Effective 8 September 2026

Privacy Policy

This policy explains how the current private Guidance deployment handles personal data.

Scope

Guidance is a privately operated, local-first life planning application. The application currently runs on the owner’s Mac and is not available as a public hosted service. This public website provides product and privacy information required for transparent Google OAuth authorization.

Google API data

When the user connects Google Calendar, Guidance requests the calendar.readonly permission together with basic identity permissions. Guidance uses this access to:

Guidance does not use Google user data for advertising, credit decisions, surveillance, or sale to data brokers. Its use of Google API data follows the Google API Services User Data Policy, including the Limited Use requirements.

Storage and security

OAuth access and refresh tokens, selected calendar identifiers and sync status are stored in the private PostgreSQL volume of the local Guidance installation. Calendar events are fetched from Google when needed and are not maintained as a separate long-term mirror by the current implementation. Access is limited to the authenticated Guidance user.

The public website does not receive Google Calendar data. Guidance does not add advertising trackers or analytics cookies to this website. Cloudflare may process ordinary connection metadata when serving these static pages under its own privacy terms.

AI-assisted features

If the user invokes an AI feature that needs schedule context, relevant calendar information may be included in the request sent to the AI provider selected in the private installation. The current primary provider is configured to deny data collection and request zero data retention; the local fallback runs on the owner’s computer. AI access is used only to provide the feature requested by the user.

Sharing

Guidance does not sell personal or Google user data. Data is shared only with service providers needed to operate a user-requested feature, such as Google for OAuth and calendar access, the selected AI provider for an AI-assisted request, and Cloudflare for delivery of this public website.

Retention, deletion and revocation

Disconnecting Google Calendar removes the stored OAuth connection, including its tokens, from the local Guidance database. The user may also revoke access from Google Account settings. Deleting the Guidance workspace removes records connected to that workspace through the local database’s deletion rules.

Questions and changes

Privacy enquiries can be sent to the developer support address displayed on the Guidance Google authorization screen. This policy will be updated before Guidance materially changes how it accesses, uses, stores or shares Google user data.