Last updated: September 14, 2026
Gonzalo HQ is a private personal dashboard operated by Gonzalo Franco at gonzalofranco.com/hq. It has exactly one user: its operator. It is not a product, it has no customers, and it does not accept sign-ups. This policy explains what it accesses and what it keeps.
Only the operator. The dashboard sits behind a password and there is no mechanism for anyone else to create an account or connect data to it. If you are reading this, you are almost certainly here because Google links to it from a consent screen.
With your explicit consent through Google's OAuth screen, Gonzalo HQ requests:
calendar.events) β to display upcoming events on the dashboard, and to create an event when the operator types something like βlunch with Dave Tuesday at noonβ into it.openid, email) β solely to label which account is connected, so the personal and work calendars can be told apart.No other Google scopes are requested. The app has no access to Gmail, Drive, Contacts, Photos, or anything else.
Google user data is not sold, rented, or shared with anyone. It is not used for advertising, for analytics, for profiling, or to train any machine-learning model. It is not transferred to third parties, except to the infrastructure providers strictly required to run the dashboard β Vercel, which hosts it, and Upstash, which stores the refresh token.
Gonzalo HQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The dashboard has a box the operator types into, and that text is sent to OpenAI's API to work out what it is β a reading link, a task, a calendar event. Only what the operator types is sent. Calendar events retrieved from Google are never sent to OpenAI.
The dashboard also pulls the operator's own data from Mercury, Stripe, Hospitable, and Open-Meteo. That data is the operator's own and is kept separate from anything received from Google.
Each calendar has a Disconnect button in the dashboard, which deletes the stored refresh token immediately. Access can also be revoked at any time from Google Account permissions, which invalidates the token regardless of what this app does.
The refresh token is kept until it is disconnected or revoked. Because no Google data is stored, there is nothing else to delete.
If this policy changes, the date at the top changes with it. Given the app has one user, changes will not be announced any other way.
Questions? Email gfrancomontero@gmail.com.