What we handle
The website is a static site. It does not ask for Google passwords, OAuth tokens, or payment-card details, and its current client scripts do not run analytics or submit a form. Normal web requests may be processed by the site host. If you email [email protected], Pongu, LLC receives the address and message so it can respond.
Purchases, receipts, license-key delivery, trial expiration, activations, and the customer portal are handled by Polar when you follow a checkout link. Review Polar’s terms and privacy information for those transactions; the Pongu website does not collect your card number.
Native app data
The native app can store Pongu-owned conversation state, optional conversation-scoped memory, configuration, diagnostics, job state, and Messages delivery state on the Mac. What is retained depends on the features you enable and the conversations you allow. macOS Messages permissions are broad at the operating-system level; Pongu’s configured conversation rules restrict which conversations it processes and answers.
Optional managed Connections store non-secret account and capability metadata locally, including a provider, display name, account address when supplied, granted capabilities, calendar labels, and connection timestamps. The app keeps this metadata in an owner-only file. Google access and refresh credentials, and the Google client configuration supplied to the app, are stored in the Mac’s device-only Keychain. They are not placed in ordinary app configuration, harness settings, message transcripts, or diagnostics. Calendar event bodies are not persisted in the connection metadata projection.
Google API and Limited Use disclosure
Google Connections are an optional native-app capability and may remain unavailable in a
particular build while the Google project and app are being qualified. When enabled, you
start authorization in the app; Google sign-in, MFA, and consent happen in Google’s
browser flow. The native flow uses PKCE/state and a short-lived loopback listener on
127.0.0.1. Pongu does not request or receive your Google password.
Pongu asks only for the capabilities you select. The current native implementation can request the following Google API access:
- Basic identity: OpenID and the Google account email/profile needed to identify the connected account.
- Gmail: search and read messages and attachments, send messages, and change message labels or state. Permanent mail deletion is not exposed.
- Calendar: discover calendars and list events; create, update, or delete events only when you grant the calendar write capability and the selected calendar permits it. Calendar sharing changes are not exposed.
-
Drive: list files, read/download file content, and create or update
files when you select Drive access. The current Drive-editing implementation uses
Google’s broad
drivescope to support user-selected existing files; it is not represented as the narrowerdrive.filescope.
These operations are performed only to provide the user-facing feature you request. If you ask your selected AI harness to use a connected account, relevant request context and Google tool arguments or results can be passed through Pongu’s private local bridge to that harness and its provider so it can produce the requested output. The selected provider’s own terms and data controls govern that provider’s handling of the content. Pongu does not sell Google data, use it for advertising, or use it to train Pongu models. Pongu does not make Google data available for human review as a product feature; support handling is limited to information you choose to send.
Limited Use: Pongu’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. See Google’s Gmail scope guidance and Drive scope guidance for Google’s current scope classifications and requirements.
Other connected accounts
The optional iCloud connection accepts an Apple app-specific password in a secure native field and stores it in the Mac’s Keychain. It can use the selected mail and calendar capabilities through native TLS IMAP/SMTP and HTTPS CalDAV. Your Apple Account password is not requested. Harness-managed accounts remain separate; Pongu does not copy harness credentials or rewrite harness MCP settings.
Disconnecting and deleting data
- Remove a Pongu connection: open the native app’s Connections tab and choose Remove. Pongu removes that connection’s local credential from Keychain and its local connection metadata. This does not delete Gmail, Calendar, or Drive data, and does not revoke a separate Google grant.
- Disable without removing: turn the connection off in Connections. The app stops admitting its tools while the local credential and metadata remain available for a later re-enable.
- Revoke at Google: use your Google Account’s third-party connections or security settings to revoke Pongu’s grant. Revocation is controlled by Google and does not delete data already in your Google account.
- Delete other local Pongu data: use the native app’s own memory, diagnostics, and data controls for those separate stores. For help identifying a local Pongu record, contact [email protected] and do not email passwords, tokens, or app-specific passwords.
Pongu has no hosted account database or phone onboarding portal for these native connections. Deleting the local connection is therefore different from revoking Google’s authorization and different from deleting provider-side mail, events, or files.
Retention, security, and changes
Connection metadata is retained until you remove the connection or the app replaces it. Credentials remain in Keychain until disconnect, replacement, or provider failure cleanup. Pongu retains support correspondence only as needed to respond and maintain records. Content sent to a selected AI provider, Google, Apple, Polar, or another tool is subject to that service’s own terms and retention practices.
We use local owner-only permissions, device-only Keychain records, explicit capability checks, and provider authorization controls appropriate to the native design. No security measure guarantees absolute protection. We may update this policy when the data practices or Google capabilities change; the effective date above identifies the current version.
Contact
Questions, privacy requests, or deletion help: [email protected]. Pongu, LLC develops Pongu AI. Pongu is not affiliated with or endorsed by Google, Apple, OpenAI, Anthropic, or any other provider named on this site.