Privacy Policy
Last updated: August 25, 2026
1. Purpose and scope
Lotsato AI is a private personal-productivity application. This policy explains how the application accesses, uses, stores and protects Google user data.
2. Google data accessed
The application uses Google OAuth to access:
- the signed-in Google Account email address, for account verification;
- basic OpenID identity information; and
- Google Calendar event metadata through the
calendar.events.readonlyscope, including event title, status, start and end time, location and Google Calendar link.
The application does not request event descriptions and does not have permission to create, edit or delete calendar events.
3. How Google data is used
Google Calendar data is used only to display up to 50 upcoming events from the next 14 days in the owner's private dashboard. Google user data is not used for advertising, profiling, credit decisions or training general-purpose AI models.
4. Storage and retention
Calendar event contents are retrieved on demand and are not written to the application's database. OAuth access and refresh tokens, connection metadata and minimal security audit records are stored so the authorized connection can operate. OAuth tokens are encrypted at rest.
Connection records are retained while the owner uses the integration. The owner may revoke access at any time through Google Account permissions or request deletion using the contact address below.
5. Sharing and disclosure
Google user data is not sold. It is not shared with third parties except infrastructure providers required to operate and secure the application, principally Google and Cloudflare, or when legally required.
6. Security
The private dashboard is protected by Cloudflare Access. Access is restricted to the authorized owner. Tokens are encrypted and secrets are stored using Cloudflare's secret-management controls.
7. Google API Services User Data Policy
Lotsato AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
8. User choices and deletion
The owner can revoke the application's access from the Google Account security settings. To request deletion of stored OAuth connection data, email lotsato@gmail.com.
9. Changes to this policy
Material changes will be published on this page with an updated effective date.
10. Contact
Questions or deletion requests: lotsato@gmail.com.