XC GRADIENT

XCG Internal

Privacy Policy

Effective and last updated: 7 September 2026

Summary. XCG Internal uses Google Calendar data only to provide calendar synchronization requested by XC Gradient team members. We do not access Gmail, sell Google user data, use it for advertising, or disclose it for unrelated purposes.

1. Scope

This policy applies to XCG Internal, XC Gradient's self-hosted private operations workspace, and specifically to its optional Google Calendar integration. XCG Internal is restricted to recognized team members through a private Tailscale network.

2. Google data we access

After a member gives explicit OAuth consent, XCG Internal accesses:

We request the scopes openid, userinfo.email, and calendar.events. We do not request Gmail, Contacts, Drive, profile, advertising, or location-history access.

3. How we use Google data

Google data is used solely to show a member's work meetings in XCG Internal, keep corresponding Internal and Google events synchronized, prevent duplicate events, reflect cancellations and time changes, and create Google Meet links for online meetings.

Google data is not used to train general-purpose AI models, build advertising profiles, determine creditworthiness, or monitor activity unrelated to the calendar integration.

4. Storage and security

Calendar event data and synchronization identifiers are stored in XC Gradient's self-hosted database. OAuth refresh tokens are encrypted at rest with a key stored separately from the database. Access to the application is restricted by Tailscale identity and role-based authorization.

Access tokens are short-lived and refreshed only as needed to provide synchronization. We apply bounded retries and audit autonomous calendar writes.

5. Sharing and disclosure

We do not sell, rent, or trade Google user data. Data is transmitted to Google only when reading or writing the connected calendar. It may be processed by infrastructure providers strictly as necessary to operate XC Gradient's systems, subject to appropriate confidentiality and security controls.

We may disclose information if legally required, or when necessary to protect users, XC Gradient, or the public from fraud, abuse, or security threats.

6. Retention, disconnection and deletion

A member may disconnect Google Calendar from the identity menu in XCG Internal. Disconnection revokes or removes the stored authorization and stops future synchronization. Synchronization bindings and copied meeting records are retained only while needed for Internal operations and audit obligations.

A current or former team member may request deletion of their Google connection data by contacting us. We will remove the stored OAuth token and associated synchronization metadata unless retention is required by law or a legitimate security obligation.

7. Google API Services policy

XCG Internal's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Contact and changes

Questions, access requests and deletion requests may be sent to [email protected].

We may update this policy when the integration or legal requirements change. The current effective date will always appear above.