Effective August 26, 2026
Privacy policy
This policy explains how ここゆめ handles information for its two approved users. The public compliance site does not use analytics, advertising trackers, cookies, accounts, or application-data storage.
Google data we access
After an approved user chooses to connect Google, the private application requests only identity information needed to bind the authorization to that user, read-only Calendar-list access, and access to events owned by ここゆめ.
- Identity: the authorized Google Account email and subject identifier.
- Calendar selection: calendar name, timezone, and access role so the user can select the intended owned calendar.
- Bounded schedule context: event title, status, start and end, timezone, event link, and location text from the selected calendar for two hours of recent context and the next 21 days, capped at 50 expanded events.
- Application-owned event state: the identifier and status needed to create or verify one event that the user explicitly confirmed.
ここゆめ does not request event descriptions, attendee lists, notes, attachments, conference links, Gmail, Drive files, contacts, or broad Calendar-management access.
How Google data is used
Google data is used only for visible user-facing features: selecting the dedicated calendar, showing schedule-aware planning results, preventing conflicts, and creating or verifying an application-owned event after explicit confirmation.
If an approved user asks an optional AI planning feature to respect Calendar, a bounded summary of the next commitment may be included in a server-side OpenAI request. Those requests use store=false; they are not used by ここゆめ for advertising or generalized model training. Calendar data is not sold.
ここゆめ's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage and security
OAuth credentials are encrypted before server-side storage and are never placed in browser storage, static files, logs, or public pages. The selected Calendar identifier remains inside the encrypted credential envelope. The service stores only the minimum connection metadata, usage safeguards, and application-owned event linkage needed to operate and audit the integration.
The private application is protected by individual Cloudflare Access authentication and a separate exact two-user application allowlist. Production and UAT use separate databases, credentials, provider projects, and environment guards. Encrypted operational backups rotate under a limited retention schedule.
Sharing and human access
Google data is processed only by the infrastructure providers needed to operate the user-requested feature, including Cloudflare, Google, and—only for an explicitly Calendar-aware AI request—OpenAI. ここゆめ does not share Google data with advertisers, data brokers, or unrelated third parties. No person reads Google user data except when an approved user explicitly requests support, when necessary to investigate a security issue, or when required by law.
Control, revocation, and deletion
An approved user can use Disconnect and revoke in the private application's Calendar settings. The application attempts to revoke the Google authorization and deletes its stored Calendar connection and pending OAuth state. The user can also remove access from Google Account connections.
To request deletion of other account-linked application data, email privacy@stolzermedical.com. Encrypted backup copies age out under the documented retention schedule and are not used for normal application access.
Changes
If ここゆめ changes how it accesses or uses Google data, this policy and the in-application disclosure will be updated before the new use begins.