Privacy policy
Effective upon first publication.
This policy describes Chula Vista CPA APC’s Google Contacts caching, local identity audit, audit spreadsheet, and related interactive contact lookup. It does not describe unrelated Hermes features.
Information accessed and used
With the Google account holder’s authorization, the Contacts workflow reads names, organizations, phone numbers, email addresses, contact identifiers, and synchronization metadata. Selected details and normalized phone/email values are stored in a local server database.
Local audit JSON/CSV files and change-tracking state contain contact details, identifiers, timestamps, normalized snapshots, hashes, and findings. Hashes do not make these records anonymous. Existing Zoho CRM exports are read locally for reconciliation; this workflow does not change records in either contact source.
The Sheets/Drive workflow reads audit-file and tab metadata and writes selected contact details and findings to the existing audit spreadsheet. Its fixed audit columns exclude tax identifiers, addresses, fiscal notes, and source documents.
Purposes and recipients
Data is used for office contact lookup, identity matching, duplicate and missing-detail review, change detection, and integration health monitoring.
Google processes the authorized API requests and hosts the Chula Vista - Identity Data Quality Audit spreadsheet. The office has verified that General access is Restricted and that only its authorized owner account is listed. No additional users or public sharing were identified in that review. Access follows the spreadsheet’s sharing settings; any future sharing changes require review.
Operational health notifications sent through Microsoft Graph contain statuses, timestamps, counts, and related diagnostic information. The compact watchdog notification path does not send contact rows.
Scheduled processing and interactive AI
Scheduled synchronization and auditing are deterministic and make no AI-model inference calls.
Interactive Hermes contact lookups have transmitted Google-derived contact details to Nous Portal for AI-assisted responses. Retained conversation records show contact names and phone or email values returned by local lookup tools and used in subsequent responses through Nous’s inference service. Those details also remain in local conversation history. Hermes currently uses Nous Portal; requests may be processed by the selected model and infrastructure providers. Conversation summarization can also use automatically selected auxiliary services. Local configuration does not establish the complete downstream recipient chain or downstream provider retention and training settings.
Nous Portal Privacy Mode is enabled for this account, as verified by the office. Nous states that, with this setting, inference payloads are not stored or used for training or product improvement, subject to the operational, security, legal, and abuse-prevention exceptions in its policy. Operational metadata may still be retained. These protections apply to Nous Research and do not establish independent downstream providers’ practices or retroactive deletion of historical data. Downstream no-training and retention controls have not been verified; we make no claim of downstream zero-retention or no-training. Publishing this policy does not authorize prohibited secondary use of Google data.
Storage and security
Contact caches, credentials, synchronization state, and audit outputs are stored on the office’s server. OAuth token files and the contact cache have restricted filesystem permissions; audit outputs have different permissions. Secret redaction is not a guarantee that contact names, phones, or emails are removed from conversation content.
The private portal is protected separately by Cloudflare Access. This policy makes no guarantee of application-level encryption at rest, uniform file permissions, or complete anonymization.
This informational website contains no client records, credentials, operational endpoints, forms, application scripts, analytics code, or application-set cookies. Cloudflare serves the static pages and may process IP addresses and other request information under its own policies; infrastructure security features may operate independently of the page code.
Retention and deletion
There is no uniform automatic time-based purge across contact caches, snapshots, audit files, reports, credential backups, and conversation history. Automatic Hermes session pruning is currently disabled; a configured 90-day value is not an enforced deletion deadline.
Latest audit outputs and spreadsheet tab contents are replaced on successful refresh. Incremental synchronization processes source deletions, and full synchronization rebuilds the current cache. Neither operation guarantees deletion of historical copies, spreadsheet history, backups, provider records, or prior conversations.
Revoking Google authorization stops future access under the revoked authorization; it does not automatically erase stored copies. Contact the office to request review or deletion. Applicable recordkeeping obligations and the relevant storage locations will be considered. No automatic deletion deadline is promised.
Google authorization and revocation
Contacts uses contacts.readonly. The separate Sheets/Drive client uses drive.file. You can review or revoke access in Google Account third-party connections. Google may group both clients’ permissions under the same application, so revocation can affect both integrations.
Google Limited Use and policy changes
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google-derived data must not be sold to data brokers, used for advertising, or used to train generalized AI models. This commitment is not a claim that every provider setting has been verified.
Material changes to Google-data use require updated disclosures and any required consent before the new use begins.
Contact
Chula Vista CPA APC — alvaro@chulavistataxcpa.com.