Your data

Privacy policy

CHRIS OS is currently a personal, local application. This policy describes the v0.7 Calendar connector and this informational website.

Last updated: October 4, 2026

1. Google data accessed

Connecting Google Calendar is optional. After you authorize it in the local app, CHRIS OS retrieves events from your primary Google Calendar to build today's agenda.

The connector uses event identifiers, title, start and end times, all-day status, event status, location, description or notes, and recurring-event identifiers when provided. It also records the calendar/provider identifiers and when the local records were last synced.

Google's event response may include additional details, such as organizer, attendee, or meeting information. CHRIS OS keeps the normalized fields listed above rather than storing the full response. Descriptions and notes can themselves contain personal information or meeting links.

The current integration does not request access to Gmail, Google Drive, Contacts, or other Google products.

2. Purpose and permissions

Google Calendar data is used only to provide the user-facing calendar functionality described here: Today's Agenda, local calendar awareness, refreshes, and cached viewing when a connection is unavailable.

The requested Google scope is:

https://www.googleapis.com/auth/calendar.events.readonly

This permits viewing Calendar events. The current connector reads the primary calendar for the local day's agenda, including recurring instances and all-day events. It does not request permission to create, edit, or delete Google Calendar events, and it implements no Google event-write operations.

Synchronization happens when opening the local interface with stored authorization or when you choose Refresh. Calendar access is not required to launch CHRIS OS.

3. Local storage

Synced Calendar fields are stored in the local CHRIS OS SQLite database on your computer. Connection status, sync times, and meaningful integration activity are also stored locally. The public website does not host that database or the local dashboard.

The app does not encrypt its SQLite database. Local database copies and backups may also contain Calendar information. Their privacy depends on your computer's permissions, security, and how you manage those files.

4. Credentials and tokens

Google authorization takes place in your browser using a Desktop app OAuth flow. The response returns to a temporary loopback address on your computer. CHRIS OS does not receive or store your Google password.

The downloaded OAuth client credential is kept in the app's local data/secrets directory. Authorization tokens are kept in data/tokens, relative to the local database directory. These directories and token files are excluded from Git by repository ignore rules.

Tokens are saved as local files, without application-level encryption. On Windows, access relies on the surrounding directory permissions. OAuth values are not stored in SQLite, returned through the app's status API, or included in its audit details. Keep credentials, tokens, the database, and backups out of public or shared folders.

5. Sharing and Google data use

The current CHRIS OS implementation does not sell Google user data or send Calendar event content to advertising services, analytics providers, external AI/model providers, or this public website. It has no external model service connected and does not use Calendar data to train AI models.

The local connector communicates directly with Google for authorization, token refresh, and Calendar reads. Google handles those requests under its own Privacy Policy. User-managed copies or cloud-synced folders are outside the app's control.

Google user data is used only for the Calendar functionality described in this policy. Any future integration or broader use requires a separate review and an updated disclosure before introduction.

6. Retention and revocation

You can revoke CHRIS OS access through your Google Account's third-party connections settings. CHRIS OS detects invalid authorization on a later refresh and offers reconnection.

Revoking Google access stops future authorized reads. It does not automatically delete Calendar information already cached on your computer, local token files, or backups.

There is no automatic age-based deletion schedule or dedicated in-app Calendar data-erasure control. Successful syncs update cached events and reconcile missing or cancelled events only within the fetched calendar/date range. Older cached records can remain. Successful reconnection clears that calendar's existing local cache before fetching again; development reset preserves Calendar data and authorization.

You control the local files and any backups. Removing stored data is a separate local maintenance action; consider other CHRIS OS records before removing a shared database. Reconnection and file removal do not delete Google Calendar events.

7. Public website

chrisos.vatechalerts.com is an informational static website, separate from the local application. Visiting it does not give the site access to your Google account, Calendar events, or private CHRIS OS data.

The site consists of HTML and CSS. Its code contains no analytics, advertising, tracking scripts, cookies, authentication, forms, database, or API. It does not contact your local application.

The selected hosting provider, Netlify, receives ordinary web requests and may process technical connection information such as an IP address as part of delivering and securing the site. This is separate from CHRIS OS Calendar data. See Netlify's Privacy Policy for its practices. Links to Google and other providers lead to websites governed by their own policies.

8. Policy updates

This policy describes the current personal/local implementation. Changes to data access, storage, or sharing should be reflected here with a revised date. The public site is not a hosted version of CHRIS OS.