Public information
Privacy
Effective August 20, 2026 · Founder First Light alpha
This notice describes the current founder-led alpha, including explicitly invited, Living-Story-scoped collaborators. It does not authorize student or public access.
What ImaginOS is
ImaginOS is a private, founder-led creative and educational intelligence environment. Its current purpose is to support one authorized founder through conversation, source-aware research, project coordination, memory, decisions, and deadlines.
Information processed
- Authentication: Google supplies a verified email claim to authenticate the allowlisted founder or an explicitly invited Story collaborator.
- Connected production sources: when an authorized person separately connects Google Drive, ImaginOS may read the selected folder tree and Google Sheets, preserve source locators and version observations, and extract bounded searchable text for the linked Living Story.
- Founder content: conversations, approved Memory Palace records, uploaded source files and their custody classifications, source references, project context, decisions, and deadlines supplied by the founder.
- Voice assist: recordings may be transcribed on request. ImaginOS does not retain the raw recording after transcription.
- Operational records: bounded authentication outcomes, timestamps, hashes, system status, and audit events needed for security, continuity, and recovery.
Authentication and cookies
Ordinary sign-in requests only the Google OpenID Connect scopes openid and email. Connecting a live production folder is a separate, explicit consent step requesting account-wide drive.readonly and spreadsheets.readonly plus offline access so approved Story sources can remain current. ImaginOS itself confines reading to the folder tree the founder registers. It encrypts the resulting refresh token server-side and does not expose it to the browser. The connector cannot write, move, rename, delete, or change permissions on source files. ImaginOS does not request Classroom, Gmail, or Calendar access. The application uses secure, HTTP-only cookies and currently uses no advertising or analytics cookies.
AI and web research providers
Authorized conversation content and the minimum relevant, Story-scoped ImaginOS context may be sent server-side to OpenAI, Anthropic, or Google when the corresponding Executive Producer, Council, transcription, read-aloud, or live-research capability is used. Ordinary turns do not automatically convene every Council provider. Browser clients never receive provider credentials. ImaginOS disables provider-side response storage where the selected API supports that control. Provider retention and abuse-monitoring rules remain governed by the applicable API account and provider terms. Live web research may transmit search queries derived from the current request.
Storage and backups
Operational memory and uploaded-source metadata are stored in a private PostgreSQL trust domain hosted on Railway. Uploaded source bytes are content-addressed, stored as non-executable working copies on the founder's persistent application volume, and linked to the founder-selected Living Story; uploading a document does not make its statements canonical memory. A connected Google Drive folder remains the live, authoritative home of its files. ImaginOS stores versioned observations, locators, hashes when available, and bounded extracted text used for search and source-grounded assistance; it does not duplicate the entire Drive folder into the Palace. Disconnecting a live root stops new synchronization and excludes its indexed excerpts from new model context; the append-only observation and audit history remains preserved unless a separate governed retention action is added. Accepted conversation turns are also written to an independent, integrity-checked journal before model processing. Encrypted recovery backups and human-readable exports may be stored in founder-controlled backup locations, including Box. Provider credentials remain server-side.
Human control
ImaginOS distinguishes preserved conversation from structured and approved memory. Canonical memory, corrections, publication, external sharing, and consequential actions remain subject to the applicable human authority and audit rules. ImaginOS does not silently treat model-generated summaries as source records.
Sensitive material and other people
The authenticated founder's own teaching, health, financial, legal, caregiving, relational, and creative life may be held and organized in the founder's actor-scoped Palace. Sensitive and restricted are handling labels, not owner-access exclusions. Invited collaborators receive only the Living Stories granted to their own verified identities; they do not inherit the founder's unrelated conversations or Palace. Within a shared Story, collaborators may receive source-grounded excerpts and links from its founder-connected Drive root even when their separate Google accounts do not hold direct Drive permission; ImaginOS does not thereby grant them Drive editing rights. Before entering student-identifiable information or granting a student access, the founder must confirm applicable district or institutional authorization or parent or guardian permission and should use only the minimum necessary information. This alpha does not yet provide student accounts, public registration, advertising, or autonomous external monitoring.
Questions and corrections
For questions about this notice or to request inspection or correction of founder-controlled information, contact writer@gloriarodriguez.com.