YAO LifeOS Owner Admin Preview Privacy Notice

YAO LifeOS Owner Admin Preview Public/User Alpha. Last updated: 2026-08-18.

Google user data accessed

YAO LifeOS Owner Admin Preview requests Google access only after the user starts a connection flow and approves Google OAuth consent. The service requests only the minimum Google scope needed for the feature the user starts.

For Google Drive, the app may access metadata and content for files and folders that the user selects or that the app creates using the Google Drive scope https://www.googleapis.com/auth/drive.file.

For Google Calendar, the current public no-cost review may use https://www.googleapis.com/auth/calendar.freebusy to read availability windows for user-selected calendar context without storing raw event bodies. The app is not requesting public production approval for https://www.googleapis.com/auth/calendar.events.owned at this time; that scope is deferred until a later action-time-confirmed event-write demo and high-impact write/delete gate are ready.

Public Gmail readonly access is currently suspended. The app is not requesting public production approval for the restricted Gmail scope https://www.googleapis.com/auth/gmail.readonly at this time, and no ADA-CASA assessment has been started. If this feature is reintroduced later, access would remain limited to user-initiated, bounded workflows such as a selected Gmail thread, a user-provided Gmail reference, or a user-provided counterparty search used to find one relevant thread.

Gmail send, Gmail modify, Gmail delete, broad mailbox scanning, Calendar invitations, Calendar notifications, recurring event automation, and broad Calendar access are not part of the current public no-cost review flow.

How Google user data is used

Drive data is used to confirm a user-selected Drive root, read file metadata or content summaries, create or update LifeOS-owned test files, and create LifeOS source-pointer records that refer back to the selected Drive item.

Calendar freebusy data is used to show schedule availability context and avoid conflicts. Calendar event write access is not part of the current public no-cost review. If introduced later, it would be used only after action-time confirmation for LifeOS-owned events, and event write actions would be audited with before/after readback when enabled.

If Gmail readonly is reintroduced in a future verified release, Gmail readonly data would be used to show the user that a selected or bounded thread can be read, summarized, and converted into a LifeOS source-pointer or project-context preview. The app would not use gmail.readonly to send, modify, archive, trash, or delete email.

The current public no-cost release path does not use Gmail restricted scopes.

Gmail message body processing

For the suspended Gmail readonly flow, message body content would be read only after a user starts a bounded review action and only for the selected or user-provided Gmail thread or exchange. The body would be processed transiently to substantiate the user-facing project-context preview, sanitized summary, source pointer, and readback metrics.

Raw Gmail message bodies are not returned in public review output, committed to Git, published on public pages, or written to ordinary operational database records. If a user later saves LifeOS-managed project context, the saved record is a sanitized summary and source pointer, not the original Gmail body.

Limited Use and AI/ML processing

The use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements. YAO LifeOS Owner Admin Preview does not use raw, aggregated, anonymized, or derived Google Workspace API data to develop, improve, or train generalized or non-personalized AI or ML models.

The suspended Gmail readonly review flow does not currently transfer raw Gmail bodies to third-party AI services for generalized model training or model improvement.

Current and planned LifeOS AI processing is backend-controlled and must use providers and configurations that do not train generalized models on API payloads unless the user explicitly opts in outside this submitted Gmail review flow. The current repository configuration includes OpenAI API model-router placeholders for application features, with web search disabled for the submitted review flow. No third-party AI aggregator or model hub is used for the submitted Gmail readonly review flow. Cloudflare is used for hosting, access control, and deployment; Cloudflare AI model processing is not used by the submitted Gmail readonly review flow.

Sharing, transfer, and disclosure

YAO LifeOS Owner Admin Preview does not sell Google user data and does not use Google user data for advertising.

Google user data is not shared with other users unless the user explicitly exports or shares LifeOS-managed output. Operational access is limited to the infrastructure and service providers needed to run the app, secure the app, store encrypted tokens, host the service, and maintain audit logs. Google user data may also be disclosed if required by law or to investigate abuse or security incidents.

Google Workspace API data is not used to develop, improve, or train generalized AI or ML models.

Data protection mechanisms

OAuth token bodies are stored only in encrypted backend vault custody. Ordinary operational records store provider name, scope reference, status, root reference, source pointer, sanitized summary, audit status, and secret references instead of token bodies.

Token bodies, client secrets, raw connection identifiers, raw message bodies, raw Gmail queries, raw email addresses, and raw provider identifiers are not committed to Git and are not returned in public review pages, fixtures, or sanitized readback payloads.

The app uses HTTPS, least-privilege OAuth scopes, Cloudflare Access for protected Owner/Admin review surfaces, bounded readback endpoints, audit events, and disconnect/revoke controls. Gmail raw message body storage is denied by default; body content is processed transiently for the user-requested summary and then excluded from ordinary storage.

Retention and deletion

OAuth tokens are retained only while the user keeps the provider connection active. When the user disconnects a provider or revokes Google access, the app invalidates future provider access and removes or disables the related secret reference according to the provider connection lifecycle.

LifeOS-managed summaries, source pointers, audit records, and operational metadata are retained while the user keeps the related LifeOS project or account active, unless the user requests deletion earlier.

Users can request export or deletion of LifeOS-managed operational data at Data export and deletion. Users can request account deletion at Account deletion. Deletion requests remove LifeOS-managed data from active systems, subject to limited backup, security, abuse-prevention, and legal-retention requirements.