CIARAN · A brighter you

Privacy and Google data

This notice describes the CIARAN application maintained by CIARAN Industries. Google connections are optional and belong to your Personal context. Google verification is not complete; availability depends on deployment configuration and your authorization.

What you connect and why

You choose capabilities before Google consent. Gmail access supports mail searches, headers, recipients, snippets and bounded selected-message text. Calendar access reads bounded events from your primary calendar. Contacts access searches saved contacts and reads names, email addresses, phone numbers and organizations. Drive access searches and reads file metadata, including names, types, timestamps and available owner information; it does not download file content.

CIARAN also receives your Google account identifier and email label to show which account you connected. That identity does not replace your CIARAN account or grant CIARAN authorization. These connections cannot send or delete email, change labels, edit events or contacts, or write Drive files. Attachment downloads are unavailable. Any embedded attachment data returned in a message payload is discarded. Remote email tracking resources are not fetched.

How information is used

Authorized data supports relevant searches, selected views and the conversation you request. Source content is untrusted information, never an instruction to execute an action. Greetings do not trigger Google reads. Local-only, no-cloud, no-network and supported source restrictions are applied before external retrieval.

General conversations may use the operator-approved local or cloud model infrastructure. CIARAN uses deterministic presentation for server-identified Google-derived answers and their retained source context, without sending those answers to the optional language model. Text you independently type or paste is ordinary conversation input; CIARAN cannot reliably identify every external source of pasted text. Review your deployment’s model policy before sharing sensitive information.

Storage and protection

Access and refresh tokens are encrypted in the backend and never delivered to browser code or models. CIARAN stores connection identity, granted access and bounded lifecycle outcomes. Read observations are transient, but answers containing source-derived information can remain in conversation history. Saving memory requires an explicit action. Account, conversation and memory access remains governed by CIARAN’s server-side authorization.

Production operators must protect database volumes, encryption keys and backups, publish their retention period and provide a privacy support contact before public launch. This repository does not establish a deployed backup schedule or claim that external verification has been completed.

Disconnect, revoke and delete

Settings → Connections lets you disconnect Google. Active credentials and pending consent are removed, future reads stop, and CIARAN attempts to revoke the Google grant. If Google is unavailable, a separate encrypted revocation record is retained temporarily for bounded retries. The UI reports pending revocation and provides manual-removal guidance. Revocation can affect the Google project’s combined access.

Disconnecting keeps existing conversation text, saved memory and tasks. The separate “Delete Google-derived retained data” control deletes source-linked conversations, memories and tasks from the active database; a linked conversation may include your own text. Deletion invalidates pending Personal requests, and you must sign in again. New requests after signing in may retain new information. It does not erase unrelated CIARAN or Work data. Older unclassified history and manually pasted material need separate review. Backup copies expire under the deployment operator’s published retention policy; restored data must have recorded deletion requests reapplied before use.

Deleting a connection is distinct from closing a CIARAN account. Account-closure requests require the deployment operator’s authenticated removal process. Archiving memory alone retains governance history and is not permanent deletion. You can also remove CIARAN directly from your Google account’s third-party connections.

Limited Use

CIARAN’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy and Google Workspace API user data policy, including Limited Use requirements. Google data is not used for advertising, sale, credit decisions or training general-purpose AI models. Any future change to processing requires appropriate disclosure and authorization.