1. Affirmative Limited Use Statement
Oxiom's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Oxiom does not request Gmail restricted scopes. Raw and derived Google user data is not transferred to third-party services for training AI or ML models, is not used for advertising, and is not sold. Where AI features are invoked by the user, requests are sent only to OpenAI's REST API, whose terms prohibit training on API customer data.
2. What Oxiom Mobile Does
Oxiom Mobile (m.oxiom.me) is a Progressive Web App that unifies meetings, tasks, reminders, and email behind one AI-assisted mobile interface. Once the user connects their Google account, Oxiom can display and act on Google Calendar and Google Tasks inside the app. Email is handled exclusively via user-configured IMAP/SMTP accounts (Gmail, Outlook, corporate mail servers, etc.); Oxiom does not access Gmail through Google APIs.
3. Google Scopes Requested and Their Purpose
We follow the principle of least privilege — each scope maps to a specific, user-facing feature. No scope is requested speculatively.
- userinfo.profile, userinfo.email— identify the signed-in Google user and link the account to the user's Oxiom profile.
- https://www.googleapis.com/auth/calendar.events — display upcoming meetings in the daily briefing and create or reschedule events when the user explicitly asks (including via voice commands such as "move the meeting to 2pm").
- https://www.googleapis.com/auth/tasks — display and edit the user's Google Tasks list inside the app.
Oxiom does not request any Gmail restricted scopes (gmail.readonly, gmail.send, or any other /auth/gmail.*). Users who want email inside the app configure a standard IMAP/SMTP account instead.
Full details on how each scope is used are also documented in Section 3 of the Privacy Policy.
4. AI Processing of Google User Data
Oxiom integrates with one — and only one — third-party AI provider: OpenAI, Inc. The app connects directly to api.openai.com; no aggregator, gateway, or model hub is used.
- Provider: OpenAI, Inc. (San Francisco, USA)
- Plan: pay-as-you-go OpenAI API (project-scoped API key)
- Models:
gpt-4o,gpt-4o-mini,gpt-4.1-mini(chat completions),whisper-1(speech-to-text),tts-1(text-to-speech) - When data is sent:only when the user explicitly triggers an in-app action that requires AI (e.g. a voice command like "what's my next meeting" or "reschedule my 10 a.m. to Thursday"). Google user data is never sent to OpenAI as part of a background job.
- Training: per OpenAI's Enterprise Privacy and API data-usage policy, OpenAI does not use API customer data to train its models unless the customer explicitly opts in. Oxiom has never opted in. No Google user data forwarded to OpenAI is used to train, fine-tune, or otherwise develop any AI/ML model.
- Retention at OpenAI: up to 30 days for abuse-and-misuse monitoring, then deleted.
- Self-hosted or offline models: not applicable. Oxiom does not operate any self-hosted or offline AI models.
- Other AI providers: none. Oxiom does not integrate with Anthropic, Google Gemini, Cohere, Groq, Perplexity, Mistral, Replicate, Azure OpenAI, AWS Bedrock, OpenRouter, Together AI, Fireworks, or any similar service.
5. What We Do Not Do
- We do not sell Google user data to any third party.
- We do not use Google user data for serving advertisements — retargeting, personalized, or interest-based — in any form.
- We do not use Google user data to build, improve, or train generalized or foundational AI or ML models, either our own or those of any third party.
- We do not permit humans to read Google user data, except: (a) with the user's explicit consent for the specific data, (b) for security purposes such as investigating abuse, (c) when required by law, or (d) when the data has been aggregated and anonymized for internal operations.
- We do not transfer Google user data to third-party services except as necessary to deliver features the user has activated, to comply with applicable law, or in the context of a merger, acquisition, or sale of assets with the user's explicit prior consent.
6. Revoking Access
Users can disconnect Oxiom from their Google account at any time — either from Settings inside the app ("Disconnect Google") or at myaccount.google.com/permissions. When access is revoked, all Google OAuth tokens are deleted from our database.
7. Contact
Questions about Oxiom's use of Google APIs?
- Privacy: [email protected]
- General: [email protected]
- Company: Oxiom d.o.o., Podgorica, Montenegro
For the full Privacy Policy, see /privacy-policy. For Terms of Service, see /terms-of-service.
