Scope
This policy describes the processing of Google user data by the locally operated Mika Life OS application. The public website is informational only and receives no access to Gmail or OAuth tokens.
Controller
Miká MüllerWeinbergstraße 16a
38159 Vechelde
Germany
Email: mika.mueller.work@gmail.com
Google user data processed
Depending on the owner’s request, the application processes Google account identity and email address; message and thread IDs; sender, recipient, subject, and timestamps; message bodies; labels; and read, star, and archive state. To save drafts, it processes the recipient, subject, and body supplied by the owner. OAuth tokens provide continuing authorization.
Purpose and use
Data is used only to provide functions requested by the account owner: finding, reading, and summarizing email; proposing or, after approval, applying organization changes; and preparing drafts. It is not used for advertising, traded profiles, credit decisions, or sale.
Google permission and safety boundaries
The application requests the Gmail gmail.modify scope. Its local policy uses this
for reading, search, labels, archive, read and star state, and drafts. Changes are first shown
as a preview and require fresh approval. Direct sending, deletion, unsubscription, and opening
links or attachments are blocked.
Local storage and security
OAuth client data, refresh tokens, and the account allowlist are encrypted with Windows DPAPI for the signed-in Windows account. They are not transferred to the public repository or Proton Drive. Raw content and attachments are likewise not retained there. Local audit data is limited to technical state, action types, and non-reversible message hashes.
AI-assisted processing
When the owner starts an AI-assisted task, selected content necessary for that task may be sent to the AI service they actively use, currently OpenAI/Codex. Processing is additionally governed by that service’s account settings and privacy terms. The Mika Life OS operator does not use Google data to train general-purpose AI models.
Retention and deletion
OAuth tokens remain stored until revocation, invalidation, or local removal. Technical audit data is retained only as long as needed for security and accountability of local automation. The Windows PC owner can delete locally stored tokens, the allowlist, and state data.
Revoking Google access
The account owner can revoke access at any time in Google Account connections. The application can no longer access that account after revocation. Locally stored tokens can also be removed from the Windows PC.
Google API Services User Data Policy
Mika Life OS’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Website technology
These pages are part of the portfolio hosted by IONOS. The portfolio’s general Privacy Policy additionally applies to hosting, server logs, and IONOS WebAnalytics. The Life OS pages contain no Gmail sign-in and retrieve no Google user data.
Rights, questions, and changes
Questions and access or deletion requests may be sent to mika.mueller.work@gmail.com. This policy will be updated if the application’s functions or data processing materially change. Statutory data protection rights remain unaffected.