Cardea

Privacy policy

Last updated August 27, 2026

Cardea is a personal agent workspace built for the OpenAI WebMCP Challenge. This page describes what the service collects, what it deliberately never stores, and how to get your data removed. It is written plainly because you should be able to read it.

What we collect

  • Your email address, if you sign in. Authentication runs on Supabase, either through a sign-in link sent to your email or through Google sign-in. From Google sign-in we receive only your basic profile: email address, name, and profile photo.
  • Mission content you create: the goals you type, the plans generated for them, the resulting work log, and decisions you approve or reject. Goals are sent to OpenAI to generate the mission plan.
  • For guest sessions: a session cookie and a hashed network signal used only for abuse limits. Guests are never asked for an email or a name.
  • If you connect Gmail or Google Calendar, we store only non-secret connection metadata: which service is connected, its Composio account id, and its status.

What we never store

  • Google access or refresh tokens. Connected-service OAuth is handled by Composio, and tokens live only there. Our database, logs, and browser code never hold them.
  • Passwords. Cardea has none, for anyone.
  • Payment details. Cardea takes no payments.

How connected Google services are used

Cardea reads from a connected Gmail or Google Calendar account only when a mission you started and approved needs it, and shows you what it read as evidence on the canvas. We do not import, sync, or archive your mailbox, calendar, or contacts. Consequential actions such as sending, spending, or signing always stop for your explicit approval first.

Cardea's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train models.

Where data lives

Account and mission data is stored in Supabase (Postgres) with row-level security, so one account cannot read another's data. Mission planning calls the OpenAI API. Durable background work runs on Inngest. The site is hosted on Vercel.

Deletion and contact

To have your account or data removed, or to ask anything about this policy, open an issue on the public repository at github.com/SankrityaT/openai-mcp-hackathon or reply to your sign-in email. Disconnecting Gmail or Calendar from the connected services page revokes Cardea's access immediately.

Scope

Cardea is a hackathon submission, not a commercial service. Data may be reset during the judging period. If the project continues past the challenge, this policy will be updated before anything about the practices above changes.

HomePrivacyTerms