Last updated 8 October 2026

Privacy Policy

This policy explains how Housekeeping Karolyi accesses, uses, stores, and protects Google user data.

Application and controller

Housekeeping Karolyi is a private, personal-use housekeeping and reservation-management application. It is operated by the owner of the Google account that authorizes access. The support email shown on the Google OAuth consent screen is the contact for privacy questions.

Google data accessed

The application requests only https://www.googleapis.com/auth/gmail.readonly. It may access reservation-related message identifiers, thread identifiers, sender addresses, subjects, received dates, and message bodies.

It does not request permission to send, compose, modify, move, or delete Gmail messages, and it does not access unrelated Google services.

How Google data is used

Gmail data is used only to identify supported reservation messages, extract reservation and guest details, reconcile stays with occupancy information, and generate housekeeping operations for the account owner. Messages that do not match supported reservation event types are not imported as reservation events.

Storage and retention

OAuth credentials are stored as access-restricted files in the owner's private self-hosted environment. Imported reservation emails and derived reservation data are stored in the owner's private database so messages can be reparsed when extraction logic improves. They are retained until the owner removes them; there is no automatic sale, advertising use, or public publication of this data.

Sharing and transfer

Google user data is not sold, rented, used for advertising, or shared with third parties. It is processed only by the owner's self-hosted application for the purposes described above.

Housekeeping Karolyi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Security

OAuth client credentials and refresh tokens are excluded from source control, stored with restrictive file permissions, and are not exposed by this public information site. The application database is not published to the internet. Access to administrative reservation data is restricted to the owner.

Control and deletion

The account owner can revoke the application's Gmail permission at any time from Google Account security settings. The owner can also delete the locally stored OAuth token, imported messages, and derived reservation records from the self-hosted system.

Changes

This policy will be updated if the application's data access or use changes. The effective date is shown at the top of this page.