Operator Privacy Policy | Northtek

Privacy Policy

Last updated 19 August 2026 · Northtek, Anchorage, Alaska

Operator is a desktop agent that runs on your own Windows PC and does work in your business. This policy explains what data it touches, where that data lives, and what we never do with it. It is written to be read, not to be survived.

The short version

  • Your credentials live on your machine, not on our server.
  • We never sell your data, and we never use it to train AI models.
  • Google data is used only to run the features you switched on, on your machine.
  • You can disconnect at any time, from our dashboard or from your Google account.

Google user data

If you choose to connect Google, Operator requests one scope: https://www.googleapis.com/auth/calendar.readonly – read-only access to your Google Calendar. It does not request access to Gmail, Drive, Contacts, or any other Google service, and it cannot read them.

What we access. The start and end times, titles, and all-day status of upcoming events on your calendar, for roughly the week ahead.

Why. So your agent can see what you are already committed to and work around it – scheduling follow-ups in your genuinely free time instead of on top of a job you already have booked, and answering you when you ask what your week looks like.

Where it goes. Calendar events are read by the agent on your own PC and used to answer you there. Event contents are not copied to our servers, and are not stored by us.

How the connection itself is stored. When you approve the connection, Google issues a refresh token. We encrypt it and hold it only until your paired device collects it – usually within a couple of minutes. The moment your device collects it, our copy is destroyed: the encrypted value is erased from our database in the same operation that hands it over. From then on, your Google token is held on your own machine, in a file restricted to your Windows user account. We could not read your calendar even if we wanted to, because we no longer hold the credential.

Where each connection is held

Not every connection works the same way, and you should know which is which before you connect anything. Operator tells you next to each one, and it is always one of three:

  • On your computer. Google Calendar, and any AI key you paste in yourself. Handled as described above: we hold it only until your machine collects it, then our copy is destroyed. We cannot use these, because we no longer have them.
  • Through a connection service. For apps like QuickBooks, Slack, HubSpot, Calendly and Gmail we use Composio and Nango. For these, that company holds the connection on their servers and requests pass through them – the credential is not stored only on your machine. It is the fastest way to connect a lot of tools, and we would rather say so plainly than let you assume otherwise. You can disconnect any of them at any time.
  • Built for you. When something has no connection available, your agent builds one on your own computer. Nothing is shared with any third party at all.

If it matters to you that a particular credential never leaves your machine, choose the first or third option for that tool, and ask us if you are unsure which one applies.

Limited Use

Operator's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the feature you enabled or as required by law, and we do not use it to develop, improve, or train generalised AI or machine learning models.

Disconnecting

You can disconnect Google at any time from the Keys page in your Operator dashboard, or from your Google account permissions. Revoking the device removes the stored grant from that machine. Because our copy was already destroyed at collection, there is nothing left on our side to revoke – we say this plainly rather than claiming a deletion that already happened.

Other data we hold

  • Your account. Your email address and a hash of your password. We never store your password itself.
  • Your activity record. A signed, chained record of what your agent did – what action, when, and whether it could be verified.
  • API keys you paste. Handled exactly like the Google connection above: encrypted, held only until your device collects them, then erased.
  • Device health. Whether your agent is online and when it last checked in, so we can tell you if it has stopped.

Screenshots are not uploaded unless you explicitly turn that on. It is off by default, per account.

What we never do

  • Sell or rent your data to anyone.
  • Use your business data, your messages, or your calendar to train AI models.
  • Read your machine remotely. Nothing listens for connections on your PC – your agent reaches out to us, never the other way around.

Sub-processors

We use Supabase (database hosting), Vercel (application hosting), and Composio and Nango for the connections listed above as going through a connection service. Those two hold the credentials for those apps; the section above says which. If you supply your own AI keys – Anthropic, OpenAI, Google, Perplexity – the requests your agent makes go directly from your machine to that vendor under your own account and their terms.

Retention and deletion

Your activity record is kept for as long as your account is open, because its value is being able to look back. Email info@northtek.io to close your account and have its data deleted; we will confirm when it is done.

Children

Operator is a business tool and is not intended for anyone under 18.

Changes

If this policy changes in a way that affects what we do with your data, we will tell account holders by email rather than silently updating the date at the top.

Contact

Northtek – info@northtek.io
Anchorage, Alaska, United States