O++

Public privacy notice

Privacy and Google Workspace data use

This notice explains what O++ accesses when you connect Google Workspace, why it accesses that data, where it goes, how long it remains, and how to revoke access or request deletion.

Last updated: August 8, 2026

At a glance: O++ uses read-only Google permissions after you connect an account and request a task. It does not sell Google user data, use it for advertising, or use it to train or improve generalized or foundation AI models.

Google data O++ requests

O++ asks for the following Google OAuth scopes. The connection is optional, and O++ cannot send or delete email, edit Drive files, or change sharing.

Search and read operations are bounded by item and byte limits. O++ does not continuously scan a mailbox or Drive in the background.

Why and how the data is used

O++ accesses Google Workspace only after the signed-in user connects Google and initiates an agent task that needs Gmail or Drive. It uses the selected content to search, retrieve, summarize, answer the user's request, and—only when the user asks to save knowledge—capture a bounded excerpt with provenance.

For a user-initiated Google-assisted agent task, O++ sends the task prompt and bounded source content needed for the request to OpenAI Codex using the user's configured OpenAI API credential. If the user asks O++ to retain knowledge, a later Codex curator and reviewer may process that retained assertion and evidence. Google OAuth tokens are never sent to OpenAI or exposed to the model or shell.

Google API Limited Use. O++'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and retention

Google credentials

O++ stores the Google refresh credential in a tenant-and-user-scoped Google Cloud KMS-encrypted envelope in a separate credential database. A short-lived access token is released only to an in-process broker for the requested read. Tokens are excluded from model context, shell commands, job results, evidence, artifacts, and application logs.

Job results and artifacts

A Google-assisted job result may retain a model response capped at 24 KiB and server-verified Google excerpts capped at 8 KiB per source and 24 KiB total, together with source identifiers, timestamps, hashes, and provenance. Current O++ job records do not automatically expire; they remain in the private job database until they are deleted under an operator-approved request. Cloud artifact objects use a 90-day live-object deletion lifecycle, while versioning, soft delete, and backup controls may preserve recoverable copies for a limited additional period.

Optional knowledge

Google content is not stored as durable O++ knowledge unless the user explicitly invokes knowledge_add or asks the agent to remember it. That action stores the assertion and bounded evidence in the user's private tenant-and-subject knowledge space and may materialize reviewed knowledge in a tenant-private GitHub repository. Knowledge records intentionally have no automatic session expiry and remain until an authorized deletion or correction process removes them; point-in-time recovery and backups may temporarily retain earlier versions.

Service providers and sharing

O++ transfers data only as needed to provide the feature the user requested:

O++ does not sell or broker Google user data; use it for advertising, retargeting, credit, or lending; or use raw or derived Google Workspace data to train or improve generalized or foundation AI or machine-learning models. Service providers process data under their own applicable agreements and privacy terms.

Revoke access and delete data

Use the O++ google_workspace_disconnect action to disconnect Google Workspace. O++ first asks Google to revoke the refresh credential and deletes its encrypted copy only after revocation is confirmed. If Google cannot confirm revocation, O++ retains the encrypted credential so the user can retry safely. A user may also revoke O++ in Google Account permissions to stop future Google API access.

Disconnecting removes the Google authorization credential; it does not automatically delete prior bounded job results or optional knowledge. To request deletion of a stored connection, job data, Google-derived evidence, or knowledge records, email eng@syntropi.ai from the account associated with O++. O++ will verify the requester and the records in scope before deletion. Recovery systems may retain deleted or superseded copies for their configured recovery window.

Security and contact

O++ separates customer credentials, job data, and private knowledge; scopes access by authenticated tenant and user; encrypts Google refresh credentials with Google Cloud KMS; and gives a job only a short-lived access token behind a bounded read-only broker. No internet service can guarantee absolute security, so users should connect only the Google account and content appropriate for the requested task.

Questions, privacy requests, or security concerns: eng@syntropi.ai.

Material changes to Google data access, use, storage, or sharing will be reflected on this public page with an updated date.