Privacy Policy

Effective date: 28 August 2026

This Privacy Policy explains how the GSD-AIOS Recovery integration accesses, uses, stores and protects information when it connects to Google Drive.

1. Purpose of the integration

GSD-AIOS Recovery is a governed backup and recovery component. Its Google Drive connection is used to place authorised recovery artifacts in off-host storage and to support later integrity verification and recovery operations.

2. Google data and permissions requested

The production integration is intended to request the Google Drive https://www.googleapis.com/auth/drive.file OAuth scope. This scope is used so the application can create and manage files and folders made available to it without requesting broad access to unrelated files in the user's Drive.

The integration may process:

3. How data is used

Google user data is used only to operate the recovery functions described above. It is not used for advertising, profiling, data brokerage or unrelated analytics.

4. Credential protection

The production design protects long-lived OAuth material on the dedicated GSD-AIOS host using encrypted local secret storage. Plaintext OAuth credentials are not intended to be stored in project documentation, logs or public website files.

5. Sharing

GSD-AIOS does not sell Google user data. Google user data is not shared with third parties for advertising or unrelated commercial purposes. Access is limited to authorised GSD-AIOS administrators and infrastructure necessary to provide the authorised recovery function, subject to applicable law.

6. Retention and deletion

Recovery artifacts are retained according to the applicable GSD-AIOS recovery and retention policy until they are deleted or superseded by an authorised administrator. OAuth credentials are retained only while the Google Drive integration remains authorised. The Google connection can also be revoked from the Google Account's third-party access controls.

7. Security

GSD-AIOS applies access controls, integrity checks, least-privilege permissions, encryption of stored credentials, governed administrative access and audit evidence to reduce the risk of unauthorised access or modification.

8. Google API Services User Data Policy

Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.

9. Changes to this policy

This policy will be updated if the integration's data access, purposes or security practices materially change. The current version will remain available at this URL.

10. Questions

Questions about this policy may be directed to the support contact displayed on the GSD-AIOS Google OAuth consent screen.