GHub AI
Built by
Closed beta

How GHub AI handles personal data

Privacy Policy

The data flows, purposes, retention periods and choices behind the GHub AI closed beta.

Effective
2026-08-31
Version
2026-08-31
Provider
PROGOS Kft.

Legal documents

Privacy PolicyTerms of ServiceCookie PolicyData Processing Addendum
PROGOS Számítástechnikai Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság
1121 Budapest, Ordas köz 2., Hungary
Company no. 01-09-718243
Tax no. 13090166-2-43
info@progos.hu

1. Who controls your data

PROGOS Számítástechnikai Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság (PROGOS Kft.) is the controller for the GHub AI website, account, connector infrastructure and product analytics described here. Registered office: 1121 Budapest, Ordas köz 2., Hungary. Company registration number: 01-09-718243. Tax number: 13090166-2-43. Contact: info@progos.hu.

We have not appointed a data protection officer because the present scale and nature of this closed beta do not require one. Privacy requests go to the contact above.

2. What the service does

GHub AI is an invitation-only connector that lets you use selected Gmail, Google Calendar and Google Tasks functions across Google accounts from a compatible client such as Claude. Google sign-in creates the GHub AI profile. Each Workspace account is connected in a separate Google OAuth flow.

The initial connection requests read scopes. You can later grant additional write scopes to a particular account. Depending on those grants and your command, tools can create drafts, send an existing draft, archive or label mail, create events and tasks, and update supported items. GHub AI does not offer a permanent-delete tool.

3. Data we process

CategoryExamples and sourceWhy
Profile and legal recordFirebase user identifier, sign-in email and provider data; Terms/Privacy versions and acceptance timestamp.Authenticate you, operate the account and prove the version you accepted.
Connected-account configurationGoogle account email and immutable OpenID subject, user-chosen slug, granted scopes, connection status and creation time.Route tool calls to the account you name, prevent duplicate connections to the same Google identity and show your dashboard.
CredentialsGoogle OAuth refresh token in Google Secret Manager; GHub AI session and connector authorization artifacts.Maintain the connection and authorize your client without asking you to reconnect for every request.
Workspace request and response dataMessages, headers, recipients, search results, calendars, events and tasks returned by Google or supplied in your tool command.Perform the request you made and return the result to your client.
Shape-only operations telemetryUser pseudonymous identifier, account slug, tool name, time, duration, outcome, item/result counts and error class.Security, reliability, beta measurement and diagnosing friction. It excludes bodies, subjects, recipient addresses, search terms, event/task text and Google item identifiers.
Feature reportsA description intentionally submitted through the feature-request tool, its type, time and optional call count.Understand missing capabilities. Do not include secrets or third-party personal data in free text.
Website analyticsOnline identifiers and visit/device information collected by Google Analytics only after opt-in.Understand public-site usage and improve the beta entry flow.
Security and service logsRequest metadata, timestamps, status/error information, and infrastructure identifiers recorded by Cloud Run and Cloud Logging.Protect and troubleshoot the service.

4. No persistent store of Google content

GHub AI handles Google Workspace content in memory for the duration of the tool request and returns it to the requesting client. It does not write message bodies, subjects, recipients, search terms, event/task text or Google item identifiers to Firestore, BigQuery or Secret Manager. Normal cloud networking and security logs can still contain request metadata; the application is designed not to log request or response content.

Your client conversation is a separate destination. For example, when Claude requests data, the returned data becomes available to Anthropic under your relationship and settings with Anthropic. Review the client’s privacy controls before sending a request.

5. Legal bases

  • Contract and steps at your request (GDPR Article 6(1)(b)): profile, account configuration, credentials and Workspace data required to provide the connector you requested.
  • Legitimate interests (Article 6(1)(f)): minimal shape-only telemetry and security/service logs needed to secure, diagnose and improve the beta. Our interest is a reliable and abuse-resistant service; the data is limited and does not include Workspace content.
  • Consent (Article 6(1)(a)): optional Google Analytics. Refusal does not restrict the service. You can withdraw at any time through Cookie settings.
  • Legal obligation (Article 6(1)(c)): records we must retain to meet binding legal, tax or regulatory duties.

Google OAuth permission authorizes technical access to the scopes you select. It is not used as blanket GDPR consent for unrelated processing.

6. Recipients and service providers

  • Google: Google Workspace APIs; Firebase Authentication and Hosting; Cloud Run, Firestore, Secret Manager, BigQuery and Cloud Logging; optional Google Analytics. Google group entities and published subprocessors may support these services.
  • Your chosen connector client: the tool result is sent to the client that you explicitly authorize, such as Claude. Anthropic is not selected by PROGOS as a hidden analytics recipient; it processes that conversation under the terms of your chosen client.
  • Professional advisers and authorities: only where reasonably necessary to establish legal claims, comply with law or protect users and the service.

We do not sell personal data and do not use Google Workspace data for advertising.

7. International transfers

Core service data is configured in Google Cloud’s European region where the selected product supports regional placement. Google and a client you choose may process data outside the EEA. Where PROGOS is responsible for a restricted transfer, it relies on the provider’s applicable EU Standard Contractual Clauses, adequacy decisions, and supplementary technical and organizational measures. A client you independently select may use its own transfer mechanism.

8. Retention

  • Profile, legal acceptance and connected-account configuration: until profile deletion, subject to any narrow legal retention duty.
  • Google refresh token: until that account is disconnected, the profile is deleted, Google revokes it, or it otherwise becomes invalid.
  • GHub AI browser session: up to 14 days; logout removes the browser cookie, and profile deletion revokes server-side sessions.
  • Pending connector consent: 5 minutes; authorization code: 60 seconds; issued connector access token: the configured lifetime, currently 30 days. Expiry is enforced immediately on read and Firestore TTL later removes expired records.
  • Pending Google connection metadata in Firestore and its refresh token in an isolated Secret Manager secret: logically available for 10 minutes. Any live service instance sweeps expired grants and asks Google to revoke them; the shared record survives scaling or a revision change until that cleanup succeeds.
  • Saved-account secret provisioning: a token-free technical Firestore reservation contains the pseudonymous user identifier, chosen slug and exact Secret Manager reference. It is normally removed atomically when the account is committed; provisioning is bounded to 2 minutes, commit recovery to 5 minutes, and a failed remote deletion keeps the minimal record only until cleanup succeeds.
  • Profile deletion recovery: deletion immediately blocks ordinary profile use. If local account, pending-grant or Secret Manager cleanup is interrupted, the access-blocked profile fields, account configuration and credentials remain only as needed for an automatic idempotent retry. After local cleanup, only the profile identifier, legal acceptance and deletion state remain in the durable job until session revocation and Firebase Auth user deletion are verified. Both phases retry automatically across service revisions; the job is then replaced by the one-hour minimal tombstone.
  • Deletion safety tombstones: a minimal profile identifier and state for up to 1 hour, plus a one-way-hashed OAuth user identifier through the maximum connector-token lifetime plus a one-hour buffer (currently up to 30 days + 1 hour). They exist solely to stop concurrent or delayed requests and old tokens from recreating access after deletion; Firestore TTL then removes them.
  • Shape telemetry and feature reports in BigQuery: table partitions expire after 90 days.
  • Cloud Logging: the production default log bucket is configured for 30 days.
  • Google Analytics: only after opt-in and according to the Analytics property’s configured retention; cookie lifetimes are listed in the Cookie Policy.

9. Your controls and rights

The dashboard lets you disconnect one Google identity, log out, or delete the complete GHub AI profile. Google’s revocation endpoint removes every scope granted by that Google identity to the Cloud project, so GHub AI permits one local connection per immutable Google subject and removes any legacy duplicate rows together. Disconnect and deletion ask Google to revoke the grant, then delete our local token and records. If Google cannot confirm remote revocation, the UI reports that limitation instead of claiming complete success; you can also remove GHub AI from your Google Account’s third-party access page.

Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability, or object to legitimate-interest processing. You may withdraw analytics consent without affecting earlier lawful processing. We may need to verify your identity. Contact info@progos.hu.

You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11, Hungary, naih.hu, or to the supervisory authority of your habitual residence or workplace.

10. Google API Limited Use

GHub AI’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is used only to provide or improve the user-facing connector functionality, for security, or as otherwise permitted by that policy. It is not used for advertising, creditworthiness, lending or generalized AI model training.

11. Security and incidents

Measures include encrypted transport, provider-managed encryption at rest, a dedicated Secret Manager namespace for account refresh tokens, hashed connector access tokens, per-user data and deletion barriers, least-privilege service accounts, short-lived authorization artifacts, explicit scope checks and no application content log. No service is risk-free. If a personal-data breach is likely to create a risk, we will notify the competent authority and affected people as required by law.

12. Children, automated decisions and changes

The beta is for adults and people authorized to act for an organization; it is not directed to children. PROGOS does not make decisions with legal or similarly significant effects about you using automated processing.

Material policy changes receive a new version. You will be asked to accept updated Terms and acknowledge an updated Privacy Policy before a new session is issued. Cookie choices are separately versioned and re-requested when needed.

PROGOS Kft. · 1121 Budapest, Ordas köz 2., Hungary

PrivacyTermsCookiesDPA

Your choice

Cookies, without the fog.

Essential storage keeps your secure session and remembers this choice. With your permission, Google Analytics also measures visits. Analytics stays off unless you choose it. Read the Cookie Policy.