Google user data
Privacy Policy
Effective August 1, 2026
TrevOS Calendar is a private, single-owner, read-only calendar integration. This policy explains the narrow data boundary used to provide its approved planning views.
Data accessed
TrevOS requests only permission to read Google Calendar events and the list of calendars available to the authorized account. It does not request Gmail, Contacts, Drive, Calendar write, event creation, event editing, event deletion, RSVP, attendee-management, or calendar-sharing permission.
How data is used
Calendar data is used only to provide the authorized owner's TrevOS Calendar, Home calendar summary, Daily Brief day shape and preparation context, and limited Command Center scheduling context. Retrieved Calendar text is treated as untrusted data and cannot expand TrevOS permissions or authorize actions.
Storage and protection
OAuth client credentials and refresh tokens are stored locally in macOS Keychain. They are not embedded in browser code or public files. TrevOS keeps a minimized, protected local calendar projection needed for its approved views.
The browser does not receive Google credentials, raw Google Calendar identifiers, attendee email addresses, conference credentials, attachments, or unbounded provider payloads.
Retention and deletion
The live projection refreshes approximately every 10 minutes and is marked stale after 20 minutes without a successful refresh. A protected last-safe projection may remain available for no more than 48 hours and is always identified as stale with its as-of time.
Privacy-safe refresh audit metadata is retained locally for up to 30 days, bounded to 500 records, and does not contain event content. Revoking Google access stops future collection. The owner can remove the local token and separately delete protected local Calendar caches through the TrevOS administrative process.
Sharing and sale
Calendar content and Google user data are not sold, used for advertising, or shared with third parties. Data remains within the owner's protected local TrevOS environment except for the direct read-only requests necessary to retrieve it from Google Calendar.
Revocation
The owner can revoke access from Google Account permissions. TrevOS then fails closed: it does not silently represent old data as current and becomes unavailable after the limited last-safe retention window.
Contact
Privacy questions may be sent to the developer-contact address shown on the Google OAuth consent screen.