Privacy Policy
Executive AI OS · Effective July 25, 2026
Who we are
Executive AI OS is a private executive operations application operated by its owner for use by a small, individually authorized internal team. It is not a public service and does not offer self-service sign-up. Questions about this policy: lisle@lislehead.com.
Information we collect
The application stores account information for authorized users (name, email, role), the operational records those users create in the application, and audit records of actions taken in the application.
Google user data
If you choose to connect your Google account, the application requests the minimum scopes needed for the features you enable, and never more:
- Identity (
openid,email,profile): used only to identify which Google account is connected and to display that identity to you. - Calendar, read-only (
calendar.calendarlist.readonly,calendar.events.readonly): used only to show you your own calendar list and a read-only view of your own events — today’s schedule, scheduling conflicts, and meeting-preparation information.
The application cannot and does not create, modify, or delete calendar events; respond to invitations; send email; or access Gmail, Google Drive, or Google Docs content under these scopes.
How Google user data is used and stored
- Calendar data is fetched live when you view it, displayed to you only, and is not stored by the application. Only the list of your calendars (names and identifiers) and your selection of which calendars to include is saved.
- Your Google identity (email address, name) is stored to label your connection.
- The OAuth refresh token that keeps your connection active is stored encrypted at rest (AES-256-GCM) in access-restricted storage. Short-lived access tokens are held in server memory only and are never written to disk, logs, or the browser.
- Google user data is visible only to the user who connected the account. It is never shared with other users, transferred to third parties, sold, or used for advertising. It is not used to train machine-learning models.
Executive AI OS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention and deletion
- Revoke access at any time: use the Disconnect control on the Integrations page. This revokes the grant with Google and permanently deletes the stored refresh token. You can also revoke access from your Google Account permissions page.
- Calendar event content is never stored, so there is no event data to delete. Stored calendar names/selections are metadata only and are removed on request.
- To request deletion of your account or any stored data, email lisle@lislehead.com. Requests are honored within 30 days. Immutable security audit records (which contain no Google user data content) are retained as required for accountability.
Security
All access requires authenticated, signed sessions. Secrets and tokens are encrypted at rest and redacted from logs. Every consequential action is audited. The application takes no external actions without explicit human approval, and its external-write capabilities are disabled.
Changes
Material changes to this policy will be posted on this page with an updated effective date.