Your data
Privacy policy
Last updated September 21, 2026 · Sho Builds It
Scope
This policy covers Sho Builds It’s private productivity, learning, fitness tracking, email automation, and workflow tools described on the Apps & tools page. These tools use Google APIs when required for personal tracking, monitoring, study, training records, or specific automation and notification features. Public app releases and client-operated workflows have their own applicable disclosures. Portfolio case studies are descriptions of past work, not services offered through this website.
Information accessed and why
- Google Sheets: learning, habit, fitness, and workflow records used for personal dashboards, practice, and record keeping. Some tools read records; others also add or update them.
- Gmail: one lesson-notification automation reads matching messages, including subject lines and message bodies, to locate lesson-message links. Its permission allows broader read access than the messages selected by its search.
- Google Calendar: a separately configured service account accesses an authorized calendar to maintain lesson events.
These desktop tools do not request basic Google profile scopes or general Drive access through user OAuth. A separately configured spreadsheet workflow uses service-account access with Sheets and Drive permissions to work with a configured spreadsheet. Permissions and actual use are not the same: a broad permission does not mean every accessible file is read.
Storage and retention
Desktop OAuth tokens are stored using macOS Keychain. Some desktop tools share an authorization. The lesson-notification automation instead stores its OAuth token in a local file. Service-account credentials are also local files.
Working records, pending changes, settings, and some backups are stored locally as files or databases. Synchronized records remain in the connected Google Sheets or Calendar. Local operational logs can contain identifiers and diagnostic details; notification preview logs can contain notification text.
No single automatic deletion period has been established across these tools. Records, logs, and backups can remain until the owner removes them. This policy does not claim that all data stays on the device or that all local files are encrypted.
Connected services and sharing
Google processes requests required by the connected features. The lesson automation can send a teacher-message notification to the owner through LINE. The message is retrieved from the lesson service using a link found in Gmail; a teacher name from the email can be used as a fallback.
Sho Builds It does not sell Google user data, use it for advertising, or share it for unrelated purposes. Data is transferred only as needed for the described, authorized features, such as the owner’s lesson notifications.
Google API data
Sho Builds It’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including applicable Limited Use requirements. This applies to derived information as well as the original data. Google has not verified or endorsed these tools.
Disconnecting and deleting data
You can remove an app’s access through your Google Account connections. Revoking access prevents future authorized access; it does not delete existing records, logs, backups, Google Sheets rows, calendar events, or notifications.
For complete deletion, stop the relevant tool and remove its local records and backups, then remove any corresponding records in the connected services. Confirm the tool-specific steps first to avoid deleting unrelated data. Revoking a shared authorization can affect more than one tool. Service-account access must be removed through the relevant resource’s sharing or permission settings.
For help identifying the records, local storage, or shared connection used by a particular tool, contact us before deleting anything. Do not send credentials, access tokens, or unnecessary personal records.
Security
Google OAuth uses Google’s authorization pages and HTTPS API endpoints. Tokens and credentials are not part of this website. Local file protection varies by tool; no claim is made of universal encryption, completed security assessment, or guaranteed security.
Website and contact
These informational pages have no Google sign-in or data-upload feature. The site uses Cloudflare Pages for hosting. Cloudflare processes network information such as IP addresses and request details to deliver and protect the site, under its privacy policy. The site does not add advertising trackers or analytics scripts.
If you email us, your address, message, and any attachments are processed by Cloudflare Email Routing and Google’s email service so we can respond. Correspondence is kept while needed to handle your request and any necessary follow-up; no fixed automatic deletion period is configured. You can ask us to delete correspondence, subject to any applicable retention obligations.
Privacy contact: [email protected]
This policy will be updated when covered features or data handling change.