Executor / Privacy

Privacy policy

Effective September 26, 2026

This policy describes the private, self-hosted Executor instance operated by Yannic. It is not the privacy policy for Executor Cloud or for the Executor software publisher. Questions or deletion requests can be sent to yannic@yanniccharlon.com.

Google data

When you authorize a Google connection, Executor uses the permissions shown by Google to carry out tool calls requested by the operator or an authorized agent. The current setup has connections for Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, People, and Meet. Depending on the permissions granted for a connection, data can include messages, drafts, attachments, labels, Gmail settings, Drive files and folders, document and spreadsheet content, presentations, forms and responses, contacts, profile fields, Workspace directory information, calendars and events, or Meet spaces, participants, recordings, and transcripts. Available actions vary by connection and scope. They can include creating, changing, sharing, sending, or deleting Google data.

Executor processes Google API data to perform those requested actions and return the result to the calling agent or client. The result may then be processed by the AI service configured for that agent. That provider's terms and privacy practices apply to its processing. The operator does not use Google API data for advertising or to train generalized AI or machine-learning models.

Product-analytics events do not include Google API responses, email or calendar content, or Drive file contents. They can record the integration plugin key when one is added or removed. If an operator or agent saves an artifact in Executor, that artifact is stored with the instance's local data.

Storage and retention

The Executor application and its SQLite database run on the operator's server. The database stores account and integration configuration, and encrypted connection secrets. The encryption key is kept in the instance's data directory, so access to that server data directory can expose both the encrypted values and the key. Artifacts that a user chooses to save are also stored there.

Connection records and saved artifacts remain until they are removed from the instance. Backups and server logs may retain information according to the operator's server settings. This policy does not set a fixed retention period for those copies.

Product analytics

As currently configured, the self-hosted Executor instance sends product-usage events to PostHog at us.i.posthog.com. The events use a random persistent installation ID and include the app version and coarse events such as whether an execution succeeded, whether it came through the API or MCP, whether an integration was added or removed, and whether an artifact was created, viewed, updated, or deleted. The event code does not include account email addresses, names, hostnames, credentials, tokens, free text, code, tool arguments, or tool results. Integration add/remove events include the integration plugin key, which can reveal the service type but does not identify the connected Google account. PostHog receives ordinary network request information when it receives these events. The instance's operator can disable this analytics feature in the server configuration. See PostHog's privacy policy for its processing details.

OpenTelemetry trace and log export is not configured on this instance. The Executor process writes operational logs to its server container; those logs and their retention are controlled by the server operator.

Other recipients

Google receives requests needed to use the Google services you connect. Other connected services receive the requests you ask Executor to make. An AI provider may receive Google data included in a tool result when that result is returned to an agent using that provider. This policy website is served by Cloudflare, which processes normal request metadata needed to deliver and protect the pages. The static site includes no analytics scripts. See Cloudflare's privacy policy for its processing details.

Your choices

You can remove a Google connection in Executor or revoke its access in your Google Account permissions. To request removal of information stored by this instance, email the operator. Local data, backups, and logs are managed on the operator's server.

Google policy

The instance's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.