Scope
This policy applies to Rookiee Brain, a private personal automation operated by Faisal Habibie. The app is used only with Google accounts expressly authorized by the operator.
Google user data the app accesses
Gmail
Rookiee Brain requests read-only Gmail access. It may read message metadata and content and fetch a supported attachment when needed for a requested workflow. It cannot send email or change provider state such as read flags, labels, folders, archives, or deletions.
Google Calendar
Rookiee Brain reads event metadata only from calendars explicitly selected by the account owner. A personal account may grant calendar write access so the app can create, update, or delete an event after the owner explicitly requests or confirms that action. Work-account calendar access is read-only.
How Google user data is used
- Classify and summarize incoming messages into private finance, task, and digest views.
- Retrieve requested PDF, JPEG, or PNG attachments after deterministic type and size checks.
- Create reminders from selected calendar events and reconcile them when an event changes or is cancelled.
- Carry out an owner-confirmed change to a personal calendar event.
Google user data is not used for advertising, credit decisions, surveillance, or the creation of a public or shared user profile.
Storage and retention
Active data is stored on private infrastructure controlled by the operator. OAuth tokens are kept in an encrypted local keyring, and backups are encrypted. Email bodies and accepted attachment contents are removed from active storage after 90 days. Compact provider identifiers and processing outcomes may be retained longer to prevent duplicate processing. Selected calendar event metadata and reminder state are retained only as needed to provide and reconcile reminders.
Encrypted backup copies expire under a rolling schedule within 12 months. Historical archives created and controlled separately by the account owner are outside the app's automated retention process.
Sharing and disclosure
Google user data is not sold, licensed, or shared with advertisers, data brokers, or unrelated third parties. Data may be processed by infrastructure, encrypted-backup, and AI service providers only to operate the features described in this policy, or disclosed when required by law or needed to protect the service from abuse. Human access is limited to the account owner, an owner-approved request concerning specific data, security or debugging needs, or legal requirements.
Security
Rookiee Brain uses HTTPS in transit, least-privilege OAuth scopes, encrypted token storage, encrypted backups, access controls, and secrets kept outside source control. Access is limited to the operator and the systems needed to provide the app.
Your controls and deletion
Google access can be revoked at any time from the Google Account connections page. To request removal of stored Google user data, email hire@faisalhabibie.com. Verified requests are removed from active storage promptly; residual encrypted copies expire through the backup retention schedule described above unless retention is required by law or for a documented security purpose.
Google API Services User Data Policy
Rookiee Brain's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including its Limited Use requirements.
Changes and contact
This policy will be updated before Google user data is used for a new purpose. Questions or requests can be sent to hire@faisalhabibie.com.