Legal
Privacy Policy
This policy explains how Tinyhat handles account, service, and Google Workspace information when you use a dedicated AI-agent Computer.
Last updated July 17, 2026
1. Who we are and what this covers
Tinyhat is a Tinyloop product that provisions and operates dedicated cloud Computers for AI agents such as Hermes. This policy covers the Tinyhat website, account and provisioning services, dedicated Computers we operate for customers, and integrations you choose to connect through Tinyhat.
2. Information we collect
We collect contact and account information you provide, such as your name, email address, phone number, and support messages. We also keep the operational records needed to provision, secure, support, and bill the service, such as account status, Computer identifiers, connection status, payment metadata from our payment provider, and security or service logs.
We do not sell personal information.
3. Google Workspace data you choose to connect
Tinyhat does not receive Google Workspace access unless you start a connection and approve Google's consent screen. The exact data an agent can access depends on the scopes shown to you and granted by Google. Tinyhat currently implements permissions only for Gmail, Google Calendar, and Google Drive, plus the basic Google account identity needed to identify the connection. Depending on the scopes you select, this can include:
- Gmail messages, metadata, threads, drafts, labels, and sending;
- Google Calendar calendars, events, attendees, and availability;
- Google Drive file metadata and file content; and
- basic Google account identity used for the connection.
Before Google opens, Tinyhat shows a summary of the requested access. Google then shows the authoritative scopes for your approval. You can decline the request or ask your agent to use more limited access.
4. How Google data is used
Google user data is used only to provide and improve the user-facing functionality you request or configure, such as finding email, preparing drafts, managing inbox labels, updating a calendar, or working with files. Your agent can access a Google service only within the permissions you granted.
When an agent action requires an AI model to reason over Google data, the dedicated Computer may send relevant content to the model provider configured for that agent solely to perform that action. Third-party providers process information under their own terms and privacy policies.
5. Your Google credentials stay on your Computer
Your Google access and refresh tokens are saved only on the dedicated Computer assigned to you. Tinyhat's application servers do not keep a usable copy of those credentials.
- The Computer creates the encryption keys. It creates a one-time key pair for the connection and sends Tinyhat only the public key. The matching private key never leaves that Computer.
- Tinyhat encrypts before storing. After Google returns the tokens, Tinyhat processes them briefly in application memory to complete the OAuth exchange. Before any credential is written to platform storage, Tinyhat immediately encrypts it with the Computer's public key using RSA-OAEP-256.
- The platform holds only a one-time encrypted package. As credential material, Tinyhat stores only that short-lived encrypted package until the Computer saves it and confirms installation. The platform does not have the private key required to decrypt it.
- The Computer saves the usable credential locally. Only the dedicated Computer can decrypt the package. It saves the credential in owner-only local storage, where your agent uses it only for actions you request or configure within the Google permissions you granted.
- The encrypted delivery copy is removed. Tinyhat deletes the encrypted package after the Computer confirms that the credential was saved. If the Computer never retrieves it, the package expires and is deleted.
We may keep non-secret connection metadata needed to operate and support the service, such as the connected account, granted scopes, connection status, and timestamps.
6. Google API Limited Use
Tinyhat's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not sell Google user data.
- We do not use Google user data for advertising.
- We do not use Google user data to train Tinyhat or general-purpose AI models.
- Humans do not read Google user data except with your affirmative permission for support or security, when needed to investigate abuse, or when required by law.
You can read the Google API Services User Data Policy ↗.
7. When information is shared
We use service providers for infrastructure, payments, communications, support, security, and other operations. They may process information only as needed to provide those services. Google user data is shared with service providers only when necessary to deliver user-requested functionality, maintain security, comply with law, or with your consent. We may also disclose information to address fraud, abuse, or a valid legal request.
8. Retention, revocation, and deletion
A Google OAuth credential remains only on the dedicated Computer while the connection is active. Tinyhat provides a disconnect tool so you can remove it easily: ask your agent to disconnect the selected Google Workspace account and confirm the request. The tool removes the selected credential from that Computer and updates only non-secret connection status on Tinyhat's platform.
You can also revoke Tinyhat from your Google Account. Revocation stops future API access but does not automatically delete items created in Google or data that the agent previously saved elsewhere at your instruction.
To request deletion of Google-derived data and related account records that Tinyhat controls, follow the steps on our support page or email privacy@tinyloop.co. We may retain limited billing, fraud-prevention, security, dispute, or legal records when required for legitimate purposes.
9. Dedicated Computers and security
Tinyhat uses dedicated customer Computers, encrypted transport, access controls, monitoring, and operational boundaries designed to protect customer isolation. No system can guarantee absolute security. If you believe your account or connection is at risk, revoke provider access and contact support promptly.
10. Your choices and rights
You can decline a connection, limit the Google scopes you approve, revoke access, or stop using the service. You may also ask to access, correct, export, or delete personal information Tinyhat controls, subject to identity verification and applicable legal limits.
11. Changes and contact
We may update this policy as the service evolves. Material changes will be reflected by a new "Last updated" date on this page. For privacy questions or requests, email privacy@tinyloop.co.