Legal
Last updated: August 24, 2026
This policy describes how BorensteinAgent ("the Application") handles data. The Application is a private automation tool built and operated by Evan Borenstein for personal use.
The Application is not a commercial product. It is not offered to, marketed to, or made available to the general public. Its sole user is its operator, and it accesses only that operator's own accounts and data.
The Application requests authorization to access the operator's own Google Account data through Google APIs. Depending on the features enabled, this may include:
The Application accesses only accounts that the operator has explicitly authorized through Google's OAuth consent flow. It does not access any other person's Google Account.
Data retrieved through Google APIs is used exclusively to perform the automation tasks the operator has requested — for example, summarizing mail, drafting replies, applying labels, or extracting information for the operator's own reference.
Data is processed only for these purposes. It is not used for advertising, profiling, resale, market research, or training generalized machine learning or AI models.
The Application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, the Application does not transfer, sell, or share Google user data with third parties except as necessary to provide or improve the Application's features, to comply with applicable law, or as part of a merger or acquisition; does not use Google user data for serving advertisements; and does not allow humans to read Google user data except with the operator's explicit consent, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized.
OAuth access and refresh tokens are stored locally in the operator's own controlled environment and are used solely to maintain the authorized connection to Google's APIs. Tokens are not transmitted to any third party.
Message content retrieved from Google APIs is processed transiently to complete a requested task. Any content retained beyond a task — for example, in a local cache or log — is stored in the operator's own environment and deleted when no longer needed.
The operator may revoke the Application's access at any time via the Google Account permissions page. Revoking access immediately invalidates stored tokens and ends the Application's ability to retrieve further data.
The Application does not sell data and does not share data with advertisers, data brokers, or analytics providers. Where the Application relies on infrastructure or model providers to carry out a requested task, data is transmitted only to the extent required to complete that task and is governed by those providers' own terms.
Credentials and tokens are stored in the operator's controlled environment with access restricted to the operator. Because the Application has exactly one user, its exposure surface is limited to that operator's own environment.
This policy may be updated as the Application's functionality changes. Material changes will be reflected in the "Last updated" date at the top of this page.
Questions about this policy can be directed to evanborenstein@gmail.com.