This policy explains how Ghast AI ("Ghast", "we" or "our"), provided by Trapezohe, accesses, uses, stores and shares information across the Ghast desktop application, browser extension and connected account services. Features and storage locations differ between the desktop application and browser extension.

Google data: Connecting Google is optional. We use Google user data to provide the user-facing features you request. We do not use Google Workspace API data to develop, improve or train non-personalized AI or machine-learning models.

1. Information we access

We process account information, settings, prompts, conversation history, tool results and memory needed for the features you use. Content retrieved through a connected service can become part of a conversation, generated output or memory and may be included in subsequent task context. Installing a plugin does not itself authorize access to your account.

Google sign-in and Workspace connections

Google sign-in provides account identifiers, email, name and profile information for authentication and account display. Connecting a Google Workspace service is a separate authorization. The Google consent screen identifies the requested permissions; access is limited by your grant and your Google account or organization permissions.

ServiceData accessed and purpose
GmailAccessible messages, threads, labels, attachments and drafts to find and summarize email, organize messages, and prepare or send messages when requested.
Google DriveAccessible file metadata and content to search and read files, and files authorized for the app to create or update requested work.
Google Docs, Sheets and SlidesDocument text, spreadsheet data and presentation content to read, summarize, create and edit items you ask Ghast to work on.
Google CalendarCalendar lists, availability and event information to answer scheduling questions and manage requested events.
Google ChatAccessible spaces, memberships, messages and read-state information to find and summarize conversations and post requested messages.
Google ContactsContact details to find people and support requested communication tasks. The current Contacts connector requests read-only contacts access.

Ghast requests permissions for the connected functionality. You can decline access, disconnect a service or revoke the account grant. Google plugins may reuse an existing grant for the same account; revoking a shared grant can affect more than one plugin.

Other information

Depending on the features you use, Ghast processes selected files and page content, browser or computer tool input and output, wallet addresses and transaction data, and operational records such as model names, token counts, request identifiers, timestamps and errors. Feedback and diagnostic reports can include information you choose to submit. Reports that include conversation excerpts require your agreement to include that content.

2. Google data use and Limited Use

Ghast AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. These restrictions apply to Google data and information derived from it, including summaries and memory.

We limit Google data use to providing or improving the user-facing features you request, such as retrieving information, generating relevant responses, managing authorized content and maintaining your connected account.

  • No generalized model training: Google Workspace API data is not used to develop, improve or train non-personalized AI or machine-learning models, including generalized foundation models. We do not permit service providers processing this data for Ghast to use it for those purposes.
  • No advertising or sale: We do not sell Google user data, transfer it to data brokers or information resellers, use it for advertising or ad targeting, or use it to determine creditworthiness or for lending.
  • Limited transfers: Transfers are limited to providing or improving the authorized, visible user-facing functionality with your consent, security purposes, applicable legal obligations, or a business transfer with your explicit prior consent where required by Google's policy.
  • Limited human access: People may access Google data only with your affirmative agreement to view specific data, when necessary for security or applicable legal obligations, or for permitted internally aggregated operations under Google's policy. For example, agreeing to include specific excerpts in a support report can allow authorized support personnel to examine those excerpts.

3. AI processing and third-party services

Ghast is an AI client. When your requested task uses Google content, relevant content may be sent as context to the AI model or inference service selected for the task, together with your prompt and applicable tool results. This processing generates responses, summaries or requested work; it is not permission to train generalized models.

The Google data restrictions above apply to processing on Ghast's behalf. Google-derived content must not be routed to a provider or custom endpoint whose terms or configuration allow prohibited training or other secondary use. Selecting a model, enabling a connector or granting OAuth consent does not waive these restrictions. Provider availability in Ghast is not a statement that every provider has identical retention terms or zero retention.

Other recipients depend on the features you enable: Google receives authenticated API requests; Ghast account services process account and authorization operations; configured inference and embedding services process task context; enabled storage or team services process saved or shared work; and messaging or external tools receive content used in the actions you request. Optional decentralized compute or storage services, such as 0G, are external services and are not local-only storage. Google-derived content remains subject to Limited Use when included in outputs, memory or synchronized material.

4. Storage and protection

Local application profiles store settings, conversations, memory and connection state. The desktop and browser extension use different storage mechanisms. Local-first does not mean all processing or storage stays on your device: account services retain account information and operational records, and enabled remote services process data for their respective features.

For Google Workspace connections, the Ghast backend handles OAuth authorization, token exchange, refresh and revocation. Application client secrets stay in the backend rather than in plugin packages. Google refresh credentials are encrypted in a server-sealed envelope before being returned to the desktop. Connection credentials persist so that the desktop can reconnect and refresh authorization. The backend holds the relevant encryption keys; this is not a claim of zero-knowledge storage.

Remote OAuth and Google API requests use HTTPS. Access controls and encryption protect credentials and applicable stored data. Authorized staff access to submitted reports is restricted. Security measures reduce risk but do not eliminate it. Do not put account passwords, recovery phrases or private keys in conversations, feedback or support reports.

5. Retention and deletion

Local conversations, retrieved results, memory and exports remain until removed using their corresponding controls or by deleting the relevant local files. Conversations and derived memory have separate lifecycles. Desktop uninstallation does not necessarily remove application profiles or exported files.

Account data is retained while needed to operate the account and meet security or legal obligations. Operational records and diagnostic reports are retained according to their purpose and applicable retention schedules. User-submitted feedback, records required for legal or security reasons, and backups may remain after a connection is removed. We do not promise zero retention or immediate erasure of every copy held by independent services. Backup copies are removed through their applicable lifecycle rather than automatically when a live record is deleted.

You can delete conversations and memory using Ghast's corresponding controls. For account, submitted report or other server-side data deletion requests, contact us using the address below and identify the account and data concerned without sending credentials. We will verify the request, address data under our control and explain applicable retention exceptions. Copies held by your selected external services may require separate requests to those services.

Optional decentralized storage and public blockchains can have persistence characteristics that prevent complete erasure. Overwriting a record does not guarantee removal of historical copies. Public blockchain transactions cannot generally be reversed or deleted.

6. Disconnecting Google

Use the connection menu in Ghast's plugin settings to disconnect Google, or revoke Ghast from Google Account connections. Revocation prevents further access with the revoked authorization, and a new connection requires authorization again.

Disconnecting is not deletion: removing a Google connection does not automatically delete content already copied into conversations, memory, reports, exports, shared work or third-party systems. Delete those copies separately using the controls and request process described above. Signing out of Ghast is also separate from revoking Google Workspace permissions.

7. Other features and your choices

Browser and computer tools process the content necessary for the actions you request and operate within granted permissions. Wallet features process public addresses and transaction information; wallet signing credentials should remain in their protected wallet storage and must not be shared through prompts. External messaging, scheduled tasks, storage synchronization and remote tools can be enabled or disabled through their respective settings. Review the destination and task before sharing sensitive content.

Ghast is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child has provided information to us, contact us.

8. Changes and contact

We update this page when data practices change and identify the revision date above. Material changes to Google data use require appropriate notice and consent before use for a new purpose.

For privacy questions and deletion requests, contact contact@trapezohe.ai. Google connection and verification questions can also be sent to the registered support contact, contact@trapezohe.ai. Do not send passwords, OAuth tokens or private content in public GitHub issues.