HomeOps
Privacy Policy
Effective: 13 September 2026
1. Scope and operator
HomeOps is a private, personal-use household operations assistant operated by its project owner. It is not offered to the general public. Questions about this policy can be submitted through the HomeOps site repository.
2. Google user data accessed
With the user's explicit OAuth authorization, HomeOps may access:
- Gmail message metadata and bounded message content using read-only access;
- Google Calendar lists and events using read-only access; and
- events owned by the user for an explicitly approved create or update operation.
HomeOps does not use Gmail permission to send, delete, label, or modify messages. It does not delete Google Calendar events.
3. How Google user data is used
Google user data is used only to:
- identify possible household obligations, deadlines, and event proposals;
- compare proposed events with existing calendar state;
- show the owner a reviewable summary; and
- perform and verify a calendar change that the owner explicitly approved.
Google user data is not used for advertising, credit decisions, surveillance, or sale to third parties.
4. Processing and disclosure
The authoritative HomeOps database runs locally on the owner's computer. HomeOps may transmit only the data needed for a feature to the following processors:
- Google APIs, to read authorized Gmail and Calendar data and to perform an approved Calendar operation;
- OpenAI API, to classify bounded, normalized, untrusted email or attachment-derived text and produce a non-authoritative proposal; and
- Telegram Bot API, to deliver operational summaries and receive review choices in the owner's private chat.
HomeOps does not grant these processors authority to approve household actions. It does not transfer Google user data to data brokers or sell it.
5. Storage and security
- Operational records are stored in a local PostgreSQL database.
- Google OAuth tokens are encrypted for the current Windows user and stored outside the source repository.
- Database recovery points are encrypted before being written to backup storage.
- Incoming email and derived content are treated as untrusted evidence and cannot directly authorize actions.
- Calendar writes require a separate least-privilege token, an exact action request, local Windows Hello confirmation, and post-write verification.
6. Retention
Eligible Gmail content is compacted after 90 days by removing stored titles, summaries, message bodies, and derived attachment content. Minimal identifiers, timestamps, provenance, and audit records may be retained to prevent duplicate processing and preserve system integrity. Content connected to an unresolved obligation is retained until it is safe to compact. Encrypted recovery points retain older state only until their normal bounded backup retention expires.
7. User control and deletion
The user can revoke HomeOps access at any time from the Google Account permissions page. The project owner can also delete the local OAuth token files, local database records, and encrypted recovery points. Revocation prevents new access but does not itself erase already stored local records.
8. Google API Services User Data Policy
HomeOps' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes
Material changes to this policy will be published on this page with a new effective date before the changed processing is used.