Open AssistantPrivacy

Your Google connection

Last updated September 16, 2026. This policy covers Open Assistant’s Google connector and the sign-in service at auth.openassistant.cloud, operated by Quentin Steinke.

What you connect

Open Assistant is self-hosted. Connect only to an installation you own or trust. Each installation connects one Google account; people with access to that assistant can ask it to use that account.

You choose the account and permissions on Google’s consent screen. Missing permissions can make some features unavailable.

What the sign-in service handles

The shared service receives your installation address, temporary sign-in identifiers, Google authorization codes, and access and refresh tokens. It uses them only to complete the connection, renew access, or revoke it.

Pending sign-in records are encrypted and expire after ten minutes. The service deletes a completed record when your installation retrieves the result. It does not keep a permanent token store or fetch your Gmail, Calendar, or Drive contents. It uses temporary browser cookies to protect sign-in. It does not use advertising or analytics cookies.

What your installation handles

Your installation stores Google tokens in its private application database and calls Google directly. Retrieved content can appear in conversations, work results, memory, and artifacts on that installation. Its operator controls retention, backups, and deletion.

When you ask the assistant to work with Google content, relevant content may be sent to the AI provider configured on your installation to fulfill your request. Choose a provider whose data handling you accept. Hosting and AI providers process data under their own terms. This sign-in service does not send your account contents to an AI provider.

How data may be used

Google data is used to provide the features you request. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Open Assistant’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Service operators do not routinely inspect account contents. Information may be disclosed if legally required, or as necessary to investigate abuse or protect the service. Sign-in requests traverse our hosting infrastructure; operational logs can include connection metadata. OAuth access logging is disabled to avoid recording codes and tokens.

Disconnect and delete

Choose Disconnect in your assistant’s Settings to remove its stored Google tokens and request revocation at Google. You can also remove Open Assistant in your Google account’s connections. Disconnecting does not erase work, messages, documents, or copies already saved by your installation. Ask its operator to delete those records and applicable backups.

For questions or deletion requests concerning this shared sign-in service, contact quentinsteinke@gmail.com. Do not send passwords or Google tokens.