← Gbrain

Privacy Policy

Effective September 3, 2026

Scope

This Gbrain deployment is a private, single-user application operated by Matthew Thompson for Symmetric Development Services and the operator's own accounts. It is not offered to the public.

Google data accessed

With the operator's consent, Gbrain reads Gmail messages, threads, labels, and metadata; Google Calendar calendars, events, and attendee information; Google Contacts; and the account's email identifier. Access is read-only. The application does not request Google Drive access and cannot send email, modify calendars, or edit contacts.

How data is used

Google data is used only to build the operator's private searchable knowledge index, retrieve business and personal context, and surface commitments or follow-ups. Gmail sources use configured positive signals and deterministic rejection rules to limit ingestion to relevant correspondence and exclude spam, trash, bulk marketing, social or forum mail, mailing-list mail, calendar-system notices, and automated noise. A thread may remain relevant when the operator substantively participated in it.

Imported content and derived text may be sent to the operator-configured OpenAI API to create search embeddings or perform model inference, including summaries and recent-mail commitment extraction. This processing is limited to providing the Gbrain features requested by the operator. Google Workspace API data is not used to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.

Storage, sharing, and retention

Imported and derived data is stored in systems controlled by the operator, including an access-restricted local computer and private databases or repositories. Google user data is not sold, used for advertising, shared with data brokers, used to determine creditworthiness, or disclosed to unrelated third parties. OpenAI and infrastructure providers process data only as needed to operate the features and storage described in this policy. Imported and derived records are retained until the operator deletes them.

Security and access

OAuth credentials are stored in access-restricted local storage. Application access is limited to the operator's authenticated devices and accounts. Network connections to Google, OpenAI, and private hosted infrastructure use HTTPS.

Google API Limited Use

Gbrain's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revocation and deletion

The operator may revoke access at any time from Google Account security settings. Revoking access or disconnecting an account stops future access and removes the stored OAuth authorization, but it does not automatically delete previously derived records; the operator may delete those records from the private knowledge system separately.

Contact

Questions about this policy may be sent to matthew@symmetricproperties.com.