TokenSchmiede
Personal gogcli · Privacy

Privacy policy

Effective date: 8 September 2026

This policy covers Personal gogcli, Sebastian's private, locally run gogcli installation for his own Google account. It does not describe every installation of the upstream gogcli project.

Data accessed and purpose

The owner grants Google OAuth permissions for Gmail, Calendar, and Drive. Depending on those permissions and the commands used, the tool may access email contents, recipients, attachments and labels; calendars and event details; and Drive file contents and metadata. It uses this access to carry out the owner's requested searches, reads, downloads, sends, edits, and other supported account-management commands.

Storage and protection

The program runs on the owner's machine and communicates with Google APIs over HTTPS. OAuth client configuration is stored locally. Authentication tokens are stored using gogcli's configured credential store, normally the operating system keyring. Command output, downloaded files, and any logs or exports remain in the locations chosen by the owner, who controls their access and deletion. These information pages do not receive Google account data or OAuth tokens.

Sharing and use limits

This installation does not sell Google user data or use it for advertising. It accesses the owner's Google account to provide the personal functions described above. Commands that send email or share files disclose the selected content to the recipients chosen by the owner. If the owner passes command output to another application or an AI service, that is a separate, owner-directed disclosure governed by that service's settings and policies; running locally does not make such onward transfers local.

Personal gogcli's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Retention, deletion, and revocation

Local credentials remain until the owner removes them. Local downloads, exports, and logs remain until deleted under the owner's storage and backup settings. The owner can revoke the app's authorization through Google Account connections and remove the account from gogcli. Revoking access stops future authorized access; it does not itself delete previously downloaded files, backups, or data held in Google services.

These web pages

These are static information pages with no sign-in, forms, analytics scripts, or embedded third-party content. The web hosting infrastructure may record ordinary request metadata, such as IP address, URL, and request time, for delivery and security. Visiting these pages grants no Google account access.

Operator and updates

The operator is Sebastian at TokenSchmiede; see the operator's public profile. The support email configured in Google's consent screen can be used for questions about this installation. This policy will be updated if its data practices change.