Effective September 30, 2026
Privacy Policy
This policy explains how Banto accesses, uses, stores, and shares information when a member connects Google services and uses Banto through LINE.
Information we process
We process the LINE identity and messages supplied to your Banto, member and conversation identifiers created by the platform, and operational records needed to deliver and secure the service.
When you open a Google connection link, Banto asks you to sign in with LINE Login to confirm that the link is yours. Banto receives only your LINE user ID for this check, compares it with the LINE account you use with Banto, and does not store it, your LINE profile, or the LINE access token. If the accounts differ, Banto stops before any Google step.
If you connect Google, we receive your Google account email address, a stable Google account identifier, the OAuth permissions Google grants, and encrypted access and refresh credentials. At your request, Banto may retrieve content and metadata from the services you selected:
- Gmail: searches return up to 20 message metadata results per page, including identifiers, sender and recipient headers, subject, received time, snippet, labels, thread identifier, and attachment presence, without downloading bodies or attachment bytes. For selected messages, Banto may read headers, labels, attachment metadata, and up to 20,000 characters of normalized body text per message. You can request up to 100 emails or conversations in a batch. Each conversation includes up to 20 messages and 100,000 body characters; batch results have a 500,000-character aggregate limit and report partial results. Email reads do not extract attachments. Label listing includes message and unread counts, up to 100 labels per page. If you then explicitly ask to read one listed attachment, Banto supports PDF, JPEG, PNG, GIF, WebP, UTF-8 text, CSV, and JSON up to 5 MiB, with a 256 KiB limit for text. Unsupported, malformed, mismatched, encrypted, active-content, or oversized files are rejected.
- Calendar: Search your primary calendar by text and date range, with up to 50 events per page. Read selected events individually or in batches of up to 20, including descriptions, attendees and responses, times, location, recurrence, reminders, Meet links, and attachment metadata. Search also includes all-day and busy/free information to help answer availability questions. Calendar tools do not download attachment contents or access shared calendars. Batch results are bounded and report partial failures.
- Drive: matching file and folder IDs, names, types, descriptions, creation and modification times, owners, parent folders, shared-drive identifiers, shortcut targets, sizes, and links. Searches and folder listings return up to 50 items per page with pagination and incomplete-coverage indicators. Metadata-only connections do not download file contents. With optional Drive content permission, Banto reads selected supported files and native Workspace exports: PDF, images, UTF-8 text, Markdown, CSV and JSON; PDF exports for Docs, Sheets, Slides and Drawings; plain text for Docs/Slides; CSV for the first sheet only. Binary reads are limited to 5 MiB and text to 256 KiB. Unsafe or oversized files are rejected. Ordinary reads return extracted content in LINE and discard original bytes. Requested downloads preserve supported original files and requested exports save their complete representation in private file storage for later reuse, including on a requested website. Saved files follow the uploaded-file lifecycle: clear your files or delete your principal account to remove them. Saving does not publish or modify Google data. Exports and extraction can omit native features or visual detail. Full extracted results and saved-file references remain in private conversation history.
How we use Google data
Banto uses Google data only to provide the user-facing features you request: connecting your chosen services, searching or reading your information, and producing the answer you requested in your LINE conversation. Google tools are read-only. Banto does not send, archive, label, modify, or delete email; alter events; edit Docs; modify Drive files; or delete Google content.
Relevant Google content may be processed by Cloudflare Workers AI or sent through Cloudflare's AI Gateway to the configured model provider (currently OpenAI or Google) solely to generate the response requested by the member. We do not use Google Workspace API data for advertising, sale, credit decisions, or to develop, improve, or train generalized AI or machine-learning models, and we do not permit service providers to use it for those purposes.
How information is shared
We disclose only the data necessary to service providers acting for Banto: Cloudflare provides application, encrypted storage, network, logging, Workers AI, and AI Gateway infrastructure; the configured model provider (currently OpenAI or Google) processes relevant request content to generate the requested response. We may also disclose information when required by law, to protect users and the service, or with your explicit consent. We do not sell Google user data.
Storage, security, and retention
Calendar tool calls and full returned search and event details are saved in your private conversation history and reused for follow-up answers. They are not replaced with shortened receipts after each reply. Normal conversation context limits and compaction apply. Resetting the conversation or deleting your Banto account clears this history; inactive conversations are cleared after 30 days once pending work has settled. Calendar results can also appear in AI diagnostic records for up to 30 days, as described below.
Google credentials are encrypted at the application layer and stored in Cloudflare Durable Object storage. They are keyed to the member's verified principal identity and usable only by active memberships belonging to that identity; they are not placed in LINE Queue payloads, model-visible identity fields, ordinary application logs, AI-provider credentials, or client website Workers.
Gmail tool calls and returned results, including selected message bodies and extracted attachment content, are saved in your private Banto conversation history and reused by the model on follow-up turns. Drive search results, selected file metadata, and folder listings also remain in conversation history. Earlier Google Docs read results follow the same history and deletion controls. Optional Drive content reads and saved download/export references follow those same history and deletion controls. This history is removed when you clear the conversation or delete your principal account, or after 30 days of conversation inactivity. Ordinary reads do not save original attachment bytes; extracted content can appear in AI diagnostic records for up to 30 days, as described below. Banto's generated LINE answer may contain a summary or excerpt. Generated LINE reply text is scrubbed after 30 days, and member request text is scrubbed after the conversation has been inactive for 90 days. Content-free security and audit metadata, such as an opaque access digest, outcome, MIME type, and byte count, may be retained without message or attachment content. Google credentials are kept while the connection is active.
When you explicitly ask to use a Gmail attachment on a website, or to download or export a selected Drive file, Banto saves the validated file in your private file storage. When you ask to use a saved file on a website, only that selected file is passed to the website coding service. Saved originals follow the uploaded-file lifecycle and are removed when you clear your files or delete your principal account. Website copies may remain in previews, repositories, and published websites until removed separately. Saving a file does not publish a website; publishing still requires your approval.
AI diagnostic records. To operate Banto and fix problems, each request Banto sends to the AI model and the model's response are kept as encrypted diagnostic records in Cloudflare R2 for up to 30 days, then deleted automatically. Because each request carries your recent conversation, these records can contain Google data returned during it, such as email text, calendar details, extracted attachment or file content, and your Google account email. One-time connection and confirmation links are removed from them. Banto staff open a diagnostic record only to investigate a specific bug, abuse, or security issue, to comply with law, or when you ask us to look, and every opening is recorded with its reason. Clearing your conversation or deleting your account does not immediately remove diagnostic records; they expire within 30 days, or email admin@banto.me to have yours deleted sooner. Diagnostic records are never used for advertising, sold, or used to train AI models.
We use encrypted transport, encrypted credential storage, member-scoped access controls, narrow service bindings, and server-side identity derivation. No security measure is perfect, but access is limited to what is needed to operate and protect the service.
Your choices and deletion
You decide which services to connect. In LINE, ask Banto what is connected, ask to clear the conversation, or ask to disconnect Google. Clearing scrubs stored conversation text and routed payloads while retaining minimum identifiers required for security and duplicate-message prevention. After confirmation, disconnecting removes the stored credentials and attempts to revoke them at Google; it does not change or delete your Gmail data. You may also revoke Banto directly from your Google Account connections.
Returned Gmail bodies and extracted attachment content are kept in conversation history, not a separate mailbox archive. Clearing the conversation removes that history. Disconnecting Google removes credentials but does not clear earlier conversation content. Originals explicitly saved for website use can be removed by clearing your files or deleting your principal account. To request deletion of your Banto account data, conversation history, or stored Google connection, email admin@banto.me from an address we can use to verify the request. We may retain limited information when legally required or necessary for security.
Google API Services User Data Policy
Banto's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Children, international processing, and changes
Banto is a business service and is not directed to children under 13. Cloudflare and the configured model provider (currently OpenAI or Google) may process information in countries other than yours, subject to their contractual safeguards. We may update this policy as the service or law changes; the effective date above will identify the current version.
Contact
Questions, privacy requests, or concerns: admin@banto.me.