Privacy policy
Effective September 17, 2026. Operator: Joe Visinski. This policy covers the private Noah Google integration and its information website.
Data and purpose
Authorized Google data is used for owner-requested email assistance, response preparation, calendar support, analytics, SEO assessment and related business operations. Depending on the permissions granted, this can include email bodies, attachments and metadata, calendar information, website performance reports and tracking configuration. Only data needed for an authorized task should be accessed. Permissions and operating approvals control which actions can be taken.
Processing and recipients
Noah runs using Hermes software on the operator’s computer. Relevant requests, retrieved data and results are processed through OpenAI’s Codex service. Processing is not exclusively local. The operator has confirmed that the connected account’s “Improve the model for everyone” setting is off. This opt-out is not a claim of zero provider retention or an audit of every provider setting.
Responses and summaries may pass through the owner-selected messaging service, including Telegram or Discord. Supporting services are used as necessary for explicitly requested tasks; Google data must not be sent to unrelated services. Netlify hosts this static information site and processes web requests, including technical connection data, under its own policies. The public site contains no mailbox content, OAuth credentials, analytics scripts or submission forms.
Limited use
Noah’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used to provide the owner-facing features described here, not sold, used for advertising or credit decisions, or used to train generalized AI models. Transfers are limited to providing authorized features, security, legal requirements, or other purposes expressly permitted by that policy. Human access outside the account owner is limited to the owner’s affirmative agreement for specific data or exceptions allowed by the policy.
Storage and protection
Authorized content and derived reports can persist in local operating files, conversation histories, logs, memory records and any applicable backups. These records do not have a single automatic deletion deadline. OAuth credentials are kept separate from public site files and protected with restricted local file permissions. Provider-side retention is governed by the applicable service terms and account controls; turning off training does not necessarily delete stored content. No system can guarantee absolute security.
Revocation and deletion
Review or revoke access in Google Account connections. Revocation stops future use of that authorization but does not automatically erase previously retained reports or conversations. To request access to, correction of, or deletion of retained records, contact joe@rhcapadvisors.com. The operator will identify the relevant local records and service-held copies, remove what is under the operator’s control as appropriate, and explain any provider, backup or legal-retention limitations. Requests do not carry a guaranteed immediate deletion timeline.
Changes
Material changes to Google-data use will be disclosed before the new use begins, with renewed consent where required. This application is not intended for children or public enrollment.