LFG Labs · LFG Vault Sync
Privacy policy
Updated
LFG Labs operates LFG Vault Sync, an internal tool that turns authorized business updates into records in a private knowledge vault and a morning brief. This policy covers that tool and its public information pages. It does not replace separate agreements for client services.
What Google data we access
The Google Drive connection requests the read-only permission drive.readonly. Google grants this permission across the files the connected account can access. It is not a per-folder permission. The app cannot use this permission to edit, delete, upload or change sharing on Drive files.
We read the connected account's name, email address and account identifier to check that we are using the intended account. We also read file metadata, including names, IDs, types, timestamps, links and folder references. The current reader can export Google Docs text for relevant business records. Other file types currently have metadata-only coverage.
Collection uses time windows and business relevance checks. The reader filters recognizable personal filenames and credential-bearing text. These checks are not a guarantee that every sensitive detail will be detected. Operators must review material before retaining or sharing it.
Why we use it
We use this information to identify new or changed work, preserve source references, update the appropriate business or client notes, and prepare briefings with suggested actions. The operator reviews AI-generated interpretations. This Drive authorization does not grant access to Gmail, Calendar or any other Google service.
Where data goes and who can access it
- Google supplies the authorized files and account information through its Drive API.
- The operator's computer stores the knowledge vault. Selected business records, source links and derived notes can also be committed to the operator's private GitHub repository. Repository collaborators and anyone with access to a local vault copy can read those saved records.
- Configured AI services process relevant content to produce notes and briefs. These include OpenAI through Codex and Anthropic when the operator uses Claude with the vault. Provider terms and the operator's account settings govern their processing and retention. Processing is not exclusively local and may take place outside the operator's country.
- Vercel hosts these public pages and processes normal web request information, such as IP address, browser information and requested URL, to serve and secure the site. The website does not host the vault or receive the Drive connection's OAuth credentials.
We do not sell Google user data or use it for advertising, credit decisions or training our own general-purpose AI models. We limit its use and transfer to the requested vault and briefing functions, security needs and applicable legal obligations, under the Google API Services User Data Policy, including its Limited Use requirements. A public privacy policy does not make connected Drive files public.
Storage, retention and security
OAuth credentials stay in restricted local files, separate from vault notes and excluded from Git. Requests to Google use HTTPS. Access to saved information depends on the operator's device, repository permissions and configured service accounts.
The vault has no automatic record-expiry period. Business records remain until the operator removes them. Git history, backups and AI task history can retain earlier copies after a file is removed from the working vault. Each connected service also applies its own retention controls. We do not promise that removing one file instantly erases every copy.
Revoke access or request deletion
You can remove LFG Vault Sync from your Google Account connections to stop future authorized Drive reads. Revocation does not delete records already saved in the vault, Git history or connected AI services.
For access, correction or deletion requests, email sami@lfglabs.ai. Identify the account and records involved, but do not send passwords or access tokens. We will verify the request and coordinate the appropriate changes with the operator, including retained copies and any applicable legal retention requirements.
Changes and contact
We will update this page when the tool's data handling changes. A new use of Google data or additional access requires an updated disclosure and consent before that use begins. Privacy questions go to sami@lfglabs.ai.