Privacy Policy
Effective date: 28 August 2026
This Privacy Policy explains how the GSD-AIOS Recovery integration accesses, uses, stores and protects information when it connects to Google Drive.
1. Purpose of the integration
GSD-AIOS Recovery is a governed backup and recovery component. Its Google Drive connection is used to place authorised recovery artifacts in off-host storage and to support later integrity verification and recovery operations.
2. Google data and permissions requested
The production integration is intended to request the Google Drive
https://www.googleapis.com/auth/drive.file OAuth scope.
This scope is used so the application can create and manage files and folders made
available to it without requesting broad access to unrelated files in the user's Drive.
The integration may process:
- OAuth access and refresh credentials required to maintain the authorised connection;
- technical identifiers and metadata required to locate and verify application-managed Drive files; and
- recovery archives, checksums and related evidence that an authorised administrator instructs the recovery system to place in Google Drive.
3. How data is used
Google user data is used only to operate the recovery functions described above. It is not used for advertising, profiling, data brokerage or unrelated analytics.
4. Credential protection
The production design protects long-lived OAuth material on the dedicated GSD-AIOS host using encrypted local secret storage. Plaintext OAuth credentials are not intended to be stored in project documentation, logs or public website files.
5. Sharing
GSD-AIOS does not sell Google user data. Google user data is not shared with third parties for advertising or unrelated commercial purposes. Access is limited to authorised GSD-AIOS administrators and infrastructure necessary to provide the authorised recovery function, subject to applicable law.
6. Retention and deletion
Recovery artifacts are retained according to the applicable GSD-AIOS recovery and retention policy until they are deleted or superseded by an authorised administrator. OAuth credentials are retained only while the Google Drive integration remains authorised. The Google connection can also be revoked from the Google Account's third-party access controls.
7. Security
GSD-AIOS applies access controls, integrity checks, least-privilege permissions, encryption of stored credentials, governed administrative access and audit evidence to reduce the risk of unauthorised access or modification.
8. Google API Services User Data Policy
Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.
9. Changes to this policy
This policy will be updated if the integration's data access, purposes or security practices materially change. The current version will remain available at this URL.
10. Questions
Questions about this policy may be directed to the support contact displayed on the GSD-AIOS Google OAuth consent screen.