Trust & control

Concierge Privacy Policy

Last updated: 26 August 2026

A. What Concierge is

Concierge is a private, user-directed AI operator. It helps you work with services that you explicitly connect and authorise.

B. Google data Concierge may access when authorised

Depending on the scopes you explicitly authorise, Concierge may access categories including:

  • Gmail messages, drafts, labels and metadata
  • Drive files and file activity
  • Docs, Sheets and Slides content
  • Calendar events
  • Contacts and Tasks
  • Forms and responses where authorised
  • Meet information where authorised
  • YouTube account, channel information and analytics where authorised

Access depends on the scopes you explicitly authorise and the functionality you request.

C. How Google data is used

Google data is used only to perform user-directed functionality, such as searching, reading, summarising, preparing content, organising, creating or updating content, and sending or publishing when explicitly requested and approved where required.

D. AI processing

Relevant portions of Google user data may be processed by configured AI service providers only when necessary to fulfil a user-directed Concierge request.

The purpose of that processing is solely to provide the requested user-facing feature.

Concierge does not use Google Workspace user data to train, develop, or improve general-purpose or foundation AI models.

E. Data storage

OAuth credentials and tokens may be stored securely on the private Concierge server. Google content should not be permanently copied by default. Temporary processing or cache storage may occur only as necessary to fulfil a user request.

Operational or audit records may store limited metadata about actions and approvals. Full Google content should not be retained in audit records by default.

F. Data sharing

Google user data is not sold or shared for advertising, marketing lists, data brokerage, lending, or creditworthiness.

Transfers to configured processors or service providers may occur only where necessary to provide a user-requested Concierge feature.

G. User control

You can stop using a connected Google service, revoke Concierge access through your Google Account permissions, and request deletion of locally stored OAuth credentials and related retained data.

H. Security

Concierge uses HTTPS, access controls, private credential storage, least-privilege design where practical, and explicit approval controls for consequential actions. No security measure can promise absolute security.

I. Google Limited Use disclosure

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

J. Contact

For privacy or data-access enquiries, please use the developer contact information associated with the Concierge Google OAuth application.

K. Last updated

26 August 2026