Privacy Policy

Turing Observatory · Effective October 2, 2026 · Policy version 1.0.0

Turing Observatory is operated by Scott Gaudet for personal infrastructure monitoring. This policy covers its optional Gmail integration and this public information website.

Google permissions and data

The integration requests https://www.googleapis.com/auth/gmail.send to send outage, recovery, and delivery-test messages. It does not request Gmail inbox-reading or message-deletion scopes. The authorized account sends these messages to the recipients selected in the operator’s local settings. Message content includes the affected host’s name and outage or recovery status, or an explicit test message.

Use and sharing

Google authorization material is used only to authenticate the configured notification sender. The application transmits authorization requests to Google OAuth services and email content to the Gmail API for delivery. Alert recipients receive those messages. Google account data is not sold, used for advertising, or used to train machine-learning models. The integration does not intentionally send Google credentials to other service providers.

Turing Observatory’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and retention

On the operator’s Windows computer, the application stores its OAuth authorization material in a Windows-user-encrypted file outside the source repository. Tokens are decrypted in process memory when needed. The downloaded OAuth client configuration is kept separately by the operator. Recipient and notification preferences are stored in local settings. Background alert status and operation history are held in the running dashboard session.

Saved authorization remains locally until the operator removes it. Disabling alerts stops background notification delivery but does not remove saved authorization. Previously delivered email remains in the sender’s and recipients’ mail accounts under their normal retention settings.

Control and deletion

The operator can disable notifications in the local setup tool, revoke access through Google Account connections, and delete the local encrypted Gmail authorization file and downloaded OAuth client configuration. Revoking access does not automatically delete previously delivered messages.

This public website

This static information site has no Google sign-in, forms, advertising, or application-added analytics. When hosted on GitHub Pages, GitHub logs visitor IP addresses for security as described in the GitHub Privacy Statement. No live infrastructure data or OAuth authorization material is published here.

Contact and changes

Questions or deletion requests: scottgaudet.devops@gmail.com. Material changes to the application’s data practices will be reflected in an updated policy and effective date.