Operator and service identity
Do You Have AI operates the service identified above. Forge is its private AI operations system, used to help the owner perform authorized work across connected business tools. This policy applies to Google user data accessed through that work.
Google data access
Google access begins only after a user completes Google's authorization flow. The intended integration family may include Gmail, Calendar, Contacts, Drive, Docs, and Sheets, but that list does not claim every service is enabled in production.
Services and data categories the integration may request
Gmail: message content, headers, labels, and delivery metadata used to read, organize, update, and send email for user-enabled work; Google Calendar: calendar and event details used to review, create, update, or remove events for user-enabled scheduling work; Google Drive: file names, metadata, content, and permissions used to find, read, create, update, share, download, or remove files when the user enables those tasks; Google Docs: document content and structure used to read, create, and edit documents for enabled work; Google Sheets: spreadsheet content and structure used to read, create, update, and append data for enabled work; Google Contacts/People: contact names, email addresses, and phone numbers used to look up contacts for enabled work
How Google data is used
Authorized information is used only to perform the user-enabled business tasks associated with the requested permissions. Requested permissions are limited to the services and data categories listed above and the work the user enables.
Storage and security
Token and Google-data storage: OAuth client credentials and access or refresh tokens are stored in files on the computer running Forge. Google data retrieved for a task may appear in Hermes tool output and conversation history stored on that computer, and may be saved to local files when the task requires it. No additional service-specific database is used beyond Hermes session and history storage. Credential files are not published with this site; access relies on the host computer's account and filesystem controls.
Retention and deletion
OAuth tokens remain on the Forge computer until access is revoked or the local credential file is deleted. Google data included in Hermes sessions or saved files remains until the relevant local session or file is deleted under the operator's normal cleanup process; no fixed retention period is currently promised. A user may request deletion at the support address. Revoking access stops future Google API access but does not automatically erase existing local session history or files.
Revocation and account controls
Users can review or revoke app access at any time through their Google Account connections. Revoking access prevents future API access. Deletion of information already retained follows the retention and deletion process above.
Google API Services User Data Policy and Limited Use
Do You Have AI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements where applicable.
Changes to this notice
This notice will be updated when the service's data practices change. Where a material change requires renewed authorization or consent, it will be obtained before the changed use begins.
Privacy and support contact
Send privacy, access, revocation, or deletion requests to forge@coronado-phx.com.