Privacy Policy
CATO is a private personal assistant used by one person, its developer, Joe Hughes. This policy explains what Google user data CATO accesses, how it is used, where it is kept, and how access can be removed.
1.Who operates CATO
CATO ("Compelled Assistant for Task Orchestration") is built, operated, and used by Joe Hughes, an individual. It is not a company product. Questions about this policy or about data handled by CATO can be sent to fivewhole@gmail.com.
2.Who CATO is for
CATO is used only with Google accounts that belong to Joe Hughes. It does not offer sign-up, it does not accept other users, and no one else can connect a Google account to it. Access to CATO's chat interface is restricted to Joe's own Telegram account; messages from anyone else are ignored.
3.Google data CATO accesses
CATO requests only the Google API scopes it needs. Currently and as planned:
-
Gmail, read-only
(
https://www.googleapis.com/auth/gmail.readonly). Gives access to email messages and their metadata (sender, recipients, subject, date, labels, and message body). CATO uses it to find job alert emails in Joe's inbox and pull out the job listings they contain. Later, it will also use it to summarize and triage Joe's mail for him. This scope cannot send, delete, or change email. - Google Calendar (not yet requested). If and when calendar features are added, CATO will request calendar scopes to read and manage events on Joe's own calendars, and this policy will be updated to name the exact scopes before they are requested.
If CATO later needs to draft replies, it will request the narrowest additional Gmail scope that allows it, and nothing will be sent without Joe approving it first. This policy will be updated before any new scope is requested.
4.How the data is used
Google user data is used only to provide CATO's features to Joe. Specifically, it is:
- not used for advertising, including targeted, personalized, or retargeted ads;
- not sold, rented, or traded;
- not shared with or transferred to third parties, except the service provider described in section 5 that is needed to generate CATO's responses;
- not used to determine creditworthiness or for lending purposes;
- not used to develop, improve, or train generalized or non-personalized AI or machine-learning models;
- not read by any human other than Joe.
5.AI processing
To generate its responses, CATO may send the relevant parts of an email or calendar entry (for example, the text of a job alert) to Anthropic's Claude API. Anthropic processes this data under its Commercial Terms of Service, which do not allow Anthropic to train its models on API inputs or outputs by default. Only the text needed for the task at hand is sent.
Anthropic is the only third party that processes Google user data on CATO's behalf. CATO's replies to Joe, which can include summaries of his own data, are delivered to him through Telegram, the messaging app he uses to talk to CATO.
6.Storage and security
- CATO runs on a private server controlled by Joe. Its data is stored there and nowhere else, apart from that server's backups.
- Google OAuth credentials (including refresh tokens) are encrypted at rest. Short-lived access tokens are held in memory only and are never written to logs.
- Access to the server is limited to Joe, using SSH key authentication.
- All data in transit to and from Google, Anthropic, and Telegram uses HTTPS (TLS).
7.Retention and deletion
- Full email content is not stored. CATO keeps only the job details it extracts from job alert emails (such as the job title, company, location, and listing link) and the message identifiers it needs to avoid processing the same email twice.
- CATO keeps short-lived nightly backups of its database (the last 7 days) so mistakes can be undone. Deleted data leaves those backups as they roll over.
- Data is deleted on request, and all of it, including stored Google credentials, is deleted if CATO is shut down. To request deletion, email fivewhole@gmail.com.
8.Revoking access
Access CATO has been granted to a Google account can be removed at any time from that account's third-party access page: https://myaccount.google.com/permissions. Once access is revoked, CATO can no longer read any data from that account.
9.Google API Services User Data Policy
CATO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10.Changes to this policy
If this policy changes, the updated version will be posted on this page with a new "Last updated" date. Any change that expands the Google data CATO accesses or how it is used will be posted here before the change takes effect.