Privacy policy
This policy explains how the private Horizon General Assistant accesses, uses, stores, and shares Google user data.
Scope and user
This is a self-hosted, personal-use application for its owner. It is not offered to the public and does not maintain accounts for other users.
Google data accessed
After explicit Google OAuth consent, the application uses the Gmail read-only scope. It may access the authorized account address, Gmail synchronization history, message identifiers, labels, headers, body text, calendar-invitation content, attachment names, timestamps, and original message bytes.
Initial activation begins at the current Gmail history position. Earlier messages are not imported unless the owner separately chooses and authorizes a historical import.
How Google data is used
The application uses Gmail data to identify new messages that may require action or contain information relevant to the owner. It can ask the owner a focused question and, after the applicable decision, preserve a copy in the owner's private mail system. It also keeps local identifiers, hashes, decisions, and delivery receipts to prevent duplicate processing and support corrections.
The Gmail integration does not send mail or alter Gmail messages, labels, read state, folders, or deletion state.
Storage and retention
Operational records and approved message copies are stored on systems controlled by the owner. OAuth client and refresh credentials are stored in an encrypted credential database accessible only to the trusted service adapter. Model-facing agents do not receive those credentials.
Excluded message content is not retained as a mailbox copy. Minimal audit records may be retained to explain a decision and prevent duplicate processing. Approved local copies and related records remain until the owner deletes them under the retention rules of the destination system.
Sharing and external processing
Selected message headers and a bounded portion of message text may be sent to OpenAI's ChatGPT service when language reasoning is needed. The entire mailbox is not sent to OpenAI for classification. Google user data is not sold, used for advertising, or shared with unrelated parties.
Use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Security
The integration uses least-privilege service identities, encrypted credential storage, fixed source and destination accounts, bounded model context, and auditable receipts. Email content is treated as untrusted data and cannot expand permissions, reveal credentials, send replies, or create personal commitments by itself.
Control and revocation
The owner can disable polling or the destination independently, revoke the application's Google access from the Google Account connections page, and request deletion of locally stored copies and records through the local systems that hold them. Revocation stops future access but does not automatically delete copies the owner previously chose to retain.
Changes
This page will be updated before the application uses Google data for a materially different purpose. A new consent decision will be requested when required.