Privacy Policy
This Privacy Policy describes how the Konsilium Personal Automation Server ("PAS", "the application", "we") accesses, uses, and protects data obtained through Google APIs. PAS is a private, self-hosted automation tool operated by Konsilium Strategic Advisory Inc. (Montréal, Québec, Canada) for the sole use of its operator, Christian Knudsen. It is not a public product and has no other users.
1. Information we access
When you authorise PAS through Google's OAuth 2.0 consent flow, the application requests access to the following data within the authorising Google account only:
- Google Drive — file and folder metadata and content, to read, create, organise, and update the operator's own files.
- Google Docs — document content, to read and edit the operator's own documents.
- Google Sheets — spreadsheet content, to read and update the operator's own spreadsheets.
PAS accesses only the account of the operator who authorises it. It does not access any other person's Google data.
2. How we use the information
Google user data is used exclusively to perform automation tasks that the operator initiates — reading, creating, organising, and editing the operator's own files, documents, and spreadsheets. PAS does not use Google user data for advertising, profiling, credit assessment, or any purpose unrelated to the operator's own file management.
3. Limited Use disclosure
The application's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. PAS does not transfer Google user data to third parties except as necessary to provide or improve the operator's own use of the application, to comply with applicable law, or as part of a merger or acquisition. PAS does not use Google user data for serving advertisements and does not allow humans other than the operator to read Google user data unless the operator has given affirmative consent, it is necessary for security purposes, or it is required by law.
4. Storage and security
- PAS runs on hardware owned and controlled by the operator. It is exposed only through an authenticated, encrypted connection (OAuth 2.1 with a private Cloudflare Tunnel).
- OAuth credentials and refresh tokens are stored only in the local operating-system service environment on the operator's machine. They are never written to any synced, shared, or public location.
- Google user data is accessed transiently to perform the requested operation. PAS does not maintain a separate long-term copy of the operator's Google content beyond limited operational logs used for security and troubleshooting.
5. Data sharing
PAS does not sell, rent, or share Google user data with any third party. Data remains within the operator's own Google account and the operator's own self-hosted environment, except where disclosure is required by applicable law.
6. Data retention and deletion
The operator controls all underlying data within their own Google account. Operational logs are retained only as long as needed for security and troubleshooting and are stored locally on the operator's machine. The operator may revoke the application's access at any time via the Google Account permissions page, which immediately ends PAS's ability to access any Google data.
7. Changes to this policy
This policy may be updated from time to time. Material changes will be reflected by an updated effective date at the top of this page.
8. Contact
Questions about this Privacy Policy may be directed to Konsilium Strategic Advisory Inc. at [email protected].