Finance Reports privacy policy

Data access, processing, storage, and deletion for Brennen Slaney’s personal Finance Reports automation.

Effective September 21, 2026.

Finance Reports is a personal-use expense-report automation operated by Brennen Slaney for his own Google accounts and financial records. It is not open for visitor registration or access to other people’s accounts. The project overview describes its purpose and current rollout status. This policy covers the automation, not every other tool on this website.

Google data accessed and why

With the owner’s authorization, the application reads expense transactions, category and account mappings, and pending capture files from a configured Finance folder in Google Drive. Records can include dates, amounts, merchants, categories, account identifiers, and capture notes or filenames. It uses that information to calculate spending summaries, identify entries needing attention, and compare reports over time.

The Drive grant requests drive.readonly and drive.file. The read-only permission technically permits broader Drive access; the application restricts its source reads to the configured Finance folder. The file permission is used for an application-created output folder containing reports, snapshots, and delivery state. Reporting does not edit the source ledger or remove duplicate entries.

A separate Gmail grant requests gmail.send to deliver reminders, reports, revisions, and diagnostic or failure notices from the authorized account to the owner’s configured address. It does not request permission to read the Gmail inbox. Opening these public web pages does not authorize Google access.

Processing and service providers

Google stores the source and output files in Drive and delivers email through Gmail. GitHub Actions temporarily processes the data on a runner. GitHub Secrets holds the credentials and private configuration used by the workflow.

OpenAI Codex and Anthropic Claude receive report evidence and draft/review text to generate and check observations. Evidence includes the reporting period’s qualifying expense rows, with dates, amounts, merchants, categories, and account identifiers, as well as pending capture summaries and changes between snapshots when available. It is not limited to aggregate totals. The source ledger file and the separate ledger snapshot used for report comparisons are not sent as a whole to the models. Individual records from them still appear in the evidence described above, so that evidence is not anonymous. If one provider is unavailable, the other may perform both tasks; the email identifies that fallback.

Model processes do not receive Google credentials, the GitHub credential-writer token, or the other provider’s credentials. Their processing and retention are subject to the applicable provider terms and the owner’s account settings. This application does not offer a guarantee of zero provider retention. The operator does not sell Google user data or use it for advertising. Google data is used to produce and maintain the owner’s requested reports.

Limited Use and model training

Finance Reports will comply with the Google API Services User Data Policy, including its Limited Use requirements, when using or transferring information received from Google APIs. Transfers to model providers are limited to generating and reviewing the owner’s requested reports with the owner’s consent. Google data must not be used to train or improve general-purpose AI models.

Before sending any live Google data to either model provider, the operator must verify that the authenticated accounts’ applicable training and model-improvement settings are disabled and their terms permit this use. This requirement applies to both providers, including single-provider fallback. Report content must not be submitted through optional feedback or data-sharing programs. Until those checks are complete, model checks must use synthetic data only. If the required protections cannot be maintained, live model processing must stop.

These account checks are a manual rollout requirement, not a setting enforced by the reporting code or verified by this website. They remain pending as part of live rollout. Training opt-out does not imply zero retention; the providers’ applicable retention and security terms still apply.

Storage and protection

The workflow stores report content, comparison snapshots, and delivery records in the owner’s application-created Drive folder. Delivered messages remain in the relevant Gmail mailboxes. These records are retained until the owner removes them; no automatic retention period is imposed by the application. Delivery records are used to prevent duplicate sends and should be reconciled before deletion or reuse of a reporting period.

The implementation is designed to keep financial content and credentials out of repository files, public pages, GitHub Actions logs, job summaries, artifacts, and caches. Operational logs contain sanitized status and failure codes. Runner processing uses temporary files, and model invocations disable local session persistence. These controls do not override the service providers’ own retention policies or prevent all possible security incidents.

The public website is hosted by Cloudflare and serves these informational pages separately from the private automation. Visiting them does not expose the private ledger or generated reports. The web host may process ordinary connection information needed to serve the site, such as IP addresses.

Owner controls and deletion

The owner can disable scheduled reporting through the repository configuration and revoke Google access through Google Account connections. Revocation stops future authorized access; it does not delete previously created reports or email.

To remove stored copies, the owner can delete reports and snapshots from Drive, messages from Gmail, and credentials from GitHub, and use the applicable providers’ account controls for provider-held data. Source ledger files remain under the owner’s control and are not deleted by disabling this app. Credentials may require renewal or reauthorization after expiry or revocation.

Changes and contact

This page will be updated when the automation’s data practices change. The effective date identifies the current policy. Questions can be directed to Brennen Slaney using the contact link on the site homepage.