Privacy Policy
This policy explains how BOC (Brian's OpenClaw), a personal, self-hosted AI assistant, accesses and handles Google Calendar data. BOC is operated by a single owner for their own use and is not offered to the public.
1. Scope
This policy covers BOC's use of Google user data obtained through Google OAuth and the Google Calendar API, and this informational website. It applies only to the Google account that the owner has explicitly connected to BOC.
2. Google Calendar access
BOC connects to Google Calendar through the gog command-line tool,
which calls the Google Calendar API using OAuth consent granted by the account
holder.
The permission currently requested is:
-
https://www.googleapis.com/auth/calendar— full access to view and manage Google Calendar.
This is not a read-only permission. With it, BOC can:
- list events from all calendars the connected account can access;
- query free/busy information; and
- create, update, and delete calendar events.
Which of these capabilities BOC's routine integration actually uses may vary over time.
The intended behavior is that BOC creates, updates, or deletes calendar events only when the owner asks it to. This has not been verified. Before this page is published, the owner must confirm and state here:
- which calendar operations BOC's routine integration uses;
- whether any calendar changes can happen without an explicit owner request (for example, from scheduled automations); and
- whether event deletion is used at all.
3. Data that may be accessed
When a task requires it, BOC may retrieve calendar data including:
- event titles, start and end times, and time zones;
- event descriptions and locations;
- attendees (which may include other people's names and email addresses);
- recurrence rules; and
- calendar metadata, such as calendar names and identifiers.
BOC retrieves the calendar data needed for the task the owner has requested — for example, events within a requested date range. Depending on the task, this may include events from all connected calendars.
4. How data is used and processed
BOC uses calendar data to provide its features for the owner:
- answering questions about schedule and availability;
- planning tasks around existing commitments;
- producing daily summaries; and
- creating, updating, or deleting events (see section 2).
5. Third-party AI model providers
To generate summaries and plans, BOC may send calendar content relevant to the request (for example, event titles, times, descriptions, and attendees) to an external AI model provider for processing. That provider handles the data under its own terms.
The exact data flow between OpenClaw and the AI model provider(s) has not been verified. Before this page is published, the owner must confirm and state here:
- which model provider(s) and services receive calendar content;
- what calendar content is included in requests to those providers;
- each provider's data retention terms for that content; and
- whether each provider may use that content to train or improve its models.
No statement on this page should be read as a guarantee about third-party retention, training use, deletion schedules, or encryption.
6. Storage and retention
OAuth credentials
The OAuth token that authorises calendar access is managed by gog on
the host that runs OpenClaw. gog's diagnostics currently report that
its keyring backend is set to automatic selection, that a local keyring directory
is in use, and that a keyring password is configured.
Those diagnostics do not confirm which keyring backend is actually selected or exactly how the token is protected at rest.
Before this page is published, the owner must verify and state here:
- which keyring backend
gogactually uses on the host; and - how the stored token is protected at rest (for example, whether and how it is encrypted, and who can access the host's keyring files).
Calendar content, outputs, and conversation history
Whether calendar content, assistant outputs (such as summaries and plans), or conversation transcripts are stored persistently — and if so, where and for how long — has not yet been confirmed.
Before this page is published, the owner must confirm and state here:
- where, if anywhere, calendar content, assistant outputs, and transcripts persist (for example, OpenClaw session history, memory files, logs, or backups);
- how long each is retained; and
- how each can be deleted.
7. Sharing
When BOC generates summaries or plans, calendar content relevant to the request may be sent to an external AI model provider for processing, as described in section 5. This is the only data transfer this draft describes.
Other data-sharing and data-use practices have not been verified. Before this page is published, the owner must confirm and state here:
- whether Google user data is shared with, transferred to, or accessible by any other party (including other tools, services, or backups);
- whether Google user data is ever sold, used for advertising, or used to build profiles; and
- whether the OAuth token is shared with or accessible to anyone else.
Until confirmed, nothing on this page should be read as a guarantee about these practices.
8. Revoking access
The account holder can revoke BOC's access to Google Calendar at any time from their Google Account:
https://myaccount.google.com/permissions
After revocation, BOC can no longer read or change calendar data through the revoked token. Revoking access does not by itself delete data that may already have been stored locally or by a model provider; see sections 5 and 6.
9. This website
This website is static HTML and CSS hosted on Cloudflare Pages. It sets no cookies and uses no analytics, trackers, or third-party scripts. As with any web host, Cloudflare may process standard request data (such as IP addresses) to deliver and protect the site.
10. Contact and deletion requests
The owner must add a contact method for privacy questions and data deletion requests, and describe how such requests are handled, before this page is published.
11. Changes to this policy
This policy may be updated as BOC changes. The “last updated” date at the top of this page shows when it was last revised.