Privacy notice
Updated 8 October 2026. Operator and contact: Stephen Liddle, stephenliddle1@gmail.com.
Purpose and information used
This application is for approved family members to manage shopping, tasks, a shared calendar, household budgets and personal health diaries. It stores information entered or imported by the family, including item names, task owners and due dates, transaction details and categories, blood pressure readings and comments, and login identifiers used to check access.
Google access
Connecting Google requests basic identity information and permission to view and edit calendar events. Identity information verifies the account allowed to connect the existing shared Family calendar. The application reads titles, dates, times, locations, notes and reminder settings from that calendar. It creates an event only after an approved family member reviews a preview and separately confirms it. New events contain no separately invited attendees. Google Calendar stores the events and delivers reminders according to each Google user’s settings.
The application stores encrypted Google refresh credentials on its server so it can renew access. Access tokens are used by the server and are not exposed to the browser or sent to the language model. Temporary event previews are stored in the application database. A preview stops being usable after 15 minutes; expiry does not itself delete its stored record.
The older family Site, where still connected, uses separately granted Google Sheets permission to maintain shopping and task lists. Those records are separate from the new Cloud database until migration is completed.
Who can access information
The dashboard checks approved family membership after sign-in. Shared shopping, tasks, budgets and calendar events are available to approved family members. Stephen’s current health diary is restricted to Stephen. Project administrators with backend access can administer application storage. Information placed in the shared Google Calendar is also subject to that calendar’s Google sharing settings.
Service providers and assistant requests
Google Cloud hosts the application and its database. Google supplies Calendar and authorization services. Auth0 provides login and identity verification. The web assistant sends the command you enter to the OpenAI API to interpret it. Commands can include personal information you choose to mention. The web assistant does not send the full calendar, health diary or transaction archive to the model for command interpretation. These providers process information under their own terms and privacy policies; not all processing is necessarily in Australia.
When using Garno through ChatGPT, the ChatGPT conversation and connected-tool results are also handled under your OpenAI account settings and applicable OpenAI policies. Browser dictation may use your browser provider’s online speech service. Review that provider’s settings before using voice input for sensitive information.
Uploaded receipts, invoices and statements
Approved family members can upload receipts, invoices and bank or credit card statements. Original files are kept in private Google Cloud storage and are downloadable only through an authenticated family session. Documents selected for AI reading are sent to the OpenAI API to extract draft line items and transactions, using requests with response storage disabled. A reviewed statement package contains the original file and previously reviewed rows; importing this package does not trigger a second AI reading request. Packages prepared in ChatGPT remain subject to your ChatGPT settings and applicable provider policies. Documents may contain information beyond the fields the application records; review and redact unwanted details before uploading. Draft extraction omits account and card numbers, but original files retain everything you upload. Stephen and Annmarie can both access uploaded files, drafts and imported records. Files are not automatically imported: a family member must review and approve each import. Receipt imports supply shopping options and history; statement imports supply budget transactions. Invoices are archived with vendor, line charges, tax and category, and do not separately increase budget spending. Failed or pending uploads are retained and may be retried; contact the operator to delete files or records.
Use and sharing limits
Information is used to provide the family functions described above, verify access and maintain the application. The operator does not sell family or Google user data, use it for advertising, or use it to determine creditworthiness or lending eligibility. The application’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Retention, corrections and deletion
Family records are retained until the operator removes them. Marking an item bought or a task complete keeps its history. Temporary previews currently have no automatic record-deletion schedule. Request correction or deletion from the operator using the contact above. Backend recovery history and provider logs may retain earlier copies for their configured retention periods.
Disconnecting Google
Stephen can use Disconnect Google in the dashboard to remove the application’s stored Calendar refresh credential. Existing Google events remain. To revoke the Google grant itself, remove the application in your Google Account connections. Revoking access does not automatically delete previously stored previews or family records; contact the operator for deletion.
Security and changes
The application uses HTTPS, encrypted login cookies, server-side membership checks and encrypted stored Google refresh credentials. These controls reduce risk and do not guarantee that every device, account or service is secure. Material changes to information use should be reflected in this notice before being introduced.