Privacy policy
This policy covers every app that signs in with Google under the gantree name: the ai-gantry agent, the gantry-pendant web app and mailbox, and the gantry-cab (Android) and gantry-helm (iPhone) apps. All of it is open-source, self-hosted software. Each copy is run by one person (the operator) on hardware or a Cloudflare account they control. The developer does not operate a server that receives, stores, or can see your Google data.
Signing in (pendant, cab, helm)
Sign in with Google is used only to identify you. The apps request your Google account id, email address, and basic profile. The mailbox keeps your account id and email to decide which room you may join, and the operator's agent keeps the same in its allowlist. Nothing else from your Google account is read by signing in.
What Google data the agent accesses
Only when the operator connects a Google account to the ai-gantry agent, and only within the scopes shown on the Google consent screen at that time. Depending on the operator's configuration this can include:
- Gmail messages, threads, labels, and drafts; sending mail.
- Calendar events and free/busy information.
- Tasks and task lists.
- Contacts (People API).
- Drive, Docs, and Sheets files.
- YouTube subscriptions, playlists, and watch data (if connected separately).
- Google fitness and health data (if connected separately).
- Basic profile (email address) to identify the connected account.
Other connected accounts
The operator may also connect non-Google accounts. The same rules in this policy apply to them:
- Strava โ activities, routes, and athlete stats, via Strava's OAuth.
- Garmin Connect โ sleep, steps, heart rate, and workouts. Garmin has no public OAuth for this data; the operator supplies their own Garmin login on their machine and the resulting session is stored there. Garmin credentials are never sent to the developer or pasted into chat.
How it is used
Data is read or changed only in direct response to a request from the operator (or an allowlisted user the operator configured), or a scheduled task the operator set up. Examples: "what's on my calendar today", "find the email from the dentist", "add this to my tasks".
To answer, the relevant content (for example an email body or a list of events) is sent to the large-language-model provider the operator configured (for example Google Gemini, OpenAI, or a model running on the operator's own hardware). That provider processes it under its own terms and privacy policy, which the operator chose. ai-gantry does not send Google data anywhere else.
Storage
- OAuth tokens (access and refresh tokens) are stored as files on the operator's machine. They are not transmitted to the developer.
- Google content is held in memory while a request is answered. The operator may enable local chat history, in which case replies that quote Google content are kept on the operator's machine.
-
The OAuth redirect page at
shotah.github.io/ai-gantry/oauth-catch/is static HTML shared by the Google, Google Health, and Strava connections. It displays the one-time authorization code from the URL and stores nothing; no server receives it.
Sharing and sale
Google user data is never sold, never used for advertising, and never shared with third parties other than the operator-configured model provider described above.
Limited Use
gantree's (including ai-gantry, gantry-pendant, gantry-cab, and gantry-helm) use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention
- Google content fetched to answer a request is discarded when the request completes, except where the operator enabled local chat history, which keeps the agent's replies (and any Google content quoted in them) on the operator's machine until the operator deletes it.
- OAuth tokens are kept until revoked or until the operator deletes the token files.
- Sign-in records (account id and email) in the mailbox and allowlist are kept until the operator removes the user.
Revoking access and deleting data
- Revoke at any time from myaccount.google.com/permissions. The stored refresh token stops working immediately.
- Delete the token files on the operator's machine (the agent's data directory) to remove local credentials; delete chat history there if it was enabled.
- Ask the operator to remove you from the mailbox and allowlist to erase your sign-in record.
Children
The software is not directed at children under 13 and the developer does not knowingly collect data from them. Operators decide who they allowlist.
Changes to this policy
This page is versioned with the source code in the ai-gantry repository. Material changes update the effective date above.
Contact
Questions about this software: open an issue at github.com/shotah/ai-gantry/issues. Questions about a specific running instance go to the person who operates it.