oauth.sayforge.ai
Data & trust

Privacy Policy.

A clear account of how this personal automation project handles Google connections and the information that moves through them.

Last updated · September 17, 2026

This page describes the data practices for oauth.sayforge.ai and its self-hosted n8n automations. It is written for anyone considering a Google OAuth connection, including future authorized users of a workflow.

Who operates this project

oauth.sayforge.ai is a personal project operated by an individual. Its automation workflows run through a self-hosted n8n instance at n8n.sayforge.ai. This policy explains the handling of information in connection with this project, including any Google account connections used by its workflows. The service is primarily used for my own automations; access may also be offered to specific authorized users.

In this policy, “I” and “me” refer to the individual operating the project. This policy does not describe Google's own handling of information within Google services; Google's privacy terms apply to that activity.

Information that may be processed

The information involved depends on the workflow you use and the permissions you approve. Connecting a Google account can provide an account identifier and the data within the Google services covered by the approved scopes. A workflow may also process information you submit directly, workflow inputs and outputs, and technical records needed to run or troubleshoot the integration. When you contact me, I receive the information you choose to include in your message. Website hosting may process basic connection information, such as an IP address and browser details, to deliver a requested page.

Google Drive

Files, file content, names, metadata, and permissions, to the extent authorized and needed by a workflow.

Google Sheets

Spreadsheet content, sheet structure, and related metadata, to the extent authorized and needed by a workflow.

Gmail

Messages, headers, attachments, labels, and send actions, only where the approved permissions and workflow require them.

Google Calendar

Calendars, events, attendees, and related details, to the extent authorized and needed by a workflow.

Other Google APIs may be connected for a specific workflow. Any such access is limited to the permissions shown during authorization and the disclosed function of that workflow. This list describes possible categories, not a claim that every connection accesses all of them.

Google OAuth and permissions

Google OAuth is used to request your authorization before a workflow connects to your Google account. Google's consent screen identifies the permissions, also called scopes, requested for that connection. A scope can allow a workflow to read information, create or change information, send content, or perform another action described by that permission. You can decline a request; the dependent workflow may then be unavailable.

Permissions should be limited to what a particular workflow needs. If a workflow needs materially different Google data or a new purpose, the relevant disclosure and this policy will be updated, and your authorization will be requested before that new access or use begins.

Why the information is used

Google data is used to perform the automation that you authorize. Depending on its configuration, a workflow may retrieve a file or spreadsheet, read or send an email, create or update a calendar event, synchronize information between approved services, or create an output requested by the user. OAuth account information and tokens are used to establish and maintain that authorized connection. Technical information may be used to operate the workflow, investigate failures, and protect the service.

For a third-party user, the specific workflow and requested permissions should be explained before authorization. The data is not used for an unrelated purpose merely because a Google account has been connected.

Self-hosted processing and storage

The workflows are created and run through my self-hosted n8n instance at n8n.sayforge.ai. Information returned by a connected service may pass through that instance as the workflow runs. OAuth credentials or tokens needed for a continuing connection may be retained there. Depending on workflow configuration, inputs, outputs, and execution details may also be stored or sent to the user-authorized destination service.

Retention depends on the purpose and configuration of the particular workflow; this policy does not promise one fixed deletion schedule for all workflows. I will retain information under my control only while it is needed for the authorized workflow, its operation or security, or a legal obligation. Disconnecting a Google account stops future authorized access but does not automatically remove information already written to another service or retained in workflow records. Contact me to request removal of data under my control; I will assess and act on the request as applicable, subject to technical and legal limits.

Sharing and disclosure

Information can be transferred to Google services or another destination only as needed to complete the workflow that the user authorized. A destination service may then process the information under its own terms and privacy policy. I do not sell Google user data or transfer it to advertising platforms, data brokers, or information resellers. I do not use Google user data for targeted advertising, credit decisions, or lending.

For authorized third-party accounts, I do not routinely read connected users' Google content. I may view specific content with the user's affirmative permission, where necessary to investigate a security issue or abuse, or where required by law. Information may also be disclosed where legally required. If a workflow would share data with an additional service or recipient, that destination and purpose should be made clear before the user authorizes the workflow.

Google API Limited Use

The use of information received from Google APIs, including Google Workspace APIs, will adhere to the Google API Services User Data Policy and, where applicable, the Google Workspace User Data and Developer Policy, including their Limited Use requirements.

Google data and data derived from it will be used only for the authorized, user-benefiting automation functions described here. It will not be sold or used for advertising or to develop, improve, or train a generalized artificial intelligence or machine learning model. Access, transfers, and human review will be limited to what those policies permit.

Security and third-party services

The n8n instance can process sensitive account credentials and workflow information. I will use reasonable safeguards appropriate to that information to reduce the risk of unauthorized access or misuse. No online system can guarantee absolute security. If you believe a connection or account has been compromised, revoke the Google connection and contact me.

Google and any other service that a workflow connects to operate independently and apply their own terms, privacy notices, security controls, and availability limits. Their processing is outside this policy except where I choose to send information to them as part of an authorized workflow.

Your choices, revocation, and deletion

  • Choose whether to connect. Review the Google consent screen and authorize only the permissions you are willing to grant. You can decline, and a related workflow may not function.
  • Revoke Google access. Visit Google Account connections, select the connection for this project, and remove its access. Google may change the wording or location of these controls.
  • Request deletion or information. Use the contact address below to ask what information related to your connection is held in systems I control, to request deletion, or to ask that a workflow stop processing your data. Include enough detail to identify the connection without sending passwords or access tokens.

Revocation prevents the integration from obtaining new Google data through that authorization. It may not undo actions already completed, remove data in a destination service, or automatically delete data already processed. I may need to verify a request before acting on it.

Changes to this policy

This policy may be updated as the project and its workflows change. The date at the top will show the latest revision. If a change would introduce a new type of Google data access or a materially different use of that data, the updated disclosure will be provided and fresh consent sought before that new access or use occurs. Review this page when connecting a new workflow.

Contact

For privacy questions, access or deletion requests, or concerns about a Google connection, contact the individual operating oauth.sayforge.ai at:

End of Privacy Policy · Read the Terms of Service