Updated 2026-09-28
Lotus app privacy policy
This policy is about the Lotus desktop app for macOS, and above all about what it does with your Google account when you connect it. The website and its waiting list have their own notice at /privacy/.
Who is responsible
The controller of your data is Alwi Sofwan, the developer of Lotus. Write to alwisofwan567@gmail.com about anything on this page.
Where the app runs
Lotus runs on your Mac. It has no server of its own and no account with us: nothing you do in the app is sent to the people who make Lotus. There is no analytics, no crash report and no telemetry sent to us.
Lotus starts AI coding tools that you install and sign in to yourself, such as Claude Code. Those tools send your prompts and the files they work on to their own providers, under those providers' terms. That is how they work, and it is why this page does not claim your data stays on your computer. Optional features you turn on yourself — voice, notifications to your phone, GitHub, Slack, Notion — talk to the service you connected them to, in the same way.
What Lotus does with Google
Connecting Google is optional. When you do, Lotus signs you in through Google in your own browser and asks for three permissions: openid and email, only to show which account is connected, and drive.file. With drive.file, Lotus can reach only the files it created and the files you pick in Google's own Picker — nothing else in your Drive.
Lotus uses that access for one feature: an automation you set up can add rows to a Google Sheet and save a report file to a Drive folder after each run. To do that it creates a sheet or a file, appends rows to it, uploads a file, and, for a sheet or folder you pick, reads its name, its link, its tab names and the first row of a tab (the column headers). It does not read the other contents of your sheets or files.
Where your Google data is kept
The sign-in token Google gives Lotus is kept in the macOS Keychain on your Mac. The short-lived access token is held only in memory. The connected account's email address and the granted permissions are kept in a file in the app's own folder, so the app can show them without opening the Keychain. None of this is sent to us.
The AI agent an automation runs never receives the Google token and never writes to Google itself. It returns rows and text, and Lotus writes them. The agent is told the column names of the sheet it writes to — which can come from that sheet's first row — as part of the instructions you gave the automation, so those names reach the AI provider you chose, like the rest of your prompt.
Google API Services User Data Policy
Lotus's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements (https://developers.google.com/terms/api-services-user-data-policy).
In plain terms: Google data is used only for the feature you set up, is never sold, never used for advertising, never used to train AI models, and is not read by any person.
Stopping and deleting
Disconnect in the app's Connectors ends Lotus's access at Google (it revokes the token) and deletes the token and the account file from your Mac. You can also remove Lotus at any time from your Google account at https://myaccount.google.com/permissions.
The sheets and files Lotus created or wrote to are yours and stay in your Drive until you delete them. Results the app keeps on your Mac are deleted when you delete the automation or the app.
Your rights
Because the app keeps your Google data only on your own Mac, you can see, change or delete it there yourself. For anything else on this page — including a question about access, correction, deletion, restriction, objection or portability — write to alwisofwan567@gmail.com, and we will answer within one month. You can also complain to your national supervisory authority.
Changes
If the app starts doing something new with Google data, this page changes first and says so at the top, and the app asks for any new permission in Google's own consent screen. The date at the top is the last change.