Privacy notice
Updated 1 October 2026
This notice describes Mohanad Anan’s personal Productivity Super App and the separately authorized agents used with it. Questions or requests about stored information can be sent to mohanad.developer@gmail.com.
Calendar information and permissions
Google sign-in supplies the connected email address and the permissions granted. The web app stores account identity, granted scopes, encrypted refresh tokens, calendar names and preferences, sync status, and cached event information such as titles, times, locations and descriptions in its Supabase database. Refresh tokens obtain short-lived access tokens for ongoing sync.
The personal connection uses calendar.calendarlist.readonly to list calendars, calendar.events to read and manage events, and calendar.app.created to create and manage SuperApp · Training and SuperApp · Events. The work connection requests calendar.readonly and remains read-only in the app. Basic identity scopes identify the account. Calendar data supports the owner’s calendar views, availability and planning.
Agent Gmail access
The web Calendar connection requests no Gmail permissions. An agent uses a separate connector or desktop OAuth client with read-only Gmail access to the explicitly authorized personal and FachPilot mailboxes. It reads messages to identify actionable follow-ups, skips routine noise, and writes derived task or capture context with sender, subject, account, thread ID, received time and a Gmail source link. Full emails and attachments are not imported into the app. Reply drafts remain proposals; this triage workflow does not send, archive or label mail.
An agent provider processes the mail content presented to that agent under its own service policies. Calendar data and derived email context returned through the app’s API or MCP can also be processed by agents the owner authorizes. Gmail credentials managed by the desktop CLI stay in that runtime’s encrypted credential store; connector credentials are managed by the connector provider.
Storage and access
Vercel hosts the web app and Supabase provides its database and authentication. The private workspace requires owner authentication or a scoped agent API key. Public information pages contain no workspace data. Google data is used for the workspace features described here, not for advertising or sale.
Disconnecting and removing information
Disconnecting Calendar in Settings removes that account’s cached calendars and events and replaces its stored secret with an unusable value. It does not delete Google events or the calendars created in Google, and does not revoke Google-side consent. Revoke the application’s access separately in your Google Account connections. Agent Gmail access must be revoked separately for its connector or desktop client.
Derived tasks, captures, proposals and activity records remain in the workspace when Google access is disconnected. Archiving a record hides it and is not permanent deletion. No automatic expiry or complete backup-deletion timeline is promised here; contact the operator for removal requests. Revocation, account policies and Google security events can require fresh authorization.