Privacy Policy
Last updated: 2026-09-17 · Effective immediately.
This privacy policy applies to REC Learning Lab (the "Application"), a personal desktop tool developed and operated by an individual developer (the "Developer", contact emailshmilydia@gmail.com). The Application uses the open-source gog command-line tool to access a signed-in user's own Google Workspace data on their behalf. This policy is written in plain language and explains in detail what personal data the Application collects, how it uses that data, how it stores the data, with whom it shares the data, and what choices the user has.
1. Scope of this policy
This privacy policy covers all personal data the Application collects when a user signs in to the Application with their Google account and authorizes the Application to access Google Workspace APIs on their behalf. The Application does not operate a web service, does not maintain a backend database of user content, and does not market itself to the general public. It is a single-user desktop tool.
For users in the European Economic Area, the United Kingdom, or California, the Developer acts as a data controller for the limited personal data described in this policy. For all other users, the same data-protection commitments apply.
2. Categories of personal data we collect
When you sign in and authorize the Application, we may collect, or process on your behalf, the following categories of personal data when you use or interact with the Application:
- Account identifiers. Your Google account email address, display name, and OAuth subject identifier. The Application uses these only to identify which authorized Google account a command applies to.
- Gmail content that you choose to read or send. When you ask the Application to list, search, fetch, draft, send, label, or delete a message, the Application reads or modifies that specific message on Google's servers and returns the result to your terminal. The Application does not retain message contents on disk.
- Calendar event content that you choose to read or modify. Event titles, descriptions, times, attendees, locations, and recurrence rules for the events you ask the Application to fetch, create, update, or delete.
- Drive file metadata and content that you choose to read or modify. File names, parent folders, MIME types, permissions, and file contents for the files you ask the Application to list, search, fetch, create, copy, move, rename, share, or delete.
- Contacts records that you choose to read or modify.Names, email addresses, phone numbers, postal addresses, organizations, and notes for the contacts you ask the Application to list, create, update, or delete.
- Sheets spreadsheet content that you choose to read or modify. Spreadsheet IDs, tab names, cell ranges, and cell values for the sheets you ask the Application to read, write, append to, or clear.
- Docs document content that you choose to read, export, or copy. Document IDs, titles, body text, tables, comments, and structural elements for the documents you ask the Application to export, cat, or copy.
- Tasks list content that you choose to read or modify.Task list IDs, task titles, due dates, notes, and completion status for the tasks you ask the Application to read or modify.
- OAuth 2.0 credentials. The OAuth 2.0 client credential JSON file you provide to the Application, plus an OAuth 2.0 refresh token returned by Google after you grant consent.
The Application does not collect any of the following categories of personal data: government identifiers, financial account numbers, health or medical information, biometric identifiers, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, immigration status, or any other category of sensitive personal data.
3. Purposes for which we use personal data
The Application uses the categories of personal data listed in section 2 only to provide the user-facing functionality the signed-in user explicitly requested through the command-line interface. The Application does not use personal data for any purpose other than providing the service the user requested. Specifically:
- Account identifiers are used only to select which authorized Google account a command applies to.
- Gmail, Calendar, Drive, Contacts, Sheets, Docs, and Tasks content is read or modified only when the user issues a command that requires that action.
- OAuth credentials are used only to obtain short-lived access tokens so the Application can call the Google APIs the user requested.
We do not use your personal data to make automated decisions about you. We do not profile you. We do not score or rank you. We do not build a behavioral model of you. We do not infer your interests, preferences, or characteristics from your Google user data.
4. Limited Use compliance
The Developer's use of Google user data is limited to providing or improving the user-facing functionality the signed-in user requested. The Application does not, and will not, use Google user data for any of the following prohibited purposes:
- Targeted advertising.
- Personalized advertising.
- Retargeted advertising.
- Interest-based advertising.
- Selling the data to data brokers.
- Selling the data to information resellers.
- Determining credit-worthiness.
- Use for lending purposes.
- Serving user advertisements.
- Creating databases built from Google user data.
- Training, developing, or improving any generalized (non-personalized) artificial intelligence or machine-learning model. In particular, Google Workspace APIs are not used to develop, train, or improve any generalized AI or ML model, and the Application does not transfer Google user data to any third party for any such purpose.
The Developer monitors the Application's behavior against this Limited Use commitment and will correct any deviation immediately upon discovery.
5. How we share, transfer, and disclose personal data
The Application does not transfer or disclose your personal data to any third party for purposes other than the ones provided in this policy. Specifically:
- No selling. We do not sell your personal data to any third party, directly or indirectly.
- No advertising partners. We do not share your personal data with advertising networks, demand-side platforms, supply-side platforms, or ad-tech vendors of any kind.
- No data brokers. We do not transfer your personal data to data brokers, information resellers, lead-generation firms, or people-search companies.
- No service providers for data storage. We do not engage third-party vendors to host or process your personal data on our behalf. The Application stores data only on the user's own machine, as described in section 6.
- No AI/ML training partners. We do not transfer your personal data to any third party for the purpose of training, developing, or improving any AI or ML model.
- Limited transfers for user-initiated actions. The only way the Application transfers personal data to a third party is when the user explicitly initiates an action that requires it (for example: sending an email to the address the user named, or copying a file into a shared drive the user selected). In each case, the third-party recipient is the recipient the user chose.
- Legal disclosure. If the Developer receives a valid subpoena, court order, or equivalent legal compulsion, the Developer will comply only to the extent legally required. The Application stores no Google user content, so any such request would yield only the OAuth refresh token, which can be revoked by the user at any time as described in section 7.
6. How we protect personal data
The Application does not run a remote server. It does not store your email bodies, calendar events, Drive files, contacts, sheets, docs, or tasks on any disk that the Developer can read. Security procedures are in place to protect the confidentiality of your personal data, and we use technical and organizational safeguards as follows.
- Encryption in transit. Every request the Application makes to Google APIs uses HTTPS (TLS 1.2 or higher). The Application does not communicate with any non-Google server.
- Encryption at rest. The OAuth refresh token described in section 2 is stored in an OS-level keyring (Secret Service on Linux, Keychain on macOS, Credential Manager on Windows), encrypted by the operating system with a user-specific secret. The token is never written to disk in plaintext.
- User-controlled credentials. The OAuth 2.0 client credential JSON file is owned by the user, stored at a path the user chose, and removable by the user at any time.
- No telemetry, no analytics, no logging to third parties. The Application does not send crash reports, usage statistics, or any other telemetry to the Developer or any third party.
- Access controls. The Application runs under the user's normal operating-system user account and inherits the operating-system file permissions for any data it touches. No process running as a different user can read the keyring-encrypted refresh token.
- Source code transparency. The
gogcommand-line tool used by the Application is open-source, so any user can audit exactly how their data is handled.
7. Data retention and deletion
We retain your personal information for the length of time needed to fulfill the purposes outlined in this privacy policy unless a longer retention period is required or permitted by law. Specifically:
- OAuth refresh token — retained for as long as you keep the Application installed and authorized. When the data retention period expires, the token is removed from the keyring.
- Gmail, Calendar, Drive, Contacts, Sheets, Docs, and Tasks content — never written to disk by the Application. Read or modified in memory on the user's own machine, returned to the terminal, then discarded by the operating system. There is no on-disk retention to expire.
- Account identifiers — used only at the moment a command runs; not retained between commands.
You may at any time request deletion of your data, or delete it yourself, by doing any of the following:
- VisitGoogle Account → Third-party apps with account accessand remove the REC Learning Lab entry. Google will immediately invalidate the refresh token.
- Delete the local token store by removing the
~/.config/gogcli/directory on Linux or macOS, or the equivalent keyring entry on Windows. - Delete the OAuth 2.0 client credential JSON file from your filesystem.
- Uninstall the Application. Any data the Application wrote is removed with it.
- Email the Developer atshmilydia@gmail.com to request manual deletion of any data the Developer might hold (such as diagnostic logs you emailed the Developer).
When the data retention period expires for a given type of data, we will delete or destroy it. Because the Application does not maintain a remote database, deletion of locally-held data takes effect immediately when you delete it.
8. Children's privacy
The Application is a personal desktop tool and is not directed to children under the age of 13. The Developer does not knowingly collect or maintain personal data from anyone identified as a child under 13, and the Application is not designed to attract children. If you believe the Application has collected personal data from a child under 13 in error, please contact the Developer so the data can be deleted.
9. Your rights and choices
You have the following rights regarding your personal data:
- Access. You can ask the Developer what personal data the Application has accessed by checking your command history.
- Deletion. You can delete the local token store, the OAuth credential file, and any data the Application wrote, at any time.
- Revocation. You can revoke the Application's Google account access at any time through your Google Account settings.
- Opt-out of optional features. You may skip any optional feature of the Application.
- Read-only mode. The Application can be invoked with a
--readonlyflag that requests read-only OAuth scopes, preventing the Application from writing any data. - Contact. You may contact the Developer at any time with questions, complaints, or data-access requests.
10. Changes to this privacy policy
If the Developer changes how the Application accesses, uses, stores, or shares Google user data, this privacy policy will be updated and the "Last updated" date at the top of this page will change. Continued use of the Application after a change means the user has read the updated policy and consents to it.
11. Contact the Developer
For questions, complaints, data-access requests, or anything else related to this privacy policy, contact the Developer:
- Email: shmilydia@gmail.com
- Developer name: Eric
- Application name: REC Learning Lab
The Developer will respond within a reasonable time.