Privacy Policy
Effective September 26, 2026 · Operator: Derrick Grant
Derrick OS is a private, owner-operated application. This public informational site does not connect to Google accounts or display private workspace records. The disclosures below describe the private application and its optional Google integrations.
Google data the application accesses
When the authorized owner connects a Google account, Derrick OS requests read-only permission to access Gmail messages, Google Calendar events, and Google Drive files, and obtains the account email address to identify the connection. These permissions can cover more information than appears in any single Derrick OS view. The application currently uses them to list inbox messages and their details, view upcoming calendar events and recent Drive file details, retrieve a Gmail message body when that message is opened, and retrieve supported file text when a file is specifically requested. The Google integration does not send or change email, or create, change, or delete calendar events or Drive files.
- Gmail: inbox messages and details such as sender, subject, date, preview snippet, and message status. Opening a message can retrieve its body. The application does not send, change, or delete messages through this integration.
- Google Calendar: upcoming events, including available titles, times, descriptions, locations, and meeting details. The application does not create, change, or delete events through this integration.
- Google Drive: file and folder details such as names, types, and modification dates. When a file is specifically requested, the application can retrieve text from supported documents or files. The application does not create, change, or delete Drive files through this integration.
How this information is used and sent for AI processing
Derrick OS displays requested Google information in the authenticated owner's private workspace. For an ordinary owner-initiated Chief of Staff question, it assembles a bounded, per-request snapshot from connected Google accounts: selected inbox sender, subject, and snippet information; upcoming calendar event details; and Drive file details. This can happen even when the question does not name a Google account. Full Gmail message bodies are not automatically included in that snapshot. If the question calls for the contents of a specifically identifiable Drive file, supported text from that file may also be included.
Selected Google context, the owner's question, and supplied conversation context may be sent to OpenAI or Anthropic to generate the requested answer; a feature that uses both providers may send that context to both. Information the owner puts into a question may also be sent as part of that question. Generated answers may contain or reflect Google information and may be inaccurate, so the owner should review them against the source.
Storage and retention
To keep an authorized Google connection working, Derrick OS stores the authenticated owner's identifier, the connected account's email address and account slot, granted permissions, token expiry, and encrypted Google access and refresh tokens in its application database. It uses these details to identify the connection and refresh access while it remains connected. Gmail, Calendar, and Drive content is fetched for requests rather than routinely copied into a separate Google-content index. Generated answers or other application records may nevertheless contain or reflect information from those requests.
Service-provider systems, operational records, and backups may retain information under their applicable practices; there is no single guaranteed retention period or immediate removal of every copy.
Sharing and limited use
Google user data and information derived from it are used for the owner-authorized, user-facing functions described in this policy. Derrick OS does not sell that information, transfer it to advertising platforms or data brokers, or use it to serve advertising. When the owner uses an AI feature with Google context, relevant information may be sent to OpenAI and/or Anthropic as described above. Services that operate the application, including its hosting, database, and authentication services, may also process information as needed to provide it. Information may also be disclosed when required by law or necessary to protect the service.
Derrick OS's use of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements.
Owner choices and questions
Connecting a Google account is optional. To disconnect one, use Settings → Integrations → Google Workspace → Disconnect for that account. Derrick OS attempts to revoke its Google authorization and deletes that account's stored connection record, including its encrypted tokens. If revocation does not complete, the account holder can also remove Derrick OS access in their Google Account permissions. Disconnecting does not itself delete generated answers, provider-held information, or backups.
To request review or deletion of identifiable stored Google-related records or generated content containing Google information, contact Derrick Grant at derrick@highpointenergygroup.com and describe the account or records involved. Such requests must be assessed against the records and deletion controls available to Derrick OS and its service providers; this policy does not promise immediate deletion of every copy. This policy may be updated if the application or its data practices change; the effective date above identifies this version.