Root AI Exec

Privacy Policy

Last updated 22 September 2026

Root AI Exec is a private executive intelligence assistant operated for a single principal. This policy describes what it accesses, why, and how long it keeps it.

Google account access

With the user's explicit authorisation through Google OAuth, Root AI Exec may access their Google Calendar. The application requests one calendar permission:

It also receives the basic identity information Google includes with a sign-in (openid, email, profile) in order to complete the authorisation.

The access is read-only. Root AI Exec cannot create, modify, or delete calendar entries, and it does not request permission to do so. It requests no access to Gmail, Drive, Contacts, or any other Google service.

Access is limited to exactly the permissions the user grants. If Google were to return a broader grant than the one requested, the application refuses the connection rather than accepting it. The user also chooses which individual calendars may be read; calendars they do not select are never fetched.

How calendar data is used

Calendar data is used only to provide the assistant's own functionality for the user who authorised it: understanding what is scheduled, organising commitments and priorities, providing scheduling context, and answering the user's questions about their own recorded context.

It is not used for anything else. Specifically:

Processing

The application runs locally on hardware the user controls. To produce written answers it sends the relevant retrieved context to a third-party large language model provider over an encrypted connection. Only the context needed to answer the question at hand is sent, and the user's stored credentials and access tokens are never included.

Apart from that model provider, calendar content is not transmitted to any third party.

Storage and retention

Authorised calendar data is stored so the application can function — a system that re-fetched everything on each question would be slower and would make more requests to Google, not fewer. Storage is on hardware the user controls, on an encrypted disk.

Stored calendar data is kept under a rolling retention window, currently 90 days, after which it ages out. The user can delete all stored calendar data at any time; doing so removes both the stored entries and everything derived from them.

Credentials and tokens

OAuth access and refresh tokens are treated as secrets. They are stored locally with file permissions restricting them to the operating-system user, are never written to logs or diagnostic output, are never included in anything sent to a model provider, and are never displayed in the interface. Diagnostics report only whether a credential is present, never any part of its value.

Revoking access

The user may revoke Root AI Exec's access to their Google account at any time, with no notice and for any reason, at myaccount.google.com/permissions. Revocation immediately prevents any further access.

The application also provides its own disconnect function, which revokes the grant with Google and deletes the locally stored tokens, and a separate function that deletes stored calendar data.

Clinical and patient data

Root AI Exec is not designed for, and is not intended to process, patient records, clinical records, or other regulated health information. It is not a clinical system. Users should not enter such information into it.

Children

Root AI Exec is a private tool for its own operator and is not directed to, or intended for use by, children.

Changes

If this policy changes, the revised version will be published on this page with an updated date above.

Contact

Questions about this policy or about data handling: privacy@rootaiexec.com