PHUONG GROUP

Context One Google OAuth Disclosure

Production-readiness package · October 6, 2026

Application: Context One

Homepage: https://phuonggroup.com/context-one.html

Privacy: https://phuonggroup.com/context-one-privacy.html

Authorized domain: phuonggroup.com

Redirect URI: https://phuonggroup.com/api/context-one/google/callback

Requested native scope

https://www.googleapis.com/auth/calendar.events.readonly

Purpose: read Calendar events so Context One can derive metadata-only work signals such as timing, duration, recurrence and attachment presence. No Calendar write scope is requested.

Scopes intentionally not requested

Callback architecture

The verified-domain callback forwards only OAuth code, state or error parameters to the Context One backend. The PHUONG GROUP callback proxy does not exchange, persist or log Google access or refresh tokens.

Data flow

  1. User enables Calendar metadata consent.
  2. Google redirects to the verified-domain callback.
  3. The callback forwards the authorization response to Context One's backend.
  4. Context One exchanges the code server-side using the same verified redirect URI.
  5. Tokens are encrypted with AES-256-GCM in a per-user vault.
  6. Calendar API calls use a field mask; raw event records are not retained as an archive.
  7. Derived work patterns are presented for user review.