Last updated .
This policy covers Stoa, a private automation setup operated by one individual (“the operator”) for his own use. Stoa has no other users, offers no service to the public, and collects nothing from anybody else.
Only the operator's own Google Accounts, and only those he has personally connected. Stoa never asks any other person to sign in, and has no mechanism by which anyone else could grant it access.
Where a document or calendar entry that the operator can see was created or shared by someone else — a household member, for example — Stoa can read it only because that person already shared it with the connected account through Google's own sharing controls. Removing that share removes Stoa's access immediately, with no action required here.
| Scope | What it permits | Why Stoa asks for it |
|---|---|---|
drive.readonly |
Read-only access to files and folders visible to the connected account. | So an agent can locate, read and summarise a document the operator asks about. |
drive.file |
Create files, and access only files this application itself created. | So a document the operator has just downloaded can be filed into one specific, pre-agreed folder. This scope gives no access to any other file in Drive. |
calendar.readonly |
Read-only access to the connected account's calendars. | So an agent can answer questions about what is scheduled. |
openid, userinfo.email |
The account's email address. | So Stoa can confirm which account a stored credential belongs to. |
Stoa holds no scope permitting it to send email, share a file, change a sharing permission, move, overwrite or delete anything. Its one write capability creates new files in a single named folder and is independently prevented by Google from altering any file it did not create.
Stoa's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
Nothing read from Google is retained beyond the request it was read for, except the metadata-only audit log described above. Credentials are retained until access is revoked or the operator removes them. Revoking access, as described below, renders any stored credential useless immediately.
The operator can withdraw Stoa's access at any moment, without contacting anyone, at myaccount.google.com/connections. Revocation takes effect immediately and invalidates every stored token. Any person who has shared a file or calendar with a connected account can likewise end that access by removing the share in Google Drive or Google Calendar.
Stoa discloses Google user data to nobody. There are no third-party recipients, no processors other than the model provider described in section 4, and no circumstance in which data is shared for commercial purposes. Data would be disclosed only if compelled by law.
Stoa is not directed at children and is not available to anyone other than its operator.
Material changes will be reflected here with a new “last updated” date. Because the operator is also the only user, changes are not notified separately.
Questions about this policy, or about data Stoa may have accessed: privacy@thestoa.dev.