Privacy Policy for Private Briefing Reader
Last updated: September 1, 2026
Private Briefing Reader is a private, single-user integration operated solely for its authorised owner's Google account. It is not a public application and does not accept other users.
Google user data accessed
The integration requests only these read-only permissions:
- Read Gmail messages, threads, headers, and attachment metadata.
- Read the list of calendars visible to the authorised account.
- Read calendar events and their details.
It does not request permission to send, delete, archive, label, or modify email, and it cannot create, update, delete, or respond to calendar events.
How Google user data is used
Data is retrieved only when the owner or an authorised scheduled task requests a briefing. It is used to identify action-required email, important information, a short summary of newsletters and notifications, and the owner's calendar for the requested period.
Storage and security
- The OAuth credential is stored separately from the application on a restricted server account and is not included in source code.
- The integration does not maintain a database or cache of Gmail message bodies or Calendar event content.
- Operational logs exclude email bodies, calendar descriptions, OAuth tokens, and other message or event content.
- The reader is reachable from the authorised workspace through a private outbound-only secure tunnel; it has no public MCP endpoint.
Sharing and transfer
Google user data is transmitted only to the service providers necessary to perform the owner's requested briefing: Google APIs, the private hosting environment, the secure tunnel provider, and the owner's authorised OpenAI/ChatGPT workspace. Data is not sold, used for advertising, or shared with unrelated third parties.
Retention and deletion
The integration does not persist retrieved email or calendar content. Generated briefing content is retained only according to the owner's OpenAI/ChatGPT workspace settings. The owner can revoke the integration at any time from Google Account security settings. The server-side OAuth credential and configuration can also be deleted on request.
Google API Services User Data Policy
Private Briefing Reader's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.
Contact
To ask a privacy question, revoke access, or request deletion of the stored OAuth credential, email ngkoil@ngkoil.com.