Privacy policy
Updated October 2, 2026
mikexu.dev is a space for Mike Xu's personal projects. This policy covers their use of Google data.
Google data
With the owner's permission, a personal project uses gmail.readonly to read selected receipts and organize personal records. This permission allows mailbox-wide reading; the reader selects a dedicated label at startup and every ten minutes. It does not send, change or delete mail. Full selected messages, headers, identifiers and derived records are retained on the owner's machine.
Processing and sharing
Google's Gemini API receives extracted payment and order details to suggest categories: identifiers, names, memos, dates, amounts, funding descriptions, item titles and quantities, and matching and classification context. This automatic path excludes raw messages and address headers. The owner can also send item names to connected recordkeeping services or include them in downloaded exports. AI coding assistants may read local records, including full messages, and send them to their model providers; session records may retain them.
Data can therefore leave the machine. Provider retention, training and human-access settings have not been verified; a request to disable storage does not establish those guarantees. Google data is not sold or used for advertising, credit scoring or lending. The Google API Services User Data Policy, including Limited Use requirements, applies. This policy does not certify third-party compliance.
Retention and deletion
There is no automatic expiry or in-app deletion control. Revoking access in Google Account permissions stops new reads but leaves retained copies. Contact the owner below for manual deletion: stop intake, remove retained messages and derived records from local storage, and remove related captures, exports, backups and session copies. Copies already sent to other services require separate handling with those services.
These pages
These pages use no scripts, trackers, analytics or external fonts and expose no retained mail. Cloudflare processes visitor IP addresses and request metadata to deliver and secure the site. Google credentials are kept in owner-only files; access to the owner's machine or authorized assistants can expose local records. Changes to Google data use require updated disclosure and renewed consent.