Privacy Policy

artie-ops-assistant. Last updated: 5 September 2026.

1. Summary

artie-ops-assistant is a single-user, self-hosted personal assistant. It is operated by one individual, on their own hardware, for their own Google account only. It is not a service offered to others, it has no other users, and it collects no data from anyone other than its operator. This policy exists because Google requires a published privacy policy for applications requesting access to Gmail data.

2. Who operates this application

This application is operated by a private individual in the United Kingdom. Contact: harlequinht@gmail.com. For the purposes of UK GDPR, the operator is the data controller. The operator is the only user of the application. However, the application necessarily processes limited personal data belonging to people who send mail to the operator's inbox, as described in section 5 below. The lawful basis for that processing is legitimate interest in managing the operator's own correspondence.

3. What the application does

The application monitors a single Gmail inbox belonging to its operator, assigns each new message to a category (for example: enquiry, admin, action needed), and sends the operator a notification through a private messaging channel when a message appears to require attention. It is a triage and notification tool.

4. What Google data it accesses

5. What is stored, and where

All storage is local to a single machine under the operator's physical control. Nothing is stored on a hosted server, and there is no cloud database, no aggregated data store, and no queryable archive of message content.

6. Third parties

Two third-party services are involved in normal operation. No other third party receives any data, and no data is sold, rented, traded, or used for advertising by the operator under any circumstances.

7. Google API Services User Data Policy

artie-ops-assistant's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through Google APIs is used only to provide the triage and notification features described above, is not transferred to others except as necessary to provide those features or as required by law, is not used for advertising, and is not read by any human other than the operator.

8. Retention

Classification records, including the sender address, subject line and message excerpt described in section 5, are retained on the local machine for as long as the system is in operation, and are deleted when the operator removes them or decommissions the machine. Activity log entries are retained on the same basis. OAuth tokens persist until revoked or replaced. All of this data is held on a single machine under the operator's physical control and is not replicated elsewhere.

9. Security

Credentials are held in files with owner-only permissions on a machine under the operator's physical control, and are not committed to any code repository. Access to the notification channel is restricted to the operator's own account. Credentials are rotated when there is reason to.

10. Rights and revocation

The operator may revoke this application's access to their Google account at any time at myaccount.google.com/permissions, which immediately ends all data access.

Anyone who has sent mail to the operator's inbox may request access to, correction of, or erasure of the records described in section 5 that relate to them, by writing to the contact address below. Requests are handled directly against the local files, and there is no other copy to reach.

11. Changes

Material changes to this policy will be published on this page with an updated date above.

12. Contact

harlequinht@gmail.com