Privacy policy

Last updated 9 August 2026

desert labs (“we”, “us”) operates the service at rundesert.com. This policy explains what we collect, why we collect it, who else sees it, and how you get rid of it. It covers data from your Google account in its own section, because that data gets the strictest handling.

Who we are

desert labs is an independent, unincorporated project. You can reach us about anything in this policy, including deletion requests, at satvikgsu@gmail.com. We answer privacy requests within 30 days.

What we collect

  • Account details. Your email address and name. If you sign in with Google, we receive these from your Google profile.
  • Content you create. The workspaces, notes, instructions, and automations you write in the product, and the messages you exchange with the agent.
  • Connected account data. Data we read from services you explicitly connect. Today that is Google. See the next section.
  • Operational logs. Timestamps, error messages, and request metadata we use to keep the service running. We scrub values that look like credentials before they reach our logs.

We do not sell your data. We do not serve advertising, and we do not share your data with advertisers or data brokers.

Data from your Google account

Connecting Google is optional and off until you turn it on. When you sign in with Google we ask only for your basic profile, which is your name, email address, and account identifier. Each additional service asks for its own permissions on its own screen, at the moment you enable it.

Gmail

If you enable Gmail, we request full access to your mailbox (https://mail.google.com/). We use it to watch your inbox for new mail, read the messages that arrive, and let your agent act on them on your instructions, including composing, sending, organising, and deleting mail when you ask it to.

Google does not send us your mail directly. It tells us your mailbox changed, and we then ask Gmail what arrived. We read message headers and bodies so your automations can act on them. We report attachments by name, type, and size, and we do not copy attachment contents out of Gmail.

Google Drive and Docs

If you enable Docs, we request access to your Google Docs and your Drive files (.../auth/documents and .../auth/drive). We use it so your agent can create, open, edit, organise, and delete documents when you ask it to. Full Drive access is required because the agent works with documents you already have, not only ones it created itself.

Why the permissions are broad

The agent decides what to do at the moment you ask it, from instructions you write in your own words. The permissions you grant are the outer limit of what it can ever do on your behalf. We ask for a service in full so that the agent can complete the jobs you give it, and you can switch any service off at any time.

Limited Use

desert labs' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, and without exception: we use your Google data only to provide the features you turned on. We do not use it for advertising. We do not sell it. We do not use it to train generalised artificial intelligence models, and neither do the providers we send it to. No human at desert labs reads your Google data except where you explicitly ask us to, where it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous.

Who else processes your data

We use a small number of providers to run the service. Each one receives only what it needs to do its job, and each is bound to use it only to provide their service to us.

  • Anthropic powers the agent. Your instructions, your workspace content, and the connected-account data the agent is working on are sent to Anthropic's API to generate a response. Anthropic does not train its models on data submitted through its API.
  • Daytona hosts the isolated sandbox that runs your agent and your automations. Your workspace files and the data your automations handle live there while a sandbox is running.
  • Google Cloud delivers Gmail change notifications to us over Pub/Sub. These notifications carry your mailbox address and a change marker, never the contents of your mail.
  • Axiom stores our operational logs, which hold timestamps and error details rather than the contents of your mail or documents.

How we store and protect it

Your Google access and refresh tokens are encrypted before they are written to our database, and they are bound to your account so a token row is useless if it is moved. Data in transit travels over TLS.

Your agent runs in a sandbox isolated from other users. The key that lets a sandbox read your tokens is scoped to that sandbox, so one workspace cannot reach another's connected accounts.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your data, we will tell you.

How long we keep it

  • Connected accounts. Disconnecting a service revokes the grant with Google and deletes our stored tokens for it right away.
  • Mail we processed. We keep the change markers that tell us where we last read up to. We do not keep a copy of your mail after your automations have handled it.
  • Your account. Deleting your account deletes your workspaces, content, and connected-account records.
  • Logs. Retained for a limited period for debugging and security, then deleted.

Your controls

  • Turn any connected service off from the integrations page.
  • Revoke our access directly from your Google account permissions. This works whether or not you can reach our site.
  • Ask us for a copy of your data, or ask us to delete it, by emailing satvikgsu@gmail.com.

Children

The service is not intended for anyone under 13, and we do not knowingly collect their data.

Changes

If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your Google data, we will tell you before it takes effect.