Privacy Policy
Effective 27 August 2026
Purpose and scope
Britannia AI Agent Dev is a personal-use development application restricted to one approved Google account. This policy explains how the application handles Google account data, Gmail data, and Calendar authorization when that user connects the application.
Data accessed
The application requests only:
- basic Google identity information: account identifier, email address, and profile;
- Gmail read-only access to search and read messages and threads;
- read-only access to events on calendars owned by the approved user, intended for bounded event-window reads from that user's primary calendar.
The application does not request permission to create drafts, send email, modify messages or labels, change events, or delete Gmail or Calendar data. Calendar runtime is not yet enabled, and the application has not performed a live Calendar API read.
How data is used
Google identity data is used to authenticate the approved user and link that identity to the user's Discord account. Gmail data is accessed only to fulfil an explicit request from that user, such as searching for or summarising email.
Calendar authorization is intended to support explicit, bounded requests to view events on the approved user's owned primary calendar. Because that runtime feature is not yet enabled, Calendar event data is not currently accessed or used.
When the user requests an AI-generated answer or summary, limited email excerpts needed for that request may be sent to the configured model service, currently Google Cloud Agent Platform, solely to generate the requested result. Gmail data is not sold, used for advertising, or used by this application to train general-purpose AI models.
Data stored
- Google and Discord account-link identifiers;
- the approved Google email address and granted OAuth scopes;
- an encrypted OAuth refresh token;
- security and operation audit events.
Gmail search text, sender and recipient addresses, subject lines, and message bodies are not stored in audit records. Raw Gmail message and thread identifiers are not stored in audit records. The application does not persist Gmail message bodies in its application database. No Calendar event data is currently accessed or stored. This policy will be updated before Calendar runtime is enabled if its storage or retention behaviour changes.
Retention and deletion
Gmail audit events are retained for up to 90 days. Account-link and encrypted credential data are retained while the connection remains active. The user can request deletion using the support email displayed on the Google OAuth consent screen.
Security
OAuth refresh tokens are encrypted before storage. Access is restricted to the approved account, Gmail and Calendar permissions are read-only, and sensitive tokens are not placed in application logs or this public website. No security measure can guarantee absolute protection, but the application uses least-privilege access and limits stored data.
Sharing
Data is not sold or shared for advertising. Data is disclosed only to service providers necessary to operate an enabled user-requested feature, including Google OAuth, Gmail API, and the configured model service, subject to their applicable terms and privacy commitments. Calendar event data is not currently sent to a model service.
Your controls
The user may revoke access at any time through Google Account connections. Revocation prevents future Gmail and Calendar access. The user may also contact the developer through the support email shown on the OAuth consent screen to request deletion of locally stored account-link and credential data.
Changes
This policy will be updated before Calendar runtime is enabled, before the application requests broader Google permissions, or before it materially changes how Google user data is handled.