GPP Automaton · Last updated 31 August 2026
GPP Automaton is a private administrative automation service for Golden Physics Project. It is not offered as a public consumer application. It is used by the project owner and explicitly authorized clients to perform requested work across connected services.
If you authorize GPP Automaton through Google OAuth, the service may access the Google products and data covered by the permissions shown on Google's consent screen. Depending on the scopes you approve, this may include Google Drive files and metadata, Gmail messages and mailbox operations, Calendar data, Google Docs, Sheets and Slides content, YouTube account or channel data, YouTube Analytics data, and Search Console properties.
GPP Automaton uses Google user data only to carry out actions requested by the authorized account holder or an AI/client acting under that holder's authorization. It is not used for advertising, profiling, data brokerage, or sale.
OAuth refresh tokens are stored server-side in Google Secret Manager. They are not displayed to connected clients and are not intended to be returned through ordinary application responses. Short-lived access tokens are obtained from Google as required to perform authorized operations.
Automaton can also connect to services such as GitHub, Supabase, hosting, DNS and cloud infrastructure. Credentials for those systems are stored in managed secret stores or platform credential systems where practical. Connected clients are given authenticated capabilities rather than raw long-lived credentials.
The service may retain operational audit records such as client identity, action name, target service, timestamp, result status and sanitized error information. Secret values, OAuth refresh tokens and other sensitive credential payloads are not intended to be written to audit logs.
Operational data is retained only as long as useful for administration, auditing, reliability or security. Google OAuth authorization remains available until it is revoked, deleted or replaced. Service-specific data may also remain in the underlying Google or third-party service according to that service's own retention rules and the actions requested by the account holder.
We do not sell personal information or Google user data. Data is transmitted only to the services necessary to perform requested operations, such as Google APIs themselves and the project infrastructure used to run Automaton.
You can revoke GPP Automaton's Google access at any time from your Google Account's third-party connections or security settings. The project owner can also delete the stored refresh token from Google Secret Manager.
Automaton uses authenticated provider endpoints, server-side secret storage and restricted operational interfaces. No security system can guarantee absolute protection, but the service is designed so ordinary clients do not need direct possession of underlying long-lived credentials.
Daniel Toupin, Golden Physics Project, Ontario, Canada. dtoupin@goldenphysics.org