1. Scope
Research OS is a desktop application for organizing research notes, references, tasks, schedules, and related project information. This Privacy Policy applies to the Research OS application, its optional Google Calendar integration, and the public website at researchos-lab.dev.
In this policy, “Research OS,” “the application,” “we,” and “us” refer to the Research OS software project and its operator. Research OS is currently an independently developed application with limited availability.
Local-first by design. The current version does not operate a central service that receives or stores synchronized Google Calendar content. Application data is stored on the user’s device, except when data must be sent directly to Google to provide the Calendar synchronization requested by the user.
2. Information the application may access
The information accessed depends on the features a user chooses to enable. Research OS may process the following categories.
Information provided directly by the user
Research notes, tasks, tags, schedules, settings, and other content entered or imported into the application. This content is stored in the user’s local Research OS vault.
Google account and authorization information
- The Google account identifier and email address associated with the connection, if provided through the permissions authorized by the user.
- OAuth access and refresh tokens required to maintain the user-requested connection.
- Authorization status, granted permissions, and synchronization state.
Google Calendar information
- Calendar identifiers and metadata, such as calendar names, time zones, colors, and access status.
- Event information, which may include titles, descriptions, dates and times, recurrence, location, attendees, reminders, availability, status, and conference links.
- Synchronization metadata, such as event identifiers, update timestamps, and change tokens needed to avoid duplicate or conflicting updates.
- Changes a user directs Research OS to make, including creating, updating, or deleting calendar events.
The Google authorization screen displays the permissions being requested before a user grants access. Research OS does not request access to Gmail, Google Drive, or Google Contacts for the Calendar synchronization described in this policy.
Website technical information
This website does not use advertising trackers, analytics scripts, or application cookies. The website hosting and network provider may automatically process limited request information—such as IP address, browser type, requested URL, timestamp, and security signals—to deliver the site, prevent abuse, and maintain service reliability.
3. How information is used
Research OS uses information only as needed to provide, secure, and support features requested by the user. Uses include:
- Displaying the connected Google account and Calendar connection status.
- Showing selected Google Calendar events inside Research OS.
- Synchronizing event changes between Research OS and Google Calendar.
- Creating, updating, or deleting events after a user takes the corresponding action in the application.
- Maintaining synchronization state and resolving duplicate or conflicting changes.
- Protecting the application, detecting errors, and responding to user-requested support.
Research OS does not use personal information or Google user data for advertising, profiling, credit decisions, surveillance, or sale to data brokers.
4. Google user data and Limited Use
Research OS accesses Google user data only after the user chooses to connect a Google account and grants the permissions shown by Google. The data is used solely to provide the user-facing Calendar features described on this website and in the application.
Google API Limited Use disclosure. Research OS’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Research OS:
- requests only permissions needed for the Calendar features the user chooses to use;
- does not sell Google user data;
- does not use or transfer Google user data for advertising, retargeting, or marketing;
- does not use Google Workspace API data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models;
- does not permit humans to read Google user data unless the user affirmatively shares specific information for support, access is required for security, or disclosure is required by law; and
- does not transfer Google user data to third parties except when necessary to provide the user-requested feature, with the user’s consent, for security, or to comply with applicable law.
6. Storage and security
Research OS is designed to store application data locally on the user’s device. Google Calendar data selected for synchronization and OAuth tokens are stored in the local Research OS vault. Persistent authorization tokens are encrypted at rest within that vault, and data sent to Google APIs is transmitted over encrypted HTTPS connections.
Additional safeguards include least-privilege access, separation of local vault data, an automatic application lock, and the ability to disconnect a Google account. Users are responsible for protecting their device, operating-system account, vault credentials, and backups.
No security method is perfect. Research OS cannot guarantee absolute security, particularly if the user’s device, operating system, or credentials are compromised.
7. Data retention and deletion
Locally stored application data
Research notes, settings, and synchronized Calendar data remain in the local vault until the user deletes the relevant records, clears the local integration data, deletes the vault, or removes the application data from the device.
Google authorization tokens
Authorization tokens are retained locally only while needed to maintain the connection. Disconnecting the Google account in Research OS removes locally stored tokens and stops future synchronization. Users can also revoke access from their Google Account third-party connections.
Data held by Google
Disconnecting Research OS does not automatically delete events already stored in Google Calendar. Those events remain under the user’s control in Google Calendar and can be deleted there. Google retains data according to the user’s settings and Google’s own policies.
Support communications and website records
Support emails are retained only as long as reasonably needed to answer the request, maintain security, or meet legal obligations. Limited website delivery and security logs may be retained by the hosting and network provider under its applicable policies.
For detailed instructions, see Disconnect and delete data.
8. Your choices and controls
- Do not connect Google Calendar. The integration is optional; core local functions can be used without granting Google access.
- Review permissions. Google shows the requested permissions before authorization.
- Disconnect at any time. Disconnect the account in Research OS or revoke access through Google Account settings.
- Delete local data. Delete individual records, clear integration data, or delete the local vault and application data.
- Ask a question. Contact support for help understanding these controls or handling a deletion request.
9. Children’s privacy
Research OS is intended for researchers and other adult users. It is not directed to children under 13, and the operator does not knowingly collect personal information from children under 13. If you believe a child has provided personal information through a support communication, contact us so it can be reviewed and deleted.
10. Changes to this policy
This policy may be updated as Research OS changes or as legal and platform requirements evolve. The effective date at the top of this page will be updated when changes are published. If a material change affects how previously authorized Google user data is used, users will be notified and asked for any consent required before the new use begins.
11. Contact
Questions about this policy, Google Calendar data, or deletion can be sent to: