Masuda · oauth.aitorsm.com

Privacy policy

How Masuda handles Google account data. Last updated 21 September 2026.

1. About this integration

Masuda is a privately operated AI assistant used only with the operator's own authorized accounts. It is not a product, has no public users, and is not offered as a public service.

2. Who this policy covers

Masuda accesses Google accounts only where the account holder has explicitly authorized it through Google's OAuth consent screen. In practice this is the operator's own account. Masuda is not offered as a public service: there is no sign-up, and no account is accessed without that explicit, individual authorization.

3. What Google data is accessed

When access has been authorized, Masuda may read and work with the following data from that account.

Gmail
Message and thread metadata (such as sender, recipients, subject, timestamps, thread and message identifiers), message content (including message bodies, snippets, and information about attachments), and labels together with read/unread state. Where the granted scopes allow it, Masuda may also create drafts, send messages, and change labels or read state on behalf of the authorized account.
Google Calendar
The calendar list for the account, event data (titles, descriptions, times, locations, attendees, organizers, recurrence, and reminders), and free/busy availability information. Where the granted scopes allow it, Masuda may also create, update, or delete events on the authorized account.

No other Google services are accessed. The scopes shown on the Google consent screen at the time of authorization are the authoritative statement of what has been granted.

4. Why it is accessed

This data is accessed for one purpose only: to carry out the assistant tasks that the authorized account holder asks for. That means reading, searching, and summarizing mail; extracting details such as dates, deadlines, and action items; drafting or sending replies on request; keeping the mailbox organized; answering questions about the schedule; checking availability; and creating or amending calendar events on request.

Google user data is not used to train machine-learning models, not used for profiling, and not used for any purpose beyond providing these requested features.

5. Limited Use disclosure

Masuda's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. OAuth token protection

OAuth access and refresh tokens are retained only while the integration is in use. Tokens and Google account data retained in task context are protected by access controls. They are not published. OAuth tokens are not shared with third parties, and Google account data is transferred only as described in the next section.

7. Task context and the AI model provider

Gmail and Calendar data retrieved for a task may be retained in the relevant task context for as long as it remains necessary to complete or continue that task.

To produce a response, only the content needed for the task at hand is sent to the configured AI model provider, which processes it in order to return the result. No bulk export of a mailbox or calendar takes place, and data is not sent to the model provider for any purpose other than completing the requested task. Google user data is not shared with any other third party.

8. No sale, no advertising

Google user data is never sold, rented, or licensed. It is never used for advertising, ad targeting, or any form of marketing or audience profiling, and it is not transferred to data brokers or advertising networks.

9. Retention

Google account data is kept only for as long as it is needed for the purposes described above. Retrieved message and event data is deleted when it is no longer needed. OAuth tokens are retained while the integration is in use and are deleted when the integration is discontinued. Revoking access, as described below, prevents further retrieval.

10. Security

Access to the integration, its stored credentials, and retained task context is restricted. Connections to Google APIs and to the configured model provider use encrypted HTTPS connections.

No system can be guaranteed to be perfectly secure. The measures described here are the ones actually in place; no further claims — certifications, audits, or formal compliance programmes — are made.

11. Revoking access

An authorized account holder can withdraw access at any time from the permissions page of their Google Account, at myaccount.google.com/permissions, by selecting Masuda and removing its access. Revocation takes effect immediately: the stored tokens stop working and no further Gmail or Calendar data can be retrieved.

12. Access and deletion

Because Masuda has no public users and is used only with accounts controlled by its operator, the operator can inspect, correct, export, or delete retained data directly and can withdraw Google access at any time.

13. Changes to this policy

If the integration changes in a way that affects this policy, this page is updated and the date at the top is revised. The current version is always the one published here at oauth.aitorsm.com/privacy.

← Back to the application page