XCG Internal
Privacy Policy
Effective and last updated: 7 September 2026
1. Scope
This policy applies to XCG Internal, XC Gradient's self-hosted private operations workspace, and specifically to its optional Google Calendar integration. XCG Internal is restricted to recognized team members through a private Tailscale network.
2. Google data we access
After a member gives explicit OAuth consent, XCG Internal accesses:
- the Google Account's primary email address, to identify the connected account;
- timed events on the connected primary Google Calendar, including event identifiers, iCalendar identifiers, titles, descriptions, start and end times, status, attendees, locations and conferencing links;
- permission to create and update calendar events and Google Meet conference details for Internal meetings.
We request the scopes openid, userinfo.email, and calendar.events. We do not request Gmail, Contacts, Drive, profile, advertising, or location-history access.
3. How we use Google data
Google data is used solely to show a member's work meetings in XCG Internal, keep corresponding Internal and Google events synchronized, prevent duplicate events, reflect cancellations and time changes, and create Google Meet links for online meetings.
Google data is not used to train general-purpose AI models, build advertising profiles, determine creditworthiness, or monitor activity unrelated to the calendar integration.
4. Storage and security
Calendar event data and synchronization identifiers are stored in XC Gradient's self-hosted database. OAuth refresh tokens are encrypted at rest with a key stored separately from the database. Access to the application is restricted by Tailscale identity and role-based authorization.
Access tokens are short-lived and refreshed only as needed to provide synchronization. We apply bounded retries and audit autonomous calendar writes.
5. Sharing and disclosure
We do not sell, rent, or trade Google user data. Data is transmitted to Google only when reading or writing the connected calendar. It may be processed by infrastructure providers strictly as necessary to operate XC Gradient's systems, subject to appropriate confidentiality and security controls.
We may disclose information if legally required, or when necessary to protect users, XC Gradient, or the public from fraud, abuse, or security threats.
6. Retention, disconnection and deletion
A member may disconnect Google Calendar from the identity menu in XCG Internal. Disconnection revokes or removes the stored authorization and stops future synchronization. Synchronization bindings and copied meeting records are retained only while needed for Internal operations and audit obligations.
A current or former team member may request deletion of their Google connection data by contacting us. We will remove the stored OAuth token and associated synchronization metadata unless retention is required by law or a legitimate security obligation.
7. Google API Services policy
XCG Internal's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Contact and changes
Questions, access requests and deletion requests may be sent to [email protected].
We may update this policy when the integration or legal requirements change. The current effective date will always appear above.