Your Google connection
Last updated September 16, 2026. This policy covers Open Assistant’s
Google connector and the sign-in service at auth.openassistant.cloud,
operated by Quentin Steinke.
What you connect
Open Assistant is self-hosted. Connect only to an installation you own
or trust. Each installation connects one Google account; people with
access to that assistant can ask it to use that account.
- Your email address identifies the connected account.
-
Gmail permissions let your assistant find and read messages, create
drafts, and send drafts after approval.
- Calendar permissions let it read and create events.
-
Drive permissions let it find and read files and documents, and create
files through the assistant.
You choose the account and permissions on Google’s consent screen.
Missing permissions can make some features unavailable.
What the sign-in service handles
The shared service receives your installation address, temporary sign-in
identifiers, Google authorization codes, and access and refresh tokens.
It uses them only to complete the connection, renew access, or revoke
it.
Pending sign-in records are encrypted and expire after ten minutes. The
service deletes a completed record when your installation retrieves the
result. It does not keep a permanent token store or fetch your Gmail,
Calendar, or Drive contents. It uses temporary browser cookies to
protect sign-in. It does not use advertising or analytics cookies.
What your installation handles
Your installation stores Google tokens in its private application
database and calls Google directly. Retrieved content can appear in
conversations, work results, memory, and artifacts on that installation.
Its operator controls retention, backups, and deletion.
When you ask the assistant to work with Google content, relevant content
may be sent to the AI provider configured on your installation to
fulfill your request. Choose a provider whose data handling you accept.
Hosting and AI providers process data under their own terms. This
sign-in service does not send your account contents to an AI provider.
How data may be used
Google data is used to provide the features you request. We do not sell
Google user data, use it for advertising, or use it to train
general-purpose AI models. Open Assistant’s use and transfer of
information received from Google APIs adheres to the
Google API Services User Data Policy, including its Limited Use requirements.
Service operators do not routinely inspect account contents. Information
may be disclosed if legally required, or as necessary to investigate
abuse or protect the service. Sign-in requests traverse our hosting
infrastructure; operational logs can include connection metadata. OAuth
access logging is disabled to avoid recording codes and tokens.
Disconnect and delete
Choose Disconnect in your assistant’s Settings to remove its stored
Google tokens and request revocation at Google. You can also remove Open
Assistant in
your Google account’s connections. Disconnecting does not erase work, messages, documents, or copies
already saved by your installation. Ask its operator to delete those
records and applicable backups.
For questions or deletion requests concerning this shared sign-in
service, contact
quentinsteinke@gmail.com.
Do not send passwords or Google tokens.