Privacy Policy
This policy explains how PicoMander handles information when the desktop application, its local features and the optional Google Contacts and Google Sheets integrations are used.
1. Controller and contact
PicoMander is a project developed by Guillermo Allasia. For questions about privacy or data use, write to soportepicomander@gmail.com.
2. Google services and permissions used
PicoMander requests only read-only permissions for the features the user chooses to enable:
https://www.googleapis.com/auth/contacts.readonly: allows the application to view and download contacts from the authorized account.https://www.googleapis.com/auth/spreadsheets.readonly: allows the application to view Google Sheets spreadsheets accessible to the authorized account.
The Google Sheets permission technically allows access to spreadsheets available to the account. PicoMander does not browse or catalogue Google Drive: it queries only the spreadsheet whose link or identifier is provided by the user.
3. Google data PicoMander may process
From Google Contacts, depending on the information stored in each contact, PicoMander may receive names, phone numbers, email addresses, postal addresses, organizations, job titles, dates, notes and other available fields.
From Google Sheets, PicoMander may read the title of the indicated spreadsheet, sheet names, headers and the cell values required to display rows and convert the selected row into the configured format.
Spreadsheet content is determined solely by its creator. It may include personal, administrative, appointment or health-related information. PicoMander does not determine or expand that content.
4. Purpose of access
Data is displayed locally within PicoMander Setup so the user can search it or review a row, select the required fields and decide when to send them to a local module, PicoMander device, equipment or software configured by the user.
Information obtained from Google is used only to provide the feature requested by the user.
5. Actions PicoMander does not perform
- It does not request or receive the Google Account password.
- It does not create, modify or delete Google contacts or spreadsheets.
- It does not use Google Drive to search for other files or query spreadsheets the user has not indicated.
- It does not sell personal data, use it for advertising or build commercial profiles.
- It does not use data obtained from Google to train artificial intelligence models.
- It does not store the address book or spreadsheet contents on developer-controlled servers.
- The developer does not remotely access this data. Information may only be received if the user voluntarily sends it in a support request.
- It does not share Google data with third parties, except when the user explicitly sends it to a destination configured by the user.
6. Local storage
OAuth authorization creates separate local tokens for Google Contacts and Google Sheets. These tokens keep the authorization active without requesting credentials again and are not sent to PicoMander servers.
For Google Sheets, PicoMander may locally save the spreadsheet link or identifier, selected sheet, headers, field aliases and other preferences needed to reopen that source. Read rows are kept in application memory while they are being used.
PicoMander does not create a permanent copy of the address book or spreadsheets on developer-controlled servers.
7. Transmission, sharing and user-selected destinations
The application communicates with Google through official APIs and secure connections. Subsequent transmission to PicoMander Setup, another local module, a PicoMander device or destination equipment occurs only after a user action and according to the configuration selected by the user.
The user is responsible for ensuring they are authorized to process the data and for reviewing the row, fields and destination before sending it.
8. Retention
PicoMander does not retain Google data on its own servers. Local tokens and configurations remain on the computer until the user deletes them, revokes access, or uninstalls the application and removes its data.
9. Revocation and local deletion
The user can select Remove token in the relevant tool, delete the local files token_google_contacts.json or token_google_sheets.json, or revoke PicoMander access from the connected-apps section of the Google Account.
After access is revoked, PicoMander cannot query the data again until the user authorizes it. Deleting a local token does not modify or delete information stored by Google.
10. Security and data protection
PicoMander applies measures designed to reduce exposure and protect the confidentiality of data obtained through Google APIs:
- Authorization is performed through Google's OAuth 2.0 flow in the system browser. PicoMander does not request, receive, or store the user's Google Account password.
- Communication with official Google APIs is performed over HTTPS/TLS connections, protecting data while it is transmitted.
- PicoMander requests only read-only permissions for Google Contacts and Google Sheets. These integrations cannot create, modify, or delete that Google data.
- Contacts and spreadsheet rows read from Google are not stored on developer-controlled servers. They are processed locally on the user's computer and kept only while needed to perform the user-requested function. OAuth tokens and configuration preferences are stored only locally.
- Information obtained from Google is used only to display the requested data and allow the user to select which fields to use or send. Any subsequent transfer occurs only after an explicit user action and only to the local module, PicoMander device, equipment, or destination software configured by the user.
- When the configured destination receives data as keyboard input, PicoMander sends only the information selected by the user through simulated keystrokes. This operation is performed locally and does not send that data to PicoMander servers.
- Communication between PicoMander modules running on the same computer may use the local loopback interface (
127.0.0.1), keeping that exchange within the user's computer. - Access can be revoked at any time through the user's Google Account or by deleting the local tokens. Users should protect their Google Account, Windows session, and physical access to the computer where local tokens and configuration files are stored.
11. Google user data and Limited Use
PicoMander's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. PicoMander limits access, use, storage and transfer of Google data to the practices described in this policy.
12. Changes to this policy
This policy may be updated when PicoMander features or applicable requirements change. The date of the current version appears at the beginning of this page.