Privacy policy
Effective September 28, 2026
This policy covers the Imago desktop application and getimago.app. Imago lets you assign tasks to AI bots and connect services that those bots can use on your behalf. Contact the Imago project at luke.fournier@gridbloom.app with privacy questions or requests.
Information you provide
Imago processes your account identifier, name and email address for sign-in and account management. You provide workspace and bot settings, instructions, messages, files and other task inputs. Imago keeps task history and can retain information in bot memory to support later work. WorkOS processes Imago sign-in; the AI services you choose process the requests you send to them.
Google account connections
You choose whether to connect Gmail, Google Calendar or Google Drive. Google asks you to authorize the requested permissions. Depending on the service and permissions you grant, Imago can access:
- Account identity: your Google account identifier, email address and profile information to identify the connected account.
- Gmail: message and thread content, headers, attachments, labels and drafts. Bots can search and summarize mail, organize messages, prepare drafts and send messages when permitted.
- Google Calendar: your calendar list and event details, including attendees, descriptions, times and locations. Bots can find events and create, update or delete events when permitted.
- Google Drive: file and folder metadata, file contents and sharing information available through your granted permissions. Bots can find and read files and create, change, move, trash or share files when permitted.
Imago uses this information to carry out your tasks, display results, maintain the context of your work and enforce connection permissions. You can restrict which workspaces may use a connection. Settings and approval rules determine which changes a bot may make.
AI processing and sharing
When you ask a bot to work with connected content, the relevant content and tool results may be included in requests to the AI provider you selected. Providers can include OpenAI, Anthropic and other services supported by your chosen agent. Your provider account, plan and privacy settings determine that provider's handling of these requests. Review those terms before connecting private information. Use provider settings and services that do not use Google user data to train generalized AI or machine-learning models.
The Connections service processes authorization and service requests and stores credentials and operation records. Its operator and hosting location depend on your installation. The current development setup runs this service locally. A self-hosted or future hosted setup may use a remote server. Authentication, hosting and AI providers receive the information needed to provide their respective functions.
We do not sell Google user data or use it for advertising, credit decisions or training generalized AI models. Imago's use and transfer of information received from Google APIs must comply with the Google API Services User Data Policy, including its Limited Use requirements. Transfers of Google data are limited to providing the features you authorize, security, legal obligations, or a business transfer with your prior consent. We do not read your Google content for support unless you give permission to access specific content, or access is necessary for security or legal obligations.
Storage and security
The desktop engine stores workspaces, tasks, conversation history and bot memory on your computer. Agent runtimes may also keep session records. The Connections vault encrypts stored OAuth credentials and keeps them separate from the public connection gateway and model tool responses. Imago uses HTTPS for Google API calls; local development services communicate over your computer's loopback interface. Your device, backups, self-hosted services and selected providers also affect the security of your data.
Retention and deletion
Imago retains local task history, memory and settings until you remove them or the relevant application data. Disconnecting a Google service stops new access through that connection. If other Google services still share the same connected account, Imago keeps the shared credential until you disconnect its last service. Disconnecting does not erase past task results, memories, audit records, backups or copies already processed by your AI provider.
The Connections service retains operation receipts and audit records. The current service prunes completed operation result payloads older than seven days during periodic cleanup when the account is used; this is not a seven-day deletion guarantee for all stored data. Contact us for help identifying data to remove. For a self-hosted installation, its operator controls the server data and backups. A provider may require a separate deletion request for data it holds.
You can also revoke Imago's Google authorization from your Google Account connections page. Revocation and deletion of Imago's local records are separate actions.
Website and support
Cloudflare hosts this website and processes network information such as IP addresses, request details and security events to serve and protect it. The site does not include advertising trackers or third-party analytics scripts. If you email us, we receive your address and the information you include so we can respond. Please avoid sending account passwords, OAuth secrets or unrelated private content.
Changes and contact
We will update this page when our data practices change. A new use of Google data outside the consent you already gave requires updated disclosure and consent. Send privacy questions and requests to luke.fournier@gridbloom.app.