This disclosure covers Ghast AI desktop, browser extension and connected account services. It supplements the Privacy Policy; extension-only descriptions do not describe every desktop or server feature.

Google Workspace: authorization is optional. Data is used for requested user-facing features, not to develop, improve or train non-personalized AI or machine-learning models. Google-derived summaries and memory remain subject to the same restrictions.

1. Data, purpose and destinations

DataPurposeProcessing and storage
Google identity and account profileSign-in and connected-account identificationGoogle, Ghast account services and local account state
Google OAuth credentialsAuthorized API calls, refresh and revocationGhast OAuth backend and desktop connection storage; refresh credentials are server-sealed
Gmail content, metadata and draftsSearch, summarize and perform requested email actionsOfficial Google APIs; retrieved results may enter conversations, memory and selected AI inference context
Drive files and Docs, Sheets and Slides contentFind, read, create and edit requested workOfficial Google APIs and task context; saved outputs may persist locally or in enabled services
Calendar, Chat and contact dataScheduling, communication and read-only contact lookupOfficial Google APIs and task context within granted scopes
Prompts, conversations, tool results and memoryResponses, continuity and user-facing assistanceLocal profiles and selected inference/embedding services; enabled synchronization or team destinations
Selected page, file or computer contentActions requested through browser, file and computer toolsTool execution and task context, subject to granted permissions
Wallet address and transaction dataBlockchain queries and requested transactionsLocal wallet features, RPC services and public blockchain records
Operational and usage recordsOperate, secure and account for service usageGhast account/operations services and applicable infrastructure
Feedback and optional diagnostic excerptsInvestigate the issue you reportGhast support systems; content excerpts are included with your agreement and can be reviewed by authorized personnel

2. AI processing is a transfer

Using an AI model can send relevant prompts and tool results to the model service selected for a task. Google data may only be processed for permitted user-facing purposes. Ghast does not permit processing of Google Workspace data for generalized model training, advertising, sale, data brokerage, creditworthiness or lending. Custom endpoints and subsequent uses of derived content must satisfy these restrictions; OAuth consent does not override them.

Optional external messaging, tools, storage and team features can transfer task content to their configured destinations. Optional decentralized services are not local-only processing. Review the selected service and its retention settings; no blanket zero-retention claim applies to all providers.

3. Credentials and protection

Application OAuth client secrets are held in the backend, not supplied by end users. The backend processes Google token exchange and refresh; the desktop retains connection state. Remote OAuth and Google API traffic uses HTTPS. Credential encryption uses keys held by the relevant services, so this should not be understood as zero-knowledge storage.

4. Controls and deletion

  • Disconnect: use the Google connection menu in Ghast or Google Account connections. A shared grant can serve multiple Google plugins.
  • Saved content: delete conversations, memory and exports separately. Disconnecting does not erase previous tool results, derived memory, submitted reports or external copies.
  • Server-side requests: contact contact@trapezohe.ai for data under our control. Retention obligations and backup lifecycles may limit immediate deletion; external services have their own deletion processes.
  • Feature controls: disable capture, remote tools, messaging, scheduled tasks or synchronization in their respective settings when not needed.
  • Local files: desktop profiles and exports may remain after uninstall. Public blockchain records and historical decentralized storage copies cannot be assumed erasable.

5. Retention and contact

Local content remains until removed. Account information, operational records, feedback and submitted reports are retained for their stated service, support, security or legal purpose, with backups governed by their lifecycle. See the Privacy Policy for data-use restrictions, retention, human-access limits and deletion requests.

Google connection support: contact@trapezohe.ai. Do not send credentials or private content in public support threads.