Privacy Policy
This Privacy Policy explains how Sofia Automation accesses, uses, stores, and shares Google user data and other operational information used by the automation system.
1. Purpose and scope
Sofia Automation is a private user-operated automation platform for structured operational records, equipment and maintenance workflows, documents, reports, and automation health/state management. It is not a public advertising or data-broker service.
2. Google user data accessed
Depending on the enabled module, Sofia Automation may access the following Google services:
- Google Sheets: read and update structured operational records, task lists, equipment registries, service logs, and related tables.
- Google Drive: read, create, organize, or store documents, reports, folders, and files used by configured workflows.
- Google Docs: read and update the persistent SOFIA synchronization memory document and other specifically configured documents.
- Gmail: a narrowly configured workflow may search for messages matching a specific report subject, read matching PDF attachments, copy those reports to a configured Google Drive folder, and apply workflow labels indicating processed or error status.
- Google Apps Script: execute configured automation code and manage only the installable triggers required by those workflows.
3. How Google user data is used
Google user data is used only to perform the operational functions requested and configured by the account owner, such as updating records, archiving reports, checking system health, and maintaining automation continuity. The system does not use Google user data for advertising, profiling for marketing, or sale to third parties.
4. Data storage and retention
Primary operational data remains in the user's Google account and configured Google Workspace files. Limited technical state, deployment metadata, audit results, and automation outputs may be stored in a private GitHub repository to support source control, recovery, and verification of completed automation actions.
OAuth credentials, access tokens, refresh tokens, client secrets, private keys, and other secret values are not intentionally stored in public website files, ordinary GitHub source files, or the SOFIA synchronization memory document. Protected credentials are intended to be stored only in appropriate secret-storage mechanisms such as protected GitHub repository secrets or Google's own authorization storage.
5. Data sharing
Sofia Automation does not sell Google user data and does not share it with advertisers or unrelated marketing services. Data may be processed by infrastructure providers required to operate the configured workflows, including Google services and GitHub, subject to their respective terms and privacy practices.
6. Security and minimization
The system is designed to request only the Google OAuth scopes required for its active features. Automation workflows use explicit module boundaries, controlled write operations, readback checks where applicable, and separate secret storage for sensitive credentials.
7. User control and deletion
The account owner can revoke Sofia Automation's Google access through their Google Account security settings. Operational files and records can be deleted from the relevant Google services by the account owner. Technical logs or state stored in the private GitHub repository can also be removed by the repository owner.
8. Google API Services User Data Policy
Sofia Automation's use and transfer of information received from Google APIs is intended to comply with the Google API Services User Data Policy, including applicable Limited Use requirements.
9. Changes to this policy
This policy will be updated when the system materially changes how it accesses, uses, stores, or shares Google user data. The effective date at the top of this page will be updated accordingly.