Mac Household Ledger Sync
Privacy policy
Last updated: October 3, 2026
This policy describes the household ledger software and its planned Gmail connection. Gmail sync remains disabled until the account owner completes consent and separately activates it. No Gmail content or OAuth token has been collected by this service as of the date above.
Information the ledger may read
After activation, the ledger is limited to one configured household Gmail account and Google's gmail.readonly permission. It indexes Gmail message IDs and metadata such as sender, subject, date, labels, snippet, thread ID, and a link back to Gmail. Its initial index includes archived, Spam, and Trash messages. It does not fetch attachments or change, send, archive, label, or delete messages.
A full message body is fetched only after an explicit request for a present email linked to an active household task. The body is cached in the local ledger database for that use.
Where information is stored
The ledger is designed to store its index, task links, task history, and any fetched body in SQLite on the household Mac. OAuth tokens are stored in that Mac's native Keychain. The public website is informational and has no forms, analytics, or account sign-in.
The application does not enforce encryption for the database or backups. Backups are created manually; the application does not automatically expire or purge backup copies. The household operator is responsible for securing the Mac and any backup destination.
This informational website is hosted on Cloudflare Pages. Cloudflare may process technical data about page requests under its own privacy practices.
Retention and removal
There is no time-based deletion of indexed metadata, task links, or task history. If Gmail reports a message missing, the ledger marks it absent and clears its cached body while retaining the metadata row and related task history. Completing a linked task clears the cached body only when no other active task still links that email. Manually made backups may retain earlier copies.
Disconnecting removes the OAuth token from the Mac's Keychain. Revoking the grant asks Google to revoke it and removes the local token only if revocation succeeds. These actions do not automatically erase the ledger database, task history, or backups.
Sharing with an assistant
The ledger's assistant interface returns task information and email context to the connected assistant when requested. Email snippets and full bodies require separate, explicit requests; the full body tool is limited to a present email linked to an active task. Content returned to the assistant leaves the local ledger boundary. The assistant provider's processing, storage, and retention policies apply, and this software does not control them.
Contact and changes
For privacy questions, use the support contact displayed on the Google authorization screen or contact the household administrator. This policy should be updated if the storage location, assistant connection, or data handling changes.