Privacy policy
Personal Ops · Last updated September 21, 2026
Scope and operator
Juan Camilo Quintero Hernandez operates Personal Ops, also called Agent OS, exclusively for his own use. This policy covers the private application and these public information pages. The public blog does not ask visitors to connect their Google accounts.
Google data accessed and its purpose
- Account identity: Google account ID, email address, and available profile information identify the connected account. Granted permissions, access and refresh tokens, and expiry information allow authorized access and background syncing.
- Calendar: calendar names, identifiers, visibility, access settings, and timezones; event titles, descriptions, dates and times, status, location, organizer, attendees, and meeting or source links. These support the owner's agenda, daily briefing, and conflict indicators.
- Contacts: names, email addresses, phone numbers, organizations, job titles, and source identifiers and metadata. Imported source records and derived contact records support organization, duplicate review, and links to the owner's private relationship and venture records.
Google Calendar and Contacts permissions are read-only. The application does not modify Google records or send messages or invitations. These integrations do not read Gmail messages or Google Drive files.
Other information
Personal Ops stores the owner's login and session information, preferences, manually entered records, uploaded documents, and operational history. Owner-uploaded health documents are private and are separate from Google Calendar and Contacts access.
The website uses Vercel Analytics for page-usage measurement. Hosting and application services also process technical request and error information to operate and troubleshoot the site. Authentication uses session cookies, and theme preferences are stored in the browser. Calendar event contents and contact records are not intentionally sent as analytics events.
Storage, security, and service providers
Vercel hosts the application, and Neon Postgres stores production application records and encrypted Google credentials. Cloudflare R2 stores private uploaded documents. Document access requires authorization and uses temporary signed links.
A Railway-hosted n8n workflow schedules Calendar refreshes by calling the application. It receives sync outcomes rather than calendar event contents; the application holds the Google credentials. Operational notifications may include failure details.
These providers process information as needed to host, store, secure, and operate the application. Owner-controlled development and preview environments may also contain copies of database records. Access to private application features requires owner authentication, and production connections use HTTPS.
Use and sharing restrictions
Google data is used for the private features described above. It is not sold, published on the blog, used for advertising, or used to train general-purpose AI models. Disclosures are limited to operating these features through service providers, addressing security issues, or meeting applicable legal requirements.
Personal Ops follows the Google API Services User Data Policy, including its Limited Use requirements.
Retention and deletion
Successful Calendar refreshes maintain a rolling event cache covering seven days before today through 30 days ahead. Failed refreshes preserve the last usable cache, so older information can remain until a successful refresh or manual removal.
Imported contacts, source records, merge history, credentials, and other saved application records remain until the owner removes them. There is no automatic expiry for all stored records and no self-service account-deletion feature. Deletion is an owner-operated maintenance action; it must include any retained development or preview copies. Backup copies may remain until the relevant provider's backup retention expires.
The owner can revoke Google access through Google Account connections. Revocation stops future authorized access but does not automatically erase previously imported information. Deleting a local copy does not delete the original Google contact or event.
For a privacy question or a request concerning information about you in the owner's records, contact juancamiloqhz@gmail.com. Requests are reviewed by the operator; identity verification may be needed before disclosing or deleting records.
Changes
This policy will be updated when data practices change. New uses of Google data or permissions require updated disclosures and any necessary authorization before they begin.