1. Scope and operator
Sabya Personal OS is a private productivity and personal knowledge system operated by Sabya Das for the operator and personal accounts the operator is authorized to use. It is not offered to the public. This documentation site contains no application interface, account login, analytics, advertising, or form-based data collection.
Questions or requests concerning this policy can be sent to sabya@sabya.co.
2. Google data the system accesses
The Google Cloud project currently declares a broad permission inventory for the operator’s personal workflows. A particular connection receives only the permissions included in that authorization request and approved on Google’s consent screen; declaring a scope in the project does not by itself grant access.
| Service | Data or action | Purpose |
|---|---|---|
| Identity | Google account identity and primary email address | Confirm which authorized account is connected. |
| Gmail | Email metadata, messages, attachments, labels, drafts, sending, and account settings, depending on the scopes granted | Retrieve, organize, search, summarize, draft, send, and maintain email at the account holder’s direction. |
| Drive, Docs, and Sheets | Files, metadata, activity, documents, spreadsheets, Drive apps, and supported Photos or Meet-created files; permissions can include reading, creating, editing, and deleting | Retrieve, organize, index, search, summarize, create, and update the account holder’s working materials. |
| Calendar | Calendars, access rules, settings, availability, and event details; permissions can include reading, creating, editing, sharing, and deleting | Provide schedule context, planning, availability, reminders, and account-holder-directed calendar actions. |
| Google Cloud | Cloud projects and data in services such as BigQuery, Cloud Storage, Dataplex, Datastore, Logging, Monitoring, Trace, and Service Management | Operate, inspect, and maintain the account holder’s private cloud workloads when a workflow requires it. |
| Other configured Google services | Google Play developer and games data, Maps tooling, Street View publishing, Drive app activity, and Generative Language models or retriever content | Support the operator’s specific developer, mapping, media, and AI-assisted workflows. |
Write or destructive actions are used only for an operator-requested workflow. The operator should review each Google consent screen because some configured scopes permit creating, changing, sharing, sending, or deleting data.
Exact Google OAuth scope inventory and current classification
As of September 1, 2026, Google Cloud classifies the declared inventory as 21 non-sensitive scopes, 54 sensitive scopes, and 18 restricted scopes. Google may revise classifications. Full scope URIs are listed below.
Non-sensitive scopes (21)
https://www.googleapis.com/auth/userinfo.emailhttps://www.googleapis.com/auth/userinfo.profileopenidhttps://www.googleapis.com/auth/androidpublisherhttps://www.googleapis.com/auth/calendar.app.createdhttps://www.googleapis.com/auth/calendar.calendarlist.readonlyhttps://www.googleapis.com/auth/calendar.events.freebusyhttps://www.googleapis.com/auth/calendar.events.public.readonlyhttps://www.googleapis.com/auth/calendar.settings.readonlyhttps://www.googleapis.com/auth/calendar.freebusyhttps://www.googleapis.com/auth/drive.filehttps://www.googleapis.com/auth/drive.appdatahttps://www.googleapis.com/auth/drive.installhttps://www.googleapis.com/auth/gameshttps://www.googleapis.com/auth/games_litehttps://www.googleapis.com/auth/gmail.addons.current.action.composehttps://www.googleapis.com/auth/gmail.addons.current.message.actionhttps://www.googleapis.com/auth/gmail.labelshttps://www.googleapis.com/auth/maps-platform.mapstoolshttps://www.googleapis.com/auth/iam.testhttps://www.googleapis.com/auth/streetviewpublish
Sensitive scopes (54)
https://www.googleapis.com/auth/calendar.readonlyhttps://www.googleapis.com/auth/spreadsheets.readonlyhttps://www.googleapis.com/auth/cloud-platformhttps://www.googleapis.com/auth/bigqueryhttps://www.googleapis.com/auth/bigquery.readonlyhttps://www.googleapis.com/auth/cloud-platform.read-onlyhttps://www.googleapis.com/auth/devstorage.full_controlhttps://www.googleapis.com/auth/devstorage.read_onlyhttps://www.googleapis.com/auth/devstorage.read_writehttps://www.googleapis.com/auth/bigquery.insertdatahttps://www.googleapis.com/auth/cloudplatformprojectshttps://www.googleapis.com/auth/bigquerymigrationhttps://www.googleapis.com/auth/bigquerymigration.readonlyhttps://www.googleapis.com/auth/calendarhttps://www.googleapis.com/auth/calendar.aclshttps://www.googleapis.com/auth/calendar.acls.readonlyhttps://www.googleapis.com/auth/calendar.calendarlisthttps://www.googleapis.com/auth/calendar.calendarshttps://www.googleapis.com/auth/calendar.calendars.readonlyhttps://www.googleapis.com/auth/calendar.eventshttps://www.googleapis.com/auth/calendar.events.ownedhttps://www.googleapis.com/auth/calendar.events.owned.readonlyhttps://www.googleapis.com/auth/calendar.events.readonlyhttps://www.googleapis.com/auth/trace.readonlyhttps://www.googleapis.com/auth/trace.appendhttps://www.googleapis.com/auth/dataplex.read-writehttps://www.googleapis.com/auth/dataplex.readonlyhttps://www.googleapis.com/auth/datastorehttps://www.googleapis.com/auth/documentshttps://www.googleapis.com/auth/documents.readonlyhttps://www.googleapis.com/auth/docshttps://www.googleapis.com/auth/drive.photos.readonlyhttps://www.googleapis.com/auth/drive.appshttps://www.googleapis.com/auth/drive.apps.readonlyhttps://www.googleapis.com/auth/activityhttps://www.googleapis.com/auth/generative-language.tuninghttps://www.googleapis.com/auth/generative-language.tuning.readonlyhttps://www.googleapis.com/auth/generative-language.retrieverhttps://www.googleapis.com/auth/generative-language.retriever.readonlyhttps://www.googleapis.com/auth/generative-language.peruserquotahttps://www.googleapis.com/auth/gmail.drafts.createhttps://www.googleapis.com/auth/gmail.addons.current.message.metadatahttps://www.googleapis.com/auth/gmail.addons.current.message.readonlyhttps://www.googleapis.com/auth/gmail.sendhttps://www.googleapis.com/auth/logging.adminhttps://www.googleapis.com/auth/logging.readhttps://www.googleapis.com/auth/logging.writehttps://www.googleapis.com/auth/monitoringhttps://www.googleapis.com/auth/monitoring.readhttps://www.googleapis.com/auth/monitoring.writehttps://www.googleapis.com/auth/service.managementhttps://www.googleapis.com/auth/service.management.readonlyhttps://www.googleapis.com/auth/spreadsheetshttps://www.googleapis.com/auth/devstorage.write_only
Restricted Drive scopes (8)
https://www.googleapis.com/auth/drive.readonlyhttps://www.googleapis.com/auth/drivehttps://www.googleapis.com/auth/drive.meet.readonlyhttps://www.googleapis.com/auth/drive.metadatahttps://www.googleapis.com/auth/drive.metadata.readonlyhttps://www.googleapis.com/auth/drive.scriptshttps://www.googleapis.com/auth/drive.activityhttps://www.googleapis.com/auth/drive.activity.readonly
Restricted Gmail scopes (10)
https://www.googleapis.com/auth/gmail.readonlyhttps://www.googleapis.com/auth/gmail.modifyhttps://www.googleapis.com/auth/gmail.composehttps://www.googleapis.com/auth/gmail.drafts.readonlyhttps://mail.google.com/https://www.googleapis.com/auth/gmail.metadatahttps://www.googleapis.com/auth/gmail.inserthttps://www.googleapis.com/auth/gmail.settings.basichttps://www.googleapis.com/auth/gmail.settings.sharinghttps://www.googleapis.com/auth/gmail.drafts
3. How Google user data is used
Authorized data is used to provide the account holder with private features such as:
- retrieving and normalizing messages, documents, attachments, and events;
- building private search indexes and contextual memory;
- finding information and relationships across authorized sources;
- summarizing content and answering the account holder’s questions;
- preparing personal briefs, reminders, drafts, and next actions; and
- sending email only when the account holder directs or approves the send action.
Google user data is not used by the operator for advertising, sold, or used to build a public user profile.
4. Storage and retention
The system can copy authorized Google content and derived text into private, operator-controlled working storage, search indexes, and backups. OAuth credentials are kept separately in access-restricted credential storage. Google user data is not stored on this public documentation site.
Stored content and derived indexes can be retained for the life of the operator’s personal archive or until the operator deletes them. There is currently no promised automatic deletion interval. Deleting an item in Google or revoking OAuth access stops or limits future access but does not automatically delete copies or derived data already stored by the system. Backup copies may remain until they are manually deleted or overwritten during ordinary backup maintenance.
5. AI-provider processing and other transfers
When an AI-assisted feature is used, the system may send selected Google content, extracted text, relevant search context, or a user-provided file to OpenAI and/or Anthropic. Those providers may perform functions such as embeddings, transcription, document or image analysis, summarization, and answer or draft generation. Transfers are limited to operating or improving the user-facing feature requested by the account holder; the operator does not transfer Google user data to those providers for advertising or data brokerage.
Google user data may otherwise be disclosed only:
- to service providers needed to operate the account holder’s requested feature;
- to a person the account holder specifically authorizes to assist with the private system;
- when reasonably necessary to investigate a security incident; or
- when required by applicable law.
6. Security
The operator uses scoped OAuth grants, access-restricted credentials, and private systems intended only for authorized personal use. The project includes some broad permissions; operational use is limited to the feature requested by the account holder. Reasonable steps are taken to reduce unauthorized access, disclosure, alteration, or loss. No system can guarantee absolute security, and this policy does not claim that all stored data is encrypted.
7. Account control, revocation, and deletion
An account holder can revoke the system’s future Google access from the Google Account connections page. The account holder can also request deletion of locally stored Google content and derived indexes by emailing sabya@sabya.co. The operator may verify the requesting identity and will identify the active data and backup copies covered by the request before deletion. Revocation alone does not delete previously stored copies.
8. Changes to this policy
This policy will be updated before Google user data is used for a materially different purpose. The effective date above will change when the policy is revised.