coach's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: data obtained through Google APIs is not sold, not transferred to third parties, not used for advertising, and not used to develop, improve, or train generalized artificial intelligence or machine learning models. No human reads this data other than the operator, whose data it already is.

4. Where the data is stored

The application runs on hardware the operator physically controls. Data retrieved from Google is written to local storage on that machine and to a private, access-controlled backup of that machine's configuration. There is no hosted backend, no third-party database, and no cloud service that receives this data.

OAuth credentials and refresh tokens are stored locally with owner-only file permissions and are never transmitted anywhere except to Google's own authentication endpoints.

5. Sharing

None. Google user data is not shared with any third party, service provider, advertiser, analytics vendor, or model provider. The application performs no analytics and sets no cookies.

6. Retention and deletion

Locally cached Google data is retained only as long as it is useful to the operator and is deleted on request or when the relevant feature is retired. Because the operator is the sole data subject, deletion is performed directly by the operator on their own machine.

Revoking access

Access can be withdrawn at any time from myaccount.google.com/permissions. Revoking access immediately invalidates the application's tokens; any locally stored copies are then deleted by the operator.

7. Security

Credentials are held in owner-only files on an access-controlled machine and are excluded from version control by an automated pre-commit guard. Tokens are transmitted only over HTTPS and only in request headers, never in URLs. The application requests the narrowest scopes that let it do its job.

8. Children

The application is not directed to children and is used by one adult operator.

9. Changes to this policy

Material changes will be reflected on this page with an updated effective date.

10. Contact

[email protected]