Pivot
Effective October 1, 2026 · 生效日期:2026 年 10 月 1 日

Privacy policy

This policy describes how Pivot’s desktop Google integrations and this product website handle information. “Pivot” refers to the developer maintaining the Pivot desktop workspace.

中文版本 ↓

1. Information accessed and why

Pivot uses Google OAuth rather than asking for your Google password. It receives your account email address and verified account identity to identify a connection, the permissions you grant, and authorization credentials needed to call Google APIs.

ServiceInformation and purpose
GmailMessage identifiers, headers and message bodies for searches, reading and summaries. Recipient, subject and body when you request sending or creating a draft.
CalendarCalendar details and events for viewing calendars and a requested time range.
DocsDocument names and content for finding and reading documents.
DriveFile names, identifiers, metadata and supported text exports for file searches and reading.

Only the permissions you grant can be used. Declaring a supported permission does not authorize an operation. Sending mail or creating a draft also follows Pivot’s action approval rules.

2. AI services and your choices

When you request an AI workflow, the relevant content and your request may be sent to the model provider configured in your installation. Review that provider’s privacy practices and service terms before enabling it. Do not use a provider for Google-connected content if its terms allow uses inconsistent with Google’s Limited Use requirements.

Continuous new-mail summaries require separate consent to a specific provider, model and API host. After establishing a current mailbox baseline, Pivot retrieves newly arriving mail and sends its sender, subject, body and relevant date information to that approved service to produce a summary. This task does not load previous conversations or scan the older mailbox. A changed destination requires renewed consent. Set notifications to Off to stop this automatic processing.

3. Storage, sharing and retention

OAuth credentials are encrypted in Pivot’s protected local credential store. The local database stores account connection metadata, granted permissions, app selections, notification checkpoints, pending mail metadata and generated summaries. Workflows may store retrieved content and outputs in local conversation history.

Pending notification summaries are retained until delivery. Delivery clears the queue’s duplicate metadata and summary, while message identifiers remain for deduplication. Delivered content may remain in conversation history and replay data until you remove the applicable local data. Removing a connection does not automatically erase all previously saved conversations or outputs.

Pivot does not sell Google account data, use it for advertising, or use it to train general-purpose AI models. Transfers are limited to Google for API operations and the user-selected model service for the requested or separately approved feature. User-managed remote deployments, backups and other configured services may have additional retention practices. The product website does not host your Google credentials or mailbox; hosting providers may process basic request information such as IP addresses for delivery and security.

4. Google API Limited Use

Pivot’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used to provide the visible, user-requested features described here. Pivot does not provide developers with routine human access to your Google content; any exceptional access must meet the policy’s permitted conditions, including your affirmative agreement when required.

5. Security and access controls

Google API calls use HTTPS; desktop OAuth uses a temporary loopback callback and PKCE. Account access is checked against current authorization and granted scopes. Diagnostic logs are designed to omit access tokens, refresh tokens, authorization codes and product secrets. Security depends also on your device, your model provider and any remote deployment you manage.

6. Your controls and deletion

7. Changes and contact

Material changes to how connected data is processed will be described in an updated policy and, when required, an in-product notice or renewed consent.

Support and privacy contact: trueme521@gmail.com.

隐私政策

本政策适用于 Pivot 桌面 Google 连接器和产品网站。“Pivot”指维护该桌面工作空间的开发者。我们通过 Google OAuth 获取你授权的账号身份、邮箱、权限范围及调用 API 所需凭证,不索取 Google 密码。

访问的数据与用途

Gmail 的邮件标识、发件人、标题、日期和正文用于搜索、阅读及总结;你请求发送或创建草稿时处理收件人和邮件内容。日历连接器读取日历和指定时间范围的事件;文档连接器搜索并读取文档;云盘连接器搜索文件、读取元数据和导出支持的文本。实际操作受你授予的权限及 Pivot 行动审批规则约束。

模型处理

你请求的 AI 工作流可能向本机配置的模型服务发送相关内容。持续新邮件总结须获得你对具体提供方、模型和服务地址的同意,只处理建立基线后新到达的邮件,不回填旧邮箱,不读取历史聊天;目的地变更须重新同意。关闭邮件通知可停止自动处理。请选择符合 Google Limited Use 要求的服务并阅读其政策。

存储、保留与共享

授权凭证保存在加密的本机凭证库。连接信息、权限、应用选择、通知游标、待投递元数据和摘要保存在本机数据库;工作流可能将内容保存到对话历史。投递后清除队列中的重复元数据和摘要,保留邮件标识用于去重;历史对话和回放内容可能继续保存。断开账号不会自动删除既有对话和输出。

Pivot 不销售 Google 数据、不用于广告、不用于训练通用 AI 模型;仅为你请求或单独同意的功能向 Google 或指定模型服务传递必要数据。自行管理的远程部署、备份和模型服务可能有各自的保留规则。此产品网站不保存你的 Google 凭证或邮箱内容,托管服务可能处理访问 IP 等基础请求信息。

权限、安全与删除

API 使用 HTTPS,桌面授权采用临时本机回调及 PKCE;诊断日志避免记录令牌、授权码和密钥。你可停用或移除连接,在 Google 账号中撤销访问,关闭通知或选择接收聊天,并使用产品提供的入口删除本地对话和输出。彻底删除本地数据可向支持联系,自己管理的备份需要另行删除。

Pivot 对 Google API 数据的使用和转移遵守 Google API Services User Data Policy,包括 Limited Use 要求。重要处理方式变更会更新本政策,并按需通知或重新征求同意。

支持与隐私联系:trueme521@gmail.com。