Operator
Privacy Policy
Effective date: July 29, 2026
This Privacy Policy explains how Operator, an owner-operated AI operations system developed and maintained by George Ramsay, accesses, uses, stores, and shares information. Operator is currently intended primarily for George's personal use and may be made available to specifically invited users.
Information Operator accesses or collects
Operator may process information that an authorized user provides directly, including account details, project instructions, approval decisions, and operational records.
When an authorized user connects a Google account, Operator may access the Google account email address and Gmail data needed for approval workflows. Depending on the granted permissions, this may include message and thread identifiers, sender and recipient information, subject lines, message bodies, timestamps, labels, and reply status.
Operator's current Gmail integration requests the OAuth scopes needed to modify Gmail data and send email. Operator may also store OAuth configuration, access tokens, refresh tokens, and token expiration information so the authorized integration can continue to operate.
Operator may create local technical and operational records, such as workflow status, approval history, error information, and audit records needed to operate, secure, and troubleshoot the system.
How information is used
Operator uses information only to provide and improve its user-facing operational features, including to:
- authenticate an authorized Google account and maintain the authorized connection;
- send Operator approval requests and related operational messages;
- create or use an Operator-specific Gmail label;
- locate and read replies associated with Operator approval workflows;
- record approval outcomes and continue, pause, or stop the corresponding workflow;
- maintain security, diagnose errors, and prevent unauthorized use; and
- comply with applicable legal obligations.
Operator does not use Google user data for advertising, personalized advertising, credit or lending decisions, data brokerage, or unrelated product development.
Google API Services User Data Policy
Operator's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Human access to Google user data is limited to the authorized account owner. The developer may access specific data only with the user's explicit consent for support or troubleshooting, when necessary to investigate security or abuse, or when required by law.
Learn more in the Google API Services User Data Policy.
Sharing and disclosure
Operator does not sell personal information or Google user data.
Information may be shared with Google to authenticate the account and operate the requested Gmail features, with infrastructure or service providers only when necessary to operate Operator, with the user's direction or consent, to address security or abuse, or when required by law.
Service providers are expected to process information only for the limited purpose of providing their services and subject to applicable contractual and legal obligations.
Storage and retention
Operator is designed to store OAuth credentials and configuration in local application state on an authorized device. Operational records may also be stored in private local files or private repositories controlled by the operator.
Gmail content is processed as needed to complete approval workflows. Operator may retain limited message details, excerpts, or derived approval records when needed to complete, document, or audit a workflow. Information is retained only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required by law or requested by the user.
Security
Reasonable administrative and technical safeguards are used to protect information, including limiting access to authorized devices and accounts and keeping local credentials and environment files out of public source control. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.
Your choices and deletion requests
A user may disconnect Operator by revoking its access in the Google Account security settings. Revocation prevents future API access but may not automatically delete local operational records already created.
To request access to, correction of, or deletion of information associated with Operator, email george.ramsay.ch@gmail.com. Reasonable requests will be addressed after identity and account ownership are verified.
Children's privacy
Operator is not directed to children under 13 and is not intended to knowingly collect personal information from children.
Changes to this policy
This policy may be updated as Operator's features or data practices change. The effective date at the top of this page will be revised, and users will be notified or asked to consent when a material change affects the use of Google user data.
Contact
George Ramsay
Email: george.ramsay.ch@gmail.com