tacitOS Privacy Policy
Effective date: June 30, 2026
This Privacy Policy explains how tacitOS, operated by ALB Division Kft. ("tacitOS",
"we", "us", or "our"), handles information when you use the tacitOS desktop
application, tacitOS Cloud, and the Google Connector CLI. If you do not agree
with this policy, do not use tacitOS or connect a Google account.
Contact: support@tacitos.hu
Scope
This policy covers two separate Google OAuth uses:
- tacitOS app login. This is used to sign in to tacitOS Cloud and the desktop
application. It requests Google identity scopes only: openid, email, and
profile.
- Google Connector CLI. This lets you connect one or more Google accounts so
your tacitOS agent can work with your Google Workspace data when you ask it
to. This uses a separate Google Cloud project and a desktop OAuth client named
tacitOS Google CLI.
The Google Connector CLI is separate from tacitOS app login. Connecting a Google
account for the agent does not change the Google account used to sign in to
tacitOS Cloud.
Information We Collect
Depending on how you use tacitOS, we may collect or process these categories of
information:
- Account information: your Google account subject identifier, email address,
verified-email status, name, and profile image when you sign in with Google.
- Subscription and entitlement information: payment status, Stripe customer or
subscription identifiers, entitlement state, device-login state, and signed
license metadata.
- Device and app metadata: app version, operating system, profile identifier,
installed CLI tool identifiers, service-readiness checks, and diagnostic
status needed to run the desktop app.
- Local agent content: chats, prompts, tool results, downloaded files, local
attachments, and other local profile data created while you use tacitOS.
- Google Workspace data that you choose to connect through the Google Connector
CLI, as described below.
Google Workspace Data
The Google Connector CLI currently requests these Google API scopes:
https://www.googleapis.com/auth/gmail.modifyhttps://www.googleapis.com/auth/drivehttps://www.googleapis.com/auth/calendarhttps://www.googleapis.com/auth/documentshttps://www.googleapis.com/auth/spreadsheetsopenidemailhttps://www.googleapis.com/auth/userinfo.email
These scopes may allow the agent, when authorized by you, to:
- Gmail: search, read, organize, label, archive, modify, draft, compose, and send
messages from your Gmail account. Gmail sending is blocked by default in the
wrapper and requires an explicit send-capable action and confirmation.
- Google Drive: list, search, read, download, upload, create, update, share,
move, trash, and delete Drive files.
- Google Calendar: read calendars and events, check availability, create,
update, delete, and manage calendars or events.
- Google Docs: read, create, edit, and delete Google Docs documents.
- Google Sheets: read, create, edit, and delete Google Sheets spreadsheets and
spreadsheet values.
- Account identity: identify which Google account is connected so tacitOS can
show account status and route commands to the correct account.
We access Google Workspace data only after you connect a Google account and only
to provide user-facing features you request, such as searching messages,
summarizing a document, downloading an attachment, updating a calendar event, or
editing a document or spreadsheet.
How We Use Information
We use information to:
- authenticate you and maintain your tacitOS Cloud session;
- verify subscription, entitlement, and CLI catalog access;
- connect your selected Google accounts to the Google Connector CLI;
- perform agent tasks that you request, including reading, summarizing,
extracting, creating, updating, sending, sharing, or deleting content when the
connected service and your consent allow it;
- show account status, readiness checks, error messages, and audit-friendly
operational events;
- secure the service, prevent abuse, debug failures, and maintain backups and
deployment evidence; and
- provide support, respond to requests, and comply with applicable law.
Storage And Retention
Google Connector CLI OAuth refresh tokens and account manifests are stored in
your local tacitOS profile on your device. The app uses profile-local storage,
the local secret store or file keyring, and separate storage for the managed
Google Connector CLI and the legacy bring-your-own-OAuth connector. tacitOS
Cloud provides the managed OAuth client configuration to entitled desktop users,
but it does not store your connected Google account refresh tokens.
Downloaded Gmail attachments, exported files, and generated outputs are stored
locally in your tacitOS profile or the download location selected by you or the
agent. Local chat history or tool results may contain snippets or derived
content from your Google data if you ask the agent to process that data.
tacitOS Cloud stores account identity, session, entitlement, billing, audit,
catalog, and operational metadata needed to run the cloud service. We keep this
data only for as long as needed for the purposes described in this policy,
unless a longer period is required for security, backup, legal, tax, accounting,
or dispute-resolution reasons.
You may disconnect Google accounts in tacitOS, remove local profiles or
downloads, and revoke access from your Google Account permissions page. You may
also contact us to request deletion of cloud account data, subject to legal,
security, billing, and backup retention requirements.
Sharing And Transfers
We do not sell Google user data. We do not use Google user data for advertising.
We do not use Google user data to train generalized or non-personalized AI or
machine learning models.
We may share or transfer information only as needed to provide tacitOS and the
features you request:
- Google APIs receive OAuth and API requests necessary to connect and operate
your selected Google account.
- Model providers selected or configured for your agent may receive the prompts,
instructions, and content needed to perform the task you requested. For
example, if you ask the agent to summarize a Google Doc, the relevant document
content may be included in the model request. You are responsible for choosing
model providers appropriate for the confidentiality of your data.
- Service providers may process cloud hosting, payment, email delivery, logging,
backups, security, and support data under appropriate confidentiality and
security obligations.
- We may disclose information if required by law, to protect rights and safety,
to investigate abuse, or as part of a merger, acquisition, financing, or sale
of assets where the recipient is bound by this policy or equivalent
protections.
Google API Services User Data Policy
tacitOS's use and transfer to any other app of information received from Google
APIs will adhere to the Google API Services User Data Policy,
including the Limited Use requirements.
For Google Workspace APIs, we also design the Google Connector CLI to align with
Google's applicable Workspace API user data and developer policies.
Security
We use reasonable administrative, technical, and organizational safeguards to
protect information. These include OAuth-based authorization, local profile
storage for Google Connector tokens, local secret/keyring protection, scoped
cloud entitlement checks, redaction of secrets in logs, HTTPS for cloud routes,
and audit events for sensitive cloud access. No system is perfectly secure, and
you are responsible for protecting your device, operating-system account, and
connected Google accounts.
Your Choices
You can:
- choose whether to sign in to tacitOS with Google;
- choose whether to connect a Google account to the Google Connector CLI;
- connect multiple Google accounts and select which account an agent should use;
- revoke Google access in your Google Account settings;
- remove local tacitOS profiles, downloaded files, and connected-account state;
- choose model providers and avoid sending sensitive Google content to providers
you do not trust; and
- contact us to request access, correction, export, or deletion of cloud account
information.
Children
tacitOS is not intended for children under 13, and we do not knowingly collect
personal information from children under 13.
International Processing
We may process information in countries other than your country of residence.
Where required, we use appropriate safeguards for international transfers.
Changes
We may update this Privacy Policy as tacitOS changes. We will update the
effective date when we make material changes. Continued use of tacitOS after a
policy update means you accept the updated policy.
Contact
For privacy questions or requests, contact:
support@tacitos.hu