tacitOS Privacy Policy

Effective date: June 30, 2026

This Privacy Policy explains how tacitOS, operated by ALB Division Kft. ("tacitOS",

"we", "us", or "our"), handles information when you use the tacitOS desktop

application, tacitOS Cloud, and the Google Connector CLI. If you do not agree

with this policy, do not use tacitOS or connect a Google account.

Contact: support@tacitos.hu

Scope

This policy covers two separate Google OAuth uses:

application. It requests Google identity scopes only: openid, email, and

profile.

your tacitOS agent can work with your Google Workspace data when you ask it

to. This uses a separate Google Cloud project and a desktop OAuth client named

tacitOS Google CLI.

The Google Connector CLI is separate from tacitOS app login. Connecting a Google

account for the agent does not change the Google account used to sign in to

tacitOS Cloud.

Information We Collect

Depending on how you use tacitOS, we may collect or process these categories of

information:

verified-email status, name, and profile image when you sign in with Google.

subscription identifiers, entitlement state, device-login state, and signed

license metadata.

installed CLI tool identifiers, service-readiness checks, and diagnostic

status needed to run the desktop app.

attachments, and other local profile data created while you use tacitOS.

CLI, as described below.

Google Workspace Data

The Google Connector CLI currently requests these Google API scopes:

These scopes may allow the agent, when authorized by you, to:

messages from your Gmail account. Gmail sending is blocked by default in the

wrapper and requires an explicit send-capable action and confirmation.

move, trash, and delete Drive files.

update, delete, and manage calendars or events.

spreadsheet values.

show account status and route commands to the correct account.

We access Google Workspace data only after you connect a Google account and only

to provide user-facing features you request, such as searching messages,

summarizing a document, downloading an attachment, updating a calendar event, or

editing a document or spreadsheet.

How We Use Information

We use information to:

extracting, creating, updating, sending, sharing, or deleting content when the

connected service and your consent allow it;

operational events;

deployment evidence; and

Storage And Retention

Google Connector CLI OAuth refresh tokens and account manifests are stored in

your local tacitOS profile on your device. The app uses profile-local storage,

the local secret store or file keyring, and separate storage for the managed

Google Connector CLI and the legacy bring-your-own-OAuth connector. tacitOS

Cloud provides the managed OAuth client configuration to entitled desktop users,

but it does not store your connected Google account refresh tokens.

Downloaded Gmail attachments, exported files, and generated outputs are stored

locally in your tacitOS profile or the download location selected by you or the

agent. Local chat history or tool results may contain snippets or derived

content from your Google data if you ask the agent to process that data.

tacitOS Cloud stores account identity, session, entitlement, billing, audit,

catalog, and operational metadata needed to run the cloud service. We keep this

data only for as long as needed for the purposes described in this policy,

unless a longer period is required for security, backup, legal, tax, accounting,

or dispute-resolution reasons.

You may disconnect Google accounts in tacitOS, remove local profiles or

downloads, and revoke access from your Google Account permissions page. You may

also contact us to request deletion of cloud account data, subject to legal,

security, billing, and backup retention requirements.

Sharing And Transfers

We do not sell Google user data. We do not use Google user data for advertising.

We do not use Google user data to train generalized or non-personalized AI or

machine learning models.

We may share or transfer information only as needed to provide tacitOS and the

features you request:

your selected Google account.

instructions, and content needed to perform the task you requested. For

example, if you ask the agent to summarize a Google Doc, the relevant document

content may be included in the model request. You are responsible for choosing

model providers appropriate for the confidentiality of your data.

backups, security, and support data under appropriate confidentiality and

security obligations.

to investigate abuse, or as part of a merger, acquisition, financing, or sale

of assets where the recipient is bound by this policy or equivalent

protections.

Google API Services User Data Policy

tacitOS's use and transfer to any other app of information received from Google

APIs will adhere to the Google API Services User Data Policy,

including the Limited Use requirements.

For Google Workspace APIs, we also design the Google Connector CLI to align with

Google's applicable Workspace API user data and developer policies.

Security

We use reasonable administrative, technical, and organizational safeguards to

protect information. These include OAuth-based authorization, local profile

storage for Google Connector tokens, local secret/keyring protection, scoped

cloud entitlement checks, redaction of secrets in logs, HTTPS for cloud routes,

and audit events for sensitive cloud access. No system is perfectly secure, and

you are responsible for protecting your device, operating-system account, and

connected Google accounts.

Your Choices

You can:

you do not trust; and

information.

Children

tacitOS is not intended for children under 13, and we do not knowingly collect

personal information from children under 13.

International Processing

We may process information in countries other than your country of residence.

Where required, we use appropriate safeguards for international transfers.

Changes

We may update this Privacy Policy as tacitOS changes. We will update the

effective date when we make material changes. Continued use of tacitOS after a

policy update means you accept the updated policy.

Contact

For privacy questions or requests, contact:

support@tacitos.hu