Just visiting the website? Part 1 is the part that applies to you, and it is short.

Arrived from a Google consent screen? Go to Part 2 — that describes the application asking for access.

Who operates this

Knappleton LLC, a California limited liability company based in San Diego, California — the consulting entity of which Jason Knapp is the manager. Contact: jason@jknapp.com.

Part 1 — The jknapp.com website

jknapp.com is a static site. There are no user accounts, no login, and no sign-up. Nothing you do here builds a profile of you, and nothing collected here is sold, rented, or used for advertising retargeting.

What is collected, and by whom

The site loads three third-party services. Each sees something about your visit:

Service What it sees Cookies?
Google Analytics 4
(measurement ID G-M4N8KXMX1D)
Pages viewed, approximate location derived from your IP address, device and browser type, and how you arrived. Present on most pages of the site. Yes — Google sets its own cookies to recognise a returning browser.
Vercel Analytics Aggregate page views and performance timings. No.
Google Fonts Your IP address, because your browser fetches the typefaces from Google's servers when a page loads. No.

What those companies do with what they receive is governed by Google's Privacy Policy and Vercel's.

Cookies this site sets itself

Separately from Google's, a few areas of the site set their own cookies. They exist to make a page work, not to track you across the web, and they are not shared with anyone:

Cookie What it is for
mn_portal_auth
owaves_proto_auth
Some prototypes and client documents sit behind a shared passcode. Once you enter it, these remember that this browser is allowed in, so you are not asked again on every page.
mn_reviewer_name On pages where you can leave review comments, this remembers the name you typed so you do not retype it on each note.

Things stored in your own browser

On a few pages — prototypes and annotated write-ups — you can leave comments or notes. Those are saved in your browser's own localStorage. They stay on your device, are never transmitted anywhere, and cannot be read by Knappleton LLC. Clearing your browser's site data for jknapp.com removes them, along with the cookies above.

Getting in touch

There is no contact form on this site. The contact links open your own email client addressed to jason@jknapp.com. If you write, that email — and whatever you chose to put in it — arrives in a mailbox Knappleton LLC controls and is kept as ordinary business correspondence. Nothing is collected from you unless you send it.

Your choices

  • Cookies: your browser can block or delete them. Nothing on this site breaks if you do.
  • Google Analytics: Google publishes a browser opt-out add-on that applies to every site using it. Content blockers and tracking-protection settings stop it too.
  • Page notes: clear your browser's site data for jknapp.com.

Children

This site is not directed at children and does not knowingly collect information from them.

Part 2 — Jason's AI Assistant

This part has nothing to do with visiting the website. It describes a private automation that runs on one machine and reads Jason Knapp's own Google accounts. It is not a product, it has no other users, and it cannot be signed up for. If a Google consent screen linked you here, the sections below describe exactly what it would read from the account being authorized.

1. What the application is

Jason's AI Assistant is a set of scripts that run on a single Mac under Knappleton LLC's physical control. They read Jason Knapp's own email, calendar, contacts and documents in order to do work he would otherwise do by hand: assembling a daily briefing, routing meeting transcripts to the right client, tracking consulting time, drafting messages for his review, and keeping records in order.

There is no server, no hosted backend, no user account system, and no way for anyone else to sign in to it. Every authorization it holds was granted from one of Jason Knapp's own Google accounts.

2. Whose accounts it accesses

It holds OAuth authorizations for Google accounts belonging to Jason Knapp, across several organizations he works in or for:

  • his personal and business accounts (jknapp.com / sbknapps.com);
  • accounts in companies he works with, where the account is his and was issued to him as a consultant or officer;
  • accounts in a client's Google Workspace, where the client's administrator has permitted the authorization.

It never accesses another person's account. Where an account exists inside an organization Knappleton LLC does not own, the authorization is granted from his account in that organization, is limited to what that account can already see, and can be revoked at any time by him or by that organization's Workspace administrator.

3. What data it accesses, by Google service

Different accounts grant different permissions. The table below is the full set the application can request; no single account grants all of it.

Google service What it can do Why
Gmail Read messages; apply and remove labels; archive; create drafts; send mail Triage the inbox, summarize what needs attention, prepare drafts for review, and send notifications that have been approved
Google Calendar Read events; on one account only, create and update events Assemble meeting briefings, and attribute working time and meeting transcripts to the correct client
Google Drive Read file metadata and contents; on one account only, create and modify files Read meeting transcripts and working documents, and know which client a document belongs to
Docs, Sheets, Slides Read contents; on some accounts, create and edit Read working documents, and produce documents that were asked for
Contacts Read, and on some accounts update, contact records Recognize who a message or meeting involves
Search Console Manage sitemaps and read search data for domains Knappleton LLC owns Maintain its own websites
Account email address Read the address of the authorized account Verify that a stored credential belongs to the account it claims to, so the application cannot act on the wrong account

Client Workspace accounts are read-only. Where the account is in a client's organization, the authorization requests read permissions only — no ability to send, write, modify or delete anything in that organization. That is a deliberate design constraint, not a coincidence: an automation has no business writing into a client's tenant.

4. Google Limited Use disclosure

Jason's AI Assistant's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used only to provide the functions described in section 3.
  • Google user data is not transferred or sold to any third party for advertising, market research, credit assessment, or any similar purpose.
  • Google user data is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models.
  • No human other than Jason Knapp reads Google user data obtained through this application, except where disclosure is legally compelled, where it is necessary for security purposes or to investigate abuse, or where the account holder's own organization requests it.

5. Where the data goes

Data read through these APIs is processed and stored on that one Mac, under a single password-protected user account. OAuth credentials live in a directory readable only by that account, and are excluded from every code repository — no credential file is tracked in version control.

There is no cloud database, no analytics pipeline, and no third-party data processor. The application does not send Google user data to any advertising network, data broker, or marketing platform.

6. AI processing

Some of this work is done by AI language models. Two kinds are used:

  • Models running locally on the same Mac. Content sent to these never leaves the machine.
  • Anthropic's Claude, through an authenticated developer session. Content sent this way is transmitted to Anthropic and handled under whatever terms govern that account at the time. Knappleton LLC does not grant, and cannot grant, any third party the right to use this content to train models.

No other AI provider receives Google user data from this application: its own code makes no calls to any third-party AI service — only to Google's APIs and to models on this machine. Content is sent to a model only when needed for one of the purposes in section 3 — for example, summarizing a meeting transcript or drafting a reply for review.

7. How long data is kept

Working records produced by the automation — meeting transcripts, time-tracking entries, notes, briefings — are retained on that machine indefinitely, because they are Knappleton LLC's business records and their history is needed. Cached copies of Google content are kept only as long as they are useful and are overwritten as they refresh.

If you are an organization in whose Workspace an authorization is held and you want records derived from your tenant deleted, write to jason@jknapp.com and Knappleton LLC will delete them and confirm.

8. Sharing

Google user data obtained through this application is not shared with anyone. It is not sold, not rented, not licensed, and not disclosed to third parties, except:

  • to the AI provider named in section 6, strictly to perform a requested task;
  • where disclosure is required by law or valid legal process;
  • to the account holder or their Workspace administrator, on request.

9. Revoking access

Any authorization can be withdrawn at any time, without notice and without Knappleton LLC's cooperation:

  • An individual account holder: myaccount.google.com/permissions → select Jason's AI AssistantRemove access.
  • A Google Workspace administrator: Admin console → Security → API controls → App access control, where the application can be blocked for the whole organization.

Revocation takes effect immediately. The application's stored credential for that account stops working, and it reports an authorization failure rather than degrading quietly.

10. Security

The machine requires a password to unlock. Credentials are held in a directory readable only by a single user account, are excluded from version control, and are scoped per account so that one authorization cannot be used to reach another — every stored token is identity-checked against the account it claims to belong to before use, so a token cannot act on the wrong account. Read-only scopes are used wherever write access is not genuinely needed, and client organizations get read-only scopes without exception.

No system is perfect, and this policy will not pretend otherwise: this is a single machine used by one person, and the security of the data is the security of that machine. If you believe a credential has been compromised, revoke it using section 9 and tell us.

Applies to both

Changes to this policy

If either the website or the application changes materially, this page changes with it and the effective date at the top is updated. The dated page is the record.

Contact

Questions, deletion requests, or a security concern — Knappleton LLC, jason@jknapp.com.

Terms of Service →