Bao

Effective September 24, 2026

Privacy Policy

Bao is a private, single-user personal assistant. This policy explains how it accesses and uses Google user data.

Data Bao accesses

Bao requests the minimum Google permissions needed for its current features:

The Google connector does not provide permission to send email, modify messages, create events, change events or delete Google data.

How Google data is used

Google user data is used only to provide requested personal-assistant functions, including ranking important email, identifying commitments and follow-ups, reviewing schedules, preparing private briefings and answering the owner's questions.

Processing and disclosure

Bao runs on the owner's Mac. Relevant excerpts may be transmitted to the configured OpenAI API solely to generate the requested analysis or response. Data is not sold, used for advertising, disclosed to data brokers or shared with unrelated parties. Google user data is not used by Bao's operator to train generalized artificial-intelligence models.

Bao's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Storage and retention

OAuth credentials are stored in the owner's macOS Keychain. Relevant excerpts, derived tasks and assistant history may be stored locally on the owner's Mac so the assistant can preserve requested work and commitments. Operational records are retained only for the owner's personal use and can be removed on request.

Security

Access is restricted to the owner's verified accounts and devices. The Google integration uses read-only scopes, local credential storage and bounded commands. No security measure eliminates every risk, but access is limited to what the assistant needs for the functions described here.

Control, revocation and deletion

The owner can revoke Bao's Google access at any time from the Google Account third-party connections page. Revocation stops future API access. To request deletion of locally stored Google-derived content, contact the address below; local OAuth credentials, assistant history and derived records associated with the connector will be removed as requested.

Changes

This policy will be updated before Bao materially changes its Google data access or use. The effective date above identifies the current version.

Contact

Questions, revocation help or deletion requests: youwu.lu@gmail.com.