Effective September 24, 2026
Privacy notice
Farm OS Monitor Alerts is a private operational tool used by the Fraserland Farm OS owner. This notice explains how it uses Google account data.
Google data accessed
The tool requests basic account identity (openid and email)
to confirm that the authorized account is exactly
alertsfarmos@gmail.com. It also requests the Gmail API
gmail.send permission so it can send operational alerts.
The tool does not request permission to read, list, change, or delete Gmail messages and does not request access to Google Drive.
How the data is used
Account identity is used only to verify the approved sender. Gmail send
access is used only to send Farm OS automation-failure alerts from
alertsfarmos@gmail.com to the same account.
Google user data is not used for advertising, sold, shared with data brokers, or used to train artificial intelligence or machine-learning models.
Data stored locally
The OAuth client identifier, client secret, and refresh token are stored on the Farm OS Windows computer using Windows CurrentUser DPAPI protection. A short-lived access token exists only in memory during an authorized operation.
Local authorization metadata records the account address, approved scopes, authorization time, optional refresh-token expiry, and a one-way hash of the client identifier. It does not contain an OAuth token or client secret.
The delivery ledger stores an execution identifier, delivery state, attempt count, message identifier, sender, recipient, and update time. It does not store the OAuth token, client secret, or email body. Sent messages remain in the Google account according to its Gmail settings.
Sharing and retention
The tool sends requests directly to Google's OAuth, identity, and Gmail API services. It does not transfer Google user data to another service for unrelated purposes.
Protected OAuth state is retained only while the Farm OS owner keeps this alert method authorized. Local delivery evidence is retained with Farm OS operational records for audit and safe-retry purposes.
Control and revocation
The Farm OS owner can revoke the app's access from the Google Account third-party connections page. Revocation prevents further Gmail API sends until the owner authorizes the app again. Local protected credentials can also be removed through the documented Farm OS recovery procedure.