Milo by 10ROW
Privacy Policy
This policy explains how Milo handles account credentials, Gmail data, local project context, and AI processing.
Effective and last updated: 28 August 2026
1. Who provides Milo
Milo is a software product operated by 10ROW. Privacy and support questions can be sent to hello@10row.com.
2. Information Milo handles
- Project missions, documents, instructions, checkpoints, outputs, and evidence supplied by the user or generated during visible project work.
- Basic Google identity information needed to verify the exact connected account.
- When the user grants permission, read-only Gmail message metadata and content relevant to an active project observation.
- Local operational records needed to resume work, prevent duplicate actions, and show what Milo actually did.
3. How Google data is used
Milo uses Google account data only to provide user-facing project functionality requested by the user: verifying the chosen mailbox, searching for project-relevant messages, observing expected replies or changes, and using relevant results to continue the visible project task.
Milo’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
4. AI processing
Relevant Gmail results and project context may be supplied to the AI worker configured for the project, including OpenAI Codex, so it can perform the user-visible task. Milo does not use Gmail data to train a general-purpose AI model. Milo does not sell Google user data or use it for advertising, credit decisions, or audience profiling.
5. Credentials and security
Each Google account has a separate authorization bound to its exact verified email identity. OAuth credentials and refresh tokens are encrypted using the operating system’s secure storage and are excluded from ordinary project state, AI prompts, browser UI, logs, and source control. Milo requests Gmail read-only permission and cannot send, edit, or delete email through this capability.
6. Storage and retention
OAuth grants are stored locally on the user’s Milo computer until the account is disconnected or local application data is removed. Relevant excerpts and derived work product may remain in the user’s local project records until the user deletes that project data. 10ROW does not maintain an advertising or data-broker database of Gmail information.
7. User control and deletion
Users can disconnect a mailbox from Milo at any time. Milo deletes its encrypted local grant and asks Google to revoke the authorization. Users can also revoke Milo from their Google Account security settings. For assistance deleting Milo project records, contact hello@10row.com.
8. Sharing
Milo shares data only with service providers needed to deliver the user-requested functionality, such as the configured AI processing provider and Google’s OAuth/Gmail services. Data may also be disclosed when required by law or to protect users and the service. Milo does not permit those providers to use Gmail data for advertising.
9. Changes
Material changes will be posted on this page with a revised effective date. If a change materially expands Google data use, Milo will require an updated disclosure or consent before that use.