Privacy Policy
Effective September 18, 2026
1. Who we are and what this policy covers
Agni Visual Library is a private, noncommercial visual-reference and image-hosting tool for The Agni Project, a personal creative art, writing, and tabletop roleplaying project. It is operated by Samuel (“Agni Visual Library,” “we,” “us,” or “our”). Questions or requests may be sent to agniprjct@gmail.com.
The project is substantially operated and maintained through agentic artificial-intelligence systems under human direction. Those systems may organize records, maintain documents and software, evaluate submitted material, generate or edit images, and perform other requested project work. AI-generated results may be incomplete, inaccurate, or unexpected and are subject to human review.
This policy covers the public information pages, the private image library, and the authorized Google-connected features of Agni Visual Library.
2. Information we collect
We collect or process only information needed to deliver the website, operate the owner-authorized library, maintain its records, and protect the service. The categories below identify the individual data elements involved and why each is needed.
- Network delivery data. IP address, request date and time, requested URL or route, HTTP method, response status, browser user-agent, device or browser type inferred from that user-agent, referring page when supplied by the browser, and ordinary network or security events. Hosting infrastructure processes these fields to deliver the requested page or file, prevent abuse, diagnose failures, and maintain service security.
- Authenticated-owner data. The authenticated account’s internal user identifier and email address. The application uses these fields to confirm that a person opening private setup or administration routes is the authorized owner and to prevent one account from replacing another account’s stored connection.
- Submitted creative material. Images, prompts, captions, filenames, revision instructions, comments, character or setting descriptions, and other text or files intentionally submitted for an Agni workflow. These items are used to generate or edit requested art, organize the visual-reference library, preserve provenance, and retrieve an exact approved reference later.
- Registry and audit metadata. Universal asset identifiers, file identifiers, filenames, media type, dimensions, byte count, checksums, creation and modification times, prompts, generation status, relationship labels, canon status, hierarchy, supersession and prune history, storage location, command identifiers, error records, and audit timestamps. These fields are needed to identify exact images, prevent incorrect substitutions, reconstruct authorized changes, and maintain database integrity.
- Connection and authorization data. OAuth client configuration supplied by the owner, authorization codes used once during connection, granted scope names, access tokens, refresh tokens, Google account email address, Google Drive permission identifier, connection role, verification time, and connection or refresh status. These fields are needed to establish, refresh, verify, separate, and revoke the owner-authorized Google connections.
The public pages contain no project-added advertising, behavioral advertising, analytics profile, tracking pixel, contact form, or public account-registration feature. The project does not intentionally collect precise location, contacts, financial information, health information, government identifiers, or the contents of a Google mailbox. Infrastructure providers may process ordinary network and security data while delivering the site.
3. How we use information
We use information to provide, display, organize, secure, maintain, troubleshoot, and improve the user-requested functions of Agni Visual Library; operate authorized connections; personalize the project’s AI-assisted workflows; generate and evaluate results; respond to requests; and comply with applicable law.
Agentic AI processing. Agni Visual Library is maintained with agentic artificial-intelligence systems under human direction. Material intentionally submitted directly to the project may be processed by OpenAI or another artificial-intelligence provider to perform requested functions such as generating or editing images, interpreting instructions, organizing records, classifying material, evaluating results, retrieving approved references, maintaining project software or documents, and improving project-specific instructions and reference behavior.
Training of directly submitted, non-Google material. Images, prompts, comments, metadata, and other material submitted directly to the project from a source other than Google Workspace APIs may, when the applicable provider, product, account settings, and user-controlled data settings permit it, be used by the artificial-intelligence provider to develop, improve, evaluate, or train its models, including general-purpose models. The provider’s terms, privacy policy, and data controls govern that provider use. By directly submitting non-Google material while a provider’s model-improvement setting is enabled, the user authorizes that provider use subject to those terms and controls.
Google-data exclusion. The preceding training permission does not apply to any information obtained through Google Workspace APIs. Google-derived data is governed by the permanent no-training restriction in Section 4.7. Google provenance is not removed by downloading, exporting, copying, caching, transforming, summarizing, or combining the information with non-Google material.
We do not sell or rent personal information or submitted content, use it for targeted advertising, provide it to data brokers, or claim ownership of submitted images.
4. Google user data
Google access is optional and begins only after the owner deliberately starts Google OAuth and approves the displayed permission request. Agni Visual Library currently uses the Google Drive API and Google Docs API through the narrow https://www.googleapis.com/auth/drive.file scope. That scope permits the application to work with files it creates and files the user specifically opens or shares with the application; it does not grant unrestricted access to every file in the user’s Drive. The application does not scan the user’s entire Drive. Agni Visual Library’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
4.1 Google account and authorization data accessed
- Google account email address and display name. Read from Google Drive account information to show which account was connected, ensure the archive connection remains attached to the same account, and ensure the canon-writer connection uses the designated project account.
- Google Drive permission identifier. Used as a stable account or permission reference when Google supplies it, so authorization is not based only on a changeable display name.
- OAuth authorization code. Received once at the callback and exchanged for tokens; it is not retained as ordinary project content.
- Access token. Used temporarily to make an authorized Google API request. Access tokens expire and are refreshed as needed.
- Refresh token. Retained so the owner does not need to repeat Google authorization for every authorized Drive or Docs operation.
- Granted scope, connection role, verification result, and verification timestamp. Retained to prove which permission was granted, distinguish the Drive Archive connection from the Canon Writer connection, and identify a failed, expired, or revoked connection.
4.2 Google Drive data accessed and why
- File and folder identifiers. Used to locate the exact original image, canon folder, canon document, or selected project file without relying on filenames.
- File and folder names. Used to display understandable labels, maintain matching library filenames, and confirm that a requested operation targets the intended item.
- MIME type, size, parent-folder identifiers, creation or modification time, application properties, and trashed status. Used to distinguish images, folders, and Google Docs; validate file type; maintain archive structure; locate application-created items; detect unavailable items; and avoid creating duplicate canon folders or documents.
- Web-view link. Stored or displayed so the owner can open the corresponding Google file or canon document directly.
- Owner and permission records. Used to verify that the project account owns a canon document and that the personal account has the intended Commenter permission. Permission records may include role, permission identifier, email address, and pending-owner status.
- Selected file bytes. Image bytes are uploaded to or retrieved from Drive only for owner-requested archive, verification, gallery, backup, or generation-reference functions. The application does not download unrelated Drive files.
- Checksums and derived technical metadata. The application may compute and retain a checksum, byte count, dimensions, media type, and availability state to verify that the retrieved original is the correct unaltered image. These derived fields do not replace the original file.
4.3 Google Docs data accessed and why
- Document identifier, title, parent folder, revision information, and web-view link. Used to maintain a stable link between each database canon node and its subordinate human-readable canon sheet.
- Document text and structure. Read when the owner requests a canon-document synchronization or verification. Written only after the authoritative database change has been validated, so the readable document reflects verified database state.
- Comments, comment anchors or quoted context, replies, author information supplied by Google, status, and timestamps. Read only when the owner requests “Canon Comments,” “Doc comments,” “document comments,” or an equivalent synchronization command. The information is used to identify a proposed correction, present or validate the requested database change, record its result, reply when appropriate, and resolve the comment only after the verified database and document update succeeds.
- Document permission information. Read and, when expressly initialized or repaired, written to maintain the Canon Writer account as owner and the personal account as Commenter.
Unresolved Google Docs comments are treated as proposed changes, not as executable canon. Reading a comment does not automatically alter the database, choose a generator reference, or authorize an unrelated use.
4.4 Actions the application may take in Google
At the owner’s request, the application may create the Agni Canon folder; create a canon Google Doc; insert or update canon text after a verified database change; upload an image original; download a selected original; list or search application-created or specifically authorized files; read file metadata; add or verify the designated Commenter permission; read, reply to, or resolve a canon-document comment after processing; and test whether a saved authorization can still refresh and access the intended account. It does not delete Google files during ordinary artwork workflow. Destructive removal is reserved for a separately authorized maintenance operation.
4.5 Gmail data and operational alerts
The existing Drive and Canon Writer connections do not read Gmail. If the separate operational-alert feature is enabled, the project account will request only https://www.googleapis.com/auth/gmail.send. That permission will be used solely to send backup-failure, audit-failure, and overdue-run alerts from the designated project Gmail account to the owner. The application will create and transmit the outgoing message, recipient address, subject, operational status, incident or run identifier, and necessary timestamps. It will not request permission to read the inbox, read message history, modify messages, manage labels, delete mail, or inspect unrelated email. Until that separate feature is authorized, the application does not access Gmail data.
4.6 How Google data is used
Every use of Google user data is tied to a visible, owner-requested Agni function: maintaining the image archive; retrieving an exact image reference; verifying file identity and integrity; maintaining readable canon documents; processing an expressly requested canon comment; preserving an audit trail of those operations; testing and refreshing an authorized connection; maintaining the required owner/commenter boundary; or sending a specifically described operational alert. Google user data is not used to build a general-purpose database about the user, advertise to the user, profile interests, determine creditworthiness, make lending decisions, sell information, supply information resellers, or support an unrelated commercial purpose.
4.7 AI and machine-learning restriction
We affirm that Google Workspace API data is not used to develop, improve, evaluate, or train generalized or non-personalized artificial-intelligence or machine-learning models. We do not sell Google user data or disclose or transfer it to OpenAI, another model provider, or any other third party for those purposes. This prohibition applies even though Section 3 separately describes possible provider training for material submitted directly from non-Google sources. If Google-derived content is processed by an AI provider to perform a function specifically requested by the owner, it may be transmitted only through a product, account, contractual arrangement, and technical configuration that prohibit the provider from using that data for model training. If that no-training condition cannot be verified, the application will not transmit the Google-derived data and the requested operation will stop.
Google OAuth credentials, authorization codes, access tokens, and refresh tokens are never submitted to an AI model. Exporting, caching, transforming, or copying Google-derived information does not remove these restrictions.
4.8 Where Google data is stored
- Google Drive: selected full-resolution image originals, application-created folders, canon Google Docs, and Google’s own permission and revision records remain in the authorized Google accounts.
- Protected authorization storage: OAuth client credentials and separate refresh-token records for the Drive Archive and Canon Writer roles are encrypted before storage. The authorization store contains connection credentials and verification receipts, not image originals or canon content.
- Supabase project database: the service may store stable Google file or folder identifiers, filenames, web-view links, checksums, byte counts, media types, dimensions, relationship metadata, provenance, document-revision bindings, comment-processing receipts, connection status, and audit events. It does not store Google account passwords.
- Temporary processing memory and caches: an access token, selected file bytes, document text, or comment data may be held briefly while completing the requested operation. Temporary material is discarded when no longer needed for that operation, except for the deliberately retained registry or audit fields described above.
4.9 Security protections
Google credentials and refresh tokens are encrypted at rest using authenticated encryption and are transmitted over HTTPS. Archive and Canon Writer tokens are stored as separate role-bound records so reconnecting one account cannot silently replace the other. Private setup routes require the authenticated owner account, origin validation, an expiring owner-bound anti-forgery token, and an expiring OAuth state. OAuth uses PKCE. OAuth attempts are consumed once to prevent replay. Credentials are not displayed after storage, placed in public pages, included in image metadata, or intentionally written to application logs. Access to private project data is owner-only, and the application requests the minimum Google permission needed for an implemented feature.
4.10 Sharing and human access
Google user data is disclosed only when necessary to provide the requested function: to Google for Drive, Docs, OAuth, and any separately authorized send-only Gmail operation; to the project’s hosting provider to run the application and deliver requested content; to Supabase to store the limited registry and audit fields listed above; and to an AI processor only for a user-requested operation under the no-training restriction in Section 4.7. Samuel, as the owner and operator, may review specific files, comments, records, or errors when necessary to direct the creative workflow, answer a request, investigate a failure or security event, or perform authorized maintenance. Google user data is not disclosed to advertisers, data brokers, information resellers, lenders, or unrelated third parties.
4.11 Retention
- Image originals and canon documents remain in Google Drive until the owner deletes them or directs a dedicated maintenance operation to remove them.
- Registry identifiers, checksums, provenance, relationship history, and audit receipts are retained while the corresponding library artifact exists and may remain afterward when necessary to preserve the integrity of the append-only audit history. A pruned item remains preserved and excluded from reference use; pruning is not deletion.
- Refresh tokens and connection records are retained until the connection is revoked, replaced, or deliberately removed. Short-lived access tokens expire according to Google’s authorization service and are not treated as permanent library records.
- Processed comment content remains in the Google Doc according to Google’s document history and may be summarized in the project audit record. The application does not retain an additional full comment copy unless needed to document the authorized change or a failed operation.
- Temporary processing copies are kept only long enough to finish, retry, verify, or safely abort the requested operation.
- Security and error records are retained only as long as reasonably necessary to diagnose incidents, prevent repeated failure, and demonstrate the integrity of project operations.
4.12 Revocation, disconnection, and deletion
The owner may revoke future Google access at any time through Google Account connections. The owner may also request removal of the application’s saved Google connection, deletion of retained Google-derived information, or deletion of a Google-hosted project file by emailing agniprjct@gmail.com. Revocation stops new API access after existing access credentials cease to be valid; it does not itself delete files still held in the owner’s Google Drive or erase records already retained for audit integrity.
Upon a valid deletion request, the operator will identify the requested account, connection, file, or record; revoke or remove the relevant stored credential where applicable; delete or de-identify retained data that is not required for security, legal compliance, or integrity of the append-only project audit; and direct deletion of a Google-hosted file only through an expressly authorized maintenance action. Provider backups may retain a protected copy until their normal backup cycle expires. When an audit entry must remain, it will be limited to the identifier, action, time, and integrity information needed to show what occurred rather than retaining unnecessary file content.
5. Disclosure and service providers
We disclose information only to service providers where necessary to host, transmit, secure, operate, or provide requested AI-assisted functions; when the user directs us to do so; to investigate misuse or protect security; or when required by law. Current infrastructure may include OpenAI and OpenAI Sites, their hosting providers, Google for authorized Google services, Google Drive for original-file storage, Supabase for project metadata, and other AI providers selected for a requested workflow. Each provider may process information under its own terms, privacy policy, and data controls. Google Workspace API data remains subject to the stricter purpose, sharing, and no-training restrictions in Section 4.
We do not sell, rent, or commercially license personal information or submitted images to third parties.
6. OpenAI relationship and independence
Agni Visual Library and The Agni Project are independent personal projects and customers or users of third-party technology services. They are not owned, operated, sponsored, endorsed, certified, or represented by OpenAI. Neither Samuel nor the project is an employee, agent, partner, reseller, spokesperson, or authorized representative of OpenAI. References to OpenAI describe a technology provider and customer relationship only. OpenAI’s own collection and use of information are governed by OpenAI’s separate Privacy Policy, Terms of Use, and applicable data controls.
7. Legal bases and international processing
Where the GDPR, UK GDPR, or similar law applies, we process essential delivery and security data because it is necessary to provide the requested service and for our legitimate interests in maintaining a safe, functional personal project. We process optional connected-account data and user submissions at the user’s request and, where required, with consent. We may process information to comply with legal obligations.
The project and its providers may process information in the United States and other countries. Where applicable law requires safeguards for an international transfer, the relevant provider or operator must use an appropriate lawful mechanism.
8. Retention, security, and deletion
We retain submitted images and project records for as long as the owner keeps them in the library or they are needed to preserve the project’s audit history. Technical logs are retained only as long as reasonably necessary for delivery, security, diagnosis, and provider operations. Authorization information is retained while a connection remains active or until it is revoked, replaced, or removed. Provider backups and logs follow the provider’s retention practices. Section 4 supplies additional retention and deletion details for Google user data.
We use access controls and appropriate technical safeguards, but no online system can guarantee absolute security. Users should keep independent copies of irreplaceable content.
To request access, correction, deletion, restriction, portability, or objection where applicable, contact us at the address above. We may need proportionate identity verification. We will respond within the period required by applicable law. A user may also complain to the relevant data-protection authority. We do not make automated decisions that produce legal or similarly significant effects.
9. Children and changes
Agni Visual Library is a private project not directed to children. We will revise this notice when our actual practices materially change and will obtain any consent required before using previously collected information for a materially different purpose.