Privacy policy

claude-vm · last updated 10 September 2026

This application is a personal automation tool operated by a single individual. It is not a product, not offered to the public, and has no users other than the operator. This policy describes what it does with Google user data, which in practice means the operator's own data.

1. Who operates it

A private individual, acting in a personal capacity and not on behalf of any organisation. The operator's contact address is shown on the Google consent screen for this application, which is the only place the application is offered.

2. Whose data it accesses

Only the two Google accounts the operator has personally authorised, both of which are his own. No other account can grant access, and the application does not process data belonging to any other person as a service.

3. What it accesses, and why

Each is used only to carry out a task the operator has explicitly started. The application does not run unattended scans of mailbox or drive content for any purpose beyond those tasks.

4. Where the data goes

Between the operator's own machine and Google's APIs, over TLS. Google user data is not transmitted to any third party, not sold, not shared, not used for advertising, not used to build profiles, and not used to train any machine-learning model.

5. What is stored, and where

The only credential retained is the OAuth token Google issues, held in a file readable solely by the operator's own account (chmod 600) on a machine under his control. Message and file content is processed in memory for the duration of a task; anything written to disk is written by the operator, on his own machine, as the output of that task.

6. Retention and revocation

Access can be withdrawn at any time by the operator at myaccount.google.com/permissions, which immediately invalidates the stored token. Deleting the token file has the same practical effect locally. There is no server-side copy to delete, because there is no server.

7. Limited Use

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Changes

Any change to this policy will be published on this page with a revised date above.