Context One Privacy Policy
Effective October 6, 2026
Information processed
Context One may process account identifiers supplied by the sign-in provider; information you directly provide; reviewed context facts, corrections, workflow candidates and benchmark feedback; and, when explicitly connected, limited Google Calendar event fields needed to derive work patterns.
Google user data
Context One requests https://www.googleapis.com/auth/calendar.events.readonly. Calendar data is used only to detect recurring work patterns, update your user-controlled Work Graph and show derived workflow opportunities. It is not used for advertising, sale of data, credit decisions or unrelated profiling.
Context One's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data minimization and retention
- Calendar requests use a field mask for start/end time, recurrence indicator, event type/status and attachment presence.
- Raw Calendar event records are processed transiently and are not retained as an event archive.
- Derived patterns and user-approved context may be stored as product output.
- Calendar sync tokens may be stored to process changes incrementally.
- OAuth tokens are encrypted at rest with AES-256-GCM in a per-user vault and plaintext tokens are never returned to the browser.
AI processing
Normalized metadata and user-provided context may be processed by AI infrastructure solely to provide extraction, pattern detection and evaluation features. Context One is designed to send the minimum information needed for the requested feature.
Sharing
We do not sell Google user data or personal data. Infrastructure providers may process data only as needed to operate authentication, hosting, databases, security and AI functionality.
User controls
You can review or reject inferred context, choose connector consent, disconnect Google, revoke provider access and stop using Connector Bridge. Disconnecting Google removes the encrypted local token vault and connector checkpoints after revocation succeeds.
Security
Controls include per-user separation, encrypted token storage, least-privilege OAuth scopes, bounded incremental synchronization, audit events and fail-closed readiness checks.
Contact
Context One is a PHUONG GROUP project. Privacy and data-rights requests may be initiated through phuonggroup.com. Do not send passwords or OAuth secrets through chat.