Policy
Privacy
The short version: Google Calendar and Gmail data is processed for the command you request. It is not collected by this website, sold, or used for advertising.
Scope
This policy applies to Xiaotian Workspace CLI and this public policy website. The CLI is a personal, invite-only tool operated by xiaotian.dev. It is not a Google product and is not affiliated with Google.
Google data the CLI can access
Depending on the workflow the user authorizes, the CLI may access:
- basic Google identity information used to select and verify an account;
- the list of calendars the user can access;
- calendar metadata, including identifiers and access roles;
- calendar events, including event details needed to read, create, update, or delete an event at the user’s direction; and
- Gmail mailbox data, including messages, threads, headers, participants, labels, drafts, attachments, and the state needed to read, search, send, organize, or permanently delete mail at the user’s direction.
How data is used
Google user data is used only to perform an action the user explicitly requests, to show the result, and to verify that an operation targets the intended account and resource. Gmail’s full-access scope is used because complete mailbox workflows can include reading, searching, sending, drafting, labeling, archiving, moving, or deleting mail; a read-only scope cannot perform those user-requested writes.
When the user explicitly requests model-assisted analysis, selected Google data may be sent by the user’s local agent to the AI provider they configured for that task. This transfer is limited to providing the requested user-facing feature and is governed by that provider’s terms. The application does not use Google data for advertising, unrelated profiling, or credit decisions.
Storage and processing
The CLI calls Google APIs directly from the user’s device. OAuth credentials are managed by the local gws profile, using encrypted credential storage and permission-restricted local files. Xiaotian Workspace CLI does not operate a server that receives or stores Google Calendar or Gmail content.
Selected command output may remain in local terminal history, local agent session history, or user-created exports and backups. These local records remain under the user’s control.
This policy website is static. It does not use forms, cookies, client-side JavaScript, advertising pixels, or analytics. It is hosted by Vercel, and its DNS is managed by Cloudflare; those providers may process ordinary request metadata needed to deliver and secure the site.
Sharing and sale
Google user data is not sold. It is not shared with advertisers, data brokers, or unrelated third parties. Data is transmitted to Google APIs, processed on the user’s device, and—only when the user requests a model-assisted feature—may be sent to the user’s configured AI provider as needed to complete that request.
Retention and deletion
The application does not retain Google Calendar or Gmail data on an application server. Local command output, agent session history, or user-created exports and backups remain under the user’s control.
A user can remove access by running gws auth logout with the relevant profile, deleting that local profile, or revoking the application from their Google Account’s connected-app settings. See the support page for practical instructions.
Security
Accounts and service boundaries use separate local profiles. Credential files are permission-restricted, credentials are encrypted where supported by gws, and each profile requests only the scopes needed for its declared workflows. The CLI verifies the active account and target resource before write operations.
Google API Services User Data Policy
Xiaotian Workspace CLI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Changes
Material changes will be published on this page with a revised effective date. The application will not silently expand its use of Google data beyond the purposes described here.
Contact
Questions about privacy or data removal can be sent to tianyupeiandy@gmail.com.