ExoCortex · Google collector

Privacy policy

Effective October 5, 2026

This policy covers the Google collector for ExoCortex, a personal app operated by Alan Shurafa, and this public informational website. It describes the current collector, which writes exports on the owner’s computer. It does not claim that future import or AI features are already operating.

Data accessed

After an account holder authorizes the app, the collector can read Gmail messages, including identifiers, labels, dates, headers, senders and recipients, subject lines, and message bodies. A message response can include attachment metadata. The collector may retrieve an attached text body when needed to reconstruct the message; this is not a general attachment-download feature.

The collector also reads Calendar event responses, which may contain titles, descriptions, dates and times, locations, attendees, and other event details returned by Google.

The app requests read-only access to saved contacts and “Other contacts.” Contact polling is not implemented in the current collector, so it does not currently export those records.

Why the data is used

The data is used for the owner’s personal archive and preparation for import into his private ExoCortex installation. The current collector creates local export batches; it does not call AI services or write directly to a hosted database.

Google account data is not sold, used for advertising, or used to train, develop, or improve generalized artificial-intelligence or machine-learning models. ExoCortex’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Storage and access

Export batches, collection state, and receipts are stored as files on the owner’s computer. Google authorization credentials are stored separately and protected with Windows Data Protection API encryption. Export files are not covered by that credential encryption; access to them depends on the computer’s access controls and any storage protection the owner configures.

The current collector communicates with Google to obtain authorized data and refresh access. It does not upload collected account data to this public website. No third-party AI service receives these exports from the collector itself. Before adding hosted storage or other processing that changes these practices, this policy must be updated to describe the data, recipients, and purpose.

Retention, stopping, and deletion

Exports remain until the owner removes them. The current collector has no automatic retention period or feed-cleanup function. Uninstalling its scheduled task stops polling but leaves existing exports, state, and credentials in place.

The account holder can revoke the app’s access through Google Account connections. Revocation stops use of that grant; it does not delete previously exported files. Removal of local exports, downstream copies, and any backups is a separate action. For help locating and removing stored copies, contact shurafa@gmail.com.

This informational website

This site has no account sign-in, collection form, advertising, or analytics code. Its hosting provider may process ordinary request information, such as IP addresses and request times, to deliver the pages and operate its service. The pages contain no Google account exports or authorization credentials.

Changes and contact

Material changes to data handling will be reflected here before the changed feature is used. Questions or data-removal requests can be sent to Alan Shurafa at shurafa@gmail.com.