Who runs this site
Shivam Bhardwaj operates too.foo under the name Antimony Labs. This policy covers the website and its connected tools, including SBL Console, Organize, and Soma. An app may provide additional notices about its particular features. External websites linked from too.foo have their own policies.
Visiting the website
Public lessons, simulations, and project pages can be browsed without connecting a Google or wearable account. Hosting and security providers, including Cloudflare, process request information such as IP addresses, browser details, requested URLs, and timestamps to deliver the site and protect it from abuse. The site uses Cloudflare Web Analytics to measure visits and performance.
Cookies and browser storage remember preferences such as theme, accent, language, and app settings. Apps with sign-in also use authentication state to control access. Clearing browser storage resets locally stored preferences and may sign you out.
If you subscribe to updates or contact the operator, your email address and the information you provide are used to deliver those updates or respond. You can ask to stop receiving updates using the contact address below.
Google account data: SBL Console
SBL Console (also called Console) is the operator's private workspace and personal assistant interface. Its Google integration connects the operator's Gmail and Calendar accounts for email search, summaries, scheduling context, and organization of receipts and subscriptions. It is not open for public Google account registration.
- Access: authorized account information; Gmail message identifiers, senders, recipients, subjects, dates, labels, and message text; and Calendar event details such as titles, times, descriptions, locations, and attendees.
- Use: synchronize messages and events into private searchable memory, answer the operator's questions, classify email, and extract useful reminders and spending records.
- Actions: scheduled synchronization reads Google data. It does not send email or automatically create Calendar events. Any separately enabled action requires the relevant account permissions and operator authorization.
- Storage: OAuth credentials, synchronized records, derived summaries, search indexes, and operational logs are stored on systems controlled by the operator. Private records are not published on the public website.
Google Drive data: Organize
Organize uses the operator's authorized Google Drive account for private file inventory, checksum verification, organization, and backup.
- Access and use: account identity; file and folder names, paths, identifiers, owners, sizes, timestamps, and checksums; and file contents for requested downloads and uploads. The Drive permission also allows file and folder changes, including moves and deletions. The operator determines which operations to run.
- Storage: file copies, inventories, checksum records, and operational logs may be retained on operator-controlled computers and drives, in the operator's Google Drive, and with other online storage providers chosen by the operator. OAuth credentials are kept in private configuration and encrypted backups, outside the public website and source code. The archives remain private.
- Archive copies: the workflow aims to maintain an online copy and a separate hard-drive copy. Verification records identify actual coverage. The retention, disconnection, and deletion information below also applies to these files and records.
AI processing and service providers
Console's email classifier sends message metadata and a limited portion of message text to the DeepSeek API to classify and summarize email and extract structured information. Relevant messages, Calendar context, and derived memory may also be passed to the AI provider configured by the operator when using the assistant. Connected data is therefore not processed exclusively on local hardware.
When the operator uses an AI assistant to organize files, relevant file metadata, operational reports, and any file content supplied to that assistant may be processed by the operator's configured AI provider.
These services process the content sent to them under their own service terms and retention settings. The operator uses them to provide the connected assistant features. Contact the operator for the current provider configuration before supplying sensitive information through an app.
Google account data is not sold or used for advertising or credit decisions. Use and transfer of information received from Google APIs must follow the Google API Services User Data Policy, including its Limited Use requirements. This policy does not grant permission to reuse connected account data for unrelated purposes.
Wearable data: Soma
Soma is a private personal wellness dashboard. When connected, it reads the operator's Oura and Whoop sleep, recovery, readiness, heart-rate, workout, and related measurements to display trends. It stores synchronized records on operator-controlled systems. The provider's consent screen specifies the access granted to each connection.
Retention, disconnection, and deletion
Connected records and derived memory are retained for the operator's ongoing use until removed; there is no automatic fixed deletion period for this private archive. Operational records and backups may persist separately from the active application.
You can revoke Google access through your Google Account connections, or revoke a wearable connection through its provider. Revocation stops future authorized access but does not erase copies already synchronized.
To request deletion, contact the operator. The request needs to cover stored records, derived summaries, search indexes, and applicable backups as well as connection credentials. The operator will explain what can be removed and any remaining retention constraints. Never send passwords or access tokens by email.
Security and changes
Private apps use access controls, and connection credentials are kept outside the public website and source code. No service can guarantee complete security. This page will be updated when these practices change; new uses of connected Google data require updated disclosure and consent where required.
Contact
For privacy questions, access, or deletion requests, email Shivam Bhardwaj at shivam@too.foo.