Zortex

Effective 5 October 2026

Zortex application privacy policy

How the Zortex desktop application handles connected Google data, authorization and optional assistant integrations.

1. Scope and contact

This policy explains how the Zortex desktop application handles information from connected Google services. It supplements the separate policy for visitors to the Zortex website and publishing studio.

Zortex is operated by the Zortex team. For questions about Google data, access or deletion, contact jpl223705@gmail.com. This is our application privacy and support contact.

2. Google information and its purposes

When you connect a Google account, the Google consent screen describes the permissions requested. Zortex uses authorized information to synchronize connected sources into a vault on your device, maintain a searchable index, retrieve information relevant to your requests and provide links to original records. The full application also provides Google API actions at the user's request.

  • Gmail: Zortex retrieves messages and related metadata for synchronization and search, including subjects, senders, dates and message contents. Mail actions can support drafts, sending, labels and movement to Trash. The production scope declaration includes read-only access and full mail access; the declared full scope grants broader Google access than these examples alone require.
  • Google Drive: Zortex retrieves file metadata and supported content for discovery, synchronization, search and source links. File actions can create or update files and change metadata. The declared permissions include read-only and full Drive access.
  • Drive Activity: Zortex can retrieve activity associated with files to provide information about file changes. This permission is read-only.
  • Google Docs: Document actions can apply user-requested changes using the Google Docs API.
  • Google Sheets: Spreadsheet actions can read and update data in specified ranges using the Google Sheets API.
  • Google Calendar: Zortex retrieves calendar and event information for synchronization and retrieval. The declared Calendar permission is read-only and does not authorize event creation, editing or deletion.

Permissions granted by Google determine the available API access. Zortex's own access policies and grants determine which results and actions it admits. Declaring a permission does not mean every operation allowed by that Google permission is a dedicated product feature.

3. Local storage and security

Zortex stores synchronized information, indexes and credentials on the device where it runs. OAuth secret cells use AES-256-GCM authenticated encryption. That protection concerns secret cells and must not be interpreted as a statement that every synchronized record, raw content blob, index or metadata field is encrypted by the application.

The product contains an encrypted-vault container path for supported macOS configurations. Storage protection depends on the actual platform and configuration, including any operating-system disk encryption. This policy does not claim equivalent full-vault encryption on every Windows installation.

4. Google authorization and token broker

Connecting and refreshing a Google account requires communication with Google. For Zortex's shared Google OAuth client, a Cloudflare-hosted token broker processes authorization codes, PKCE values and refresh credentials, forwards the necessary request to Google's token endpoint and returns the token response to the application. Tokens are therefore processed off-device during authorization and refresh.

The inspected broker handler processes authorization credentials rather than Gmail messages, Drive files, document bodies, spreadsheet cells or calendar event contents. Its response instructs clients not to cache the token response. The handler contains no explicit application-level persistence of token bodies. These implementation facts do not constitute a guarantee that all infrastructure or security logs are absent. Hosting and infrastructure services may process ordinary request metadata for operation and security; actual logging settings and retention must remain consistent with this policy.

5. Optional AI and assistant integrations

Zortex can return permitted search results, metadata and selected content to an assistant you connect through MCP. The information released depends on the connected integration, your request and Zortex's applicable access policies and grants. The assistant host receives those results. If that host uses a cloud model, its provider may receive and process the returned information on its servers.

Local synchronization is separate from assistant processing. It does not imply that every later use of selected information stays on your device. The product also contains local model paths and optional remote model configurations; users should review the actual provider and integration configuration before enabling them. This policy does not promise that all AI processing is local.

A separately connected assistant or model provider may have its own privacy and retention terms. Information already received by such a provider is not deleted merely by disconnecting Zortex from Google. Contact the provider or use its controls for its retained information.

6. Commitments for Google user data

The Zortex team makes the following commitments for Google user data handled by the application and services under its control:

  1. No sale or advertising use. We do not sell Google user data or use it for targeted advertising.
  2. No generalized model training. We do not use Google user data to train or improve generalized AI or machine-learning models. A permitted integration's processing of selected context must remain consistent with this commitment and the disclosed user-facing purpose.
  3. Google API policy and Limited Use. Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Access and transfers are limited to providing or improving the appropriate user-facing features, applicable permitted security or legal purposes and other uses expressly allowed by that policy. Relevant service-provider arrangements must uphold these restrictions.

These commitments cover Zortex's handling of Google user data; they do not imply that an independently chosen assistant's general policies are identical. Zortex must limit its integrations and service arrangements so its own permitted disclosures remain consistent with these commitments.

7. Retention, disconnecting and deletion

Synchronized information is retained locally until the user removes it from the local storage and any retained backups or archives. This policy does not promise a universal automatic expiration period.

Disconnecting a source disables its applicable grant and stops its use through that grant while preserving previously synchronized local records. Disconnect is not deletion. Uninstalling the application may preserve the event log or archive it; uninstall is not a promise that Google content has been erased.

To stop future Google-authorized access, remove Zortex from your Google Account's third-party connections settings. Revocation alone does not erase information already stored locally. To delete locally stored data, first stop Zortex and its connected background processes. Remove your Zortex data directory and any separately configured event or index directories, together with retained uninstall archives, exports and backups that you also want to delete. This removes all data in those locations, including data from other connected sources; it is not a Google-only deletion tool. If you are unsure which locations your installation uses, contact support before deleting files. Disconnecting Google or uninstalling Zortex does not by itself erase previously synchronized information. Revoking Google access prevents future authorized access but does not delete existing local copies or copies held by an assistant provider.

Broker infrastructure retention is separate from local content retention. Cloudflare and other infrastructure providers may retain operational request information according to their service configuration and retention policies. We do not promise that authorization requests produce no infrastructure logs. Contact our privacy address with questions or requests about information handled by our services.

8. Policy changes

Material changes to the application's handling of Google data will be reflected in an updated version of this policy on zortex.me. This policy is effective from 5 October 2026. Privacy questions can be sent to jpl223705@gmail.com.

Zortex
Explore Studio All stories