Effective October 9, 2026
Privacy Policy
This policy covers Task231 MOS Bridge and its credential manager, operated by Mike Blake for his private MOS workflow. It describes the approved data practices; publication of this policy does not authorize credential enrollment or live execution.
Google information accessed
- Account identity: the consenting account’s email address and Google account identifier, used to verify the approved owner.
- Spreadsheet data: the authorized MOS assignment, linked task, directive receipt, and execution checkpoint information required by an approved operation.
- OAuth credentials: access and refresh credentials returned by Google, used to authenticate approved Google API requests.
The requested Google OAuth scopes are https://www.googleapis.com/auth/spreadsheets and https://www.googleapis.com/auth/userinfo.email. The Sheets scope can permit reads and writes across spreadsheets accessible to the consenting account, including shared spreadsheets. The intended application use is constrained to the approved MOS workbook and authorized operations.
How information is used
Information is used to verify identity, check current assignment authorization, read assignments, enforce claims, append checkpoints, submit results, and maintain an audit trail. The application does not use Google user data for advertising, profiling, sale, or training generalized AI or machine-learning models.
Storage and protection
Spreadsheet records remain in Google Sheets. The approved credential lifecycle stores refresh credentials encrypted on the owner’s host; access credentials are held temporarily in protected runtime storage and memory. A local journal retains secret-free authorization and execution metadata for audit and recovery. Credentials must not be placed in chat, source code, clipboard, command-line arguments, or ordinary logs. Host administrators remain trusted.
Sharing and service providers
Google processes authentication and spreadsheet API requests. Authorized MOS operators and the bounded executor may receive the assignment information and results necessary for the workflow. Bearer credentials are not delivered to the bounded executor. The public information website uses hosting infrastructure that may process standard request metadata, such as IP addresses and browser information, to serve and secure these pages. These pages contain no Google sign-in, token intake, analytics scripts, or forms.
Google user data is not sold or shared with advertisers. Any transfer or disclosure must serve the disclosed application functionality, comply with applicable requirements, or occur at the owner’s direction. Task231 MOS Bridge’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Temporary access credentials are discarded locally at expiry, run termination, or failure cleanup. Local cleanup does not by itself revoke a credential at Google. The encrypted refresh grant is retained until access is revoked or the approved lifecycle is decommissioned. MOS records and secret-free audit metadata are retained under the owner’s recordkeeping decisions; no automatic deletion period is currently specified.
Control and revocation
The owner may revoke Google authorization through Google Account connections. Revocation can prevent subsequent renewal and API access. To request local credential removal or review of retained records, contact the operator. Revoking authorization does not automatically delete existing MOS records.
Changes and contact
Material changes to data practices require an updated policy and any applicable scope or release approval. Contact Mike Blake at wtrskimike@gmail.com.