Banto

Effective September 30, 2026

Privacy Policy

This policy explains how Banto accesses, uses, stores, and shares information when a member connects Google services and uses Banto through LINE.

Information we process

We process the LINE identity and messages supplied to your Banto, member and conversation identifiers created by the platform, and operational records needed to deliver and secure the service.

When you open a Google connection link, Banto asks you to sign in with LINE Login to confirm that the link is yours. Banto receives only your LINE user ID for this check, compares it with the LINE account you use with Banto, and does not store it, your LINE profile, or the LINE access token. If the accounts differ, Banto stops before any Google step.

If you connect Google, we receive your Google account email address, a stable Google account identifier, the OAuth permissions Google grants, and encrypted access and refresh credentials. At your request, Banto may retrieve content and metadata from the services you selected:

How we use Google data

Banto uses Google data only to provide the user-facing features you request: connecting your chosen services, searching or reading your information, and producing the answer you requested in your LINE conversation. Google tools are read-only. Banto does not send, archive, label, modify, or delete email; alter events; edit Docs; modify Drive files; or delete Google content.

Relevant Google content may be processed by Cloudflare Workers AI or sent through Cloudflare's AI Gateway to the configured model provider (currently OpenAI or Google) solely to generate the response requested by the member. We do not use Google Workspace API data for advertising, sale, credit decisions, or to develop, improve, or train generalized AI or machine-learning models, and we do not permit service providers to use it for those purposes.

How information is shared

We disclose only the data necessary to service providers acting for Banto: Cloudflare provides application, encrypted storage, network, logging, Workers AI, and AI Gateway infrastructure; the configured model provider (currently OpenAI or Google) processes relevant request content to generate the requested response. We may also disclose information when required by law, to protect users and the service, or with your explicit consent. We do not sell Google user data.

Storage, security, and retention

Calendar tool calls and full returned search and event details are saved in your private conversation history and reused for follow-up answers. They are not replaced with shortened receipts after each reply. Normal conversation context limits and compaction apply. Resetting the conversation or deleting your Banto account clears this history; inactive conversations are cleared after 30 days once pending work has settled. Calendar results can also appear in AI diagnostic records for up to 30 days, as described below.

Google credentials are encrypted at the application layer and stored in Cloudflare Durable Object storage. They are keyed to the member's verified principal identity and usable only by active memberships belonging to that identity; they are not placed in LINE Queue payloads, model-visible identity fields, ordinary application logs, AI-provider credentials, or client website Workers.

Gmail tool calls and returned results, including selected message bodies and extracted attachment content, are saved in your private Banto conversation history and reused by the model on follow-up turns. Drive search results, selected file metadata, and folder listings also remain in conversation history. Earlier Google Docs read results follow the same history and deletion controls. Optional Drive content reads and saved download/export references follow those same history and deletion controls. This history is removed when you clear the conversation or delete your principal account, or after 30 days of conversation inactivity. Ordinary reads do not save original attachment bytes; extracted content can appear in AI diagnostic records for up to 30 days, as described below. Banto's generated LINE answer may contain a summary or excerpt. Generated LINE reply text is scrubbed after 30 days, and member request text is scrubbed after the conversation has been inactive for 90 days. Content-free security and audit metadata, such as an opaque access digest, outcome, MIME type, and byte count, may be retained without message or attachment content. Google credentials are kept while the connection is active.

When you explicitly ask to use a Gmail attachment on a website, or to download or export a selected Drive file, Banto saves the validated file in your private file storage. When you ask to use a saved file on a website, only that selected file is passed to the website coding service. Saved originals follow the uploaded-file lifecycle and are removed when you clear your files or delete your principal account. Website copies may remain in previews, repositories, and published websites until removed separately. Saving a file does not publish a website; publishing still requires your approval.

AI diagnostic records. To operate Banto and fix problems, each request Banto sends to the AI model and the model's response are kept as encrypted diagnostic records in Cloudflare R2 for up to 30 days, then deleted automatically. Because each request carries your recent conversation, these records can contain Google data returned during it, such as email text, calendar details, extracted attachment or file content, and your Google account email. One-time connection and confirmation links are removed from them. Banto staff open a diagnostic record only to investigate a specific bug, abuse, or security issue, to comply with law, or when you ask us to look, and every opening is recorded with its reason. Clearing your conversation or deleting your account does not immediately remove diagnostic records; they expire within 30 days, or email admin@banto.me to have yours deleted sooner. Diagnostic records are never used for advertising, sold, or used to train AI models.

We use encrypted transport, encrypted credential storage, member-scoped access controls, narrow service bindings, and server-side identity derivation. No security measure is perfect, but access is limited to what is needed to operate and protect the service.

Your choices and deletion

You decide which services to connect. In LINE, ask Banto what is connected, ask to clear the conversation, or ask to disconnect Google. Clearing scrubs stored conversation text and routed payloads while retaining minimum identifiers required for security and duplicate-message prevention. After confirmation, disconnecting removes the stored credentials and attempts to revoke them at Google; it does not change or delete your Gmail data. You may also revoke Banto directly from your Google Account connections.

Returned Gmail bodies and extracted attachment content are kept in conversation history, not a separate mailbox archive. Clearing the conversation removes that history. Disconnecting Google removes credentials but does not clear earlier conversation content. Originals explicitly saved for website use can be removed by clearing your files or deleting your principal account. To request deletion of your Banto account data, conversation history, or stored Google connection, email admin@banto.me from an address we can use to verify the request. We may retain limited information when legally required or necessary for security.

Google API Services User Data Policy

Banto's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Children, international processing, and changes

Banto is a business service and is not directed to children under 13. Cloudflare and the configured model provider (currently OpenAI or Google) may process information in countries other than yours, subject to their contractual safeguards. We may update this policy as the service or law changes; the effective date above will identify the current version.

Contact

Questions, privacy requests, or concerns: admin@banto.me.