All Purpose Login — Privacy Policy
Last Updated: April 23, 2026
This privacy policy covers the All Purpose Login command-line tool ("the CLI") distributed by Deemwar. It is specific to this product. For Deemwar's general website and consulting services, see the general privacy policy.
1. Summary
All Purpose Login is a local-first tool. It runs on your computer, authenticates you with Google and Microsoft using their official OAuth 2.0 flows, and stores the resulting tokens on your device. Deemwar does not operate a server for this product, does not receive your tokens, and does not receive any of the user data the tokens grant access to.
2. Data the CLI Accesses
When you run the CLI and approve a scope in your browser, it obtains an access token that lets it call the corresponding Google or Microsoft API on your behalf. Depending on the scopes you approve, this may include:
- Your basic profile (name, email address)
- Your Gmail messages and metadata (if you approve Gmail scopes)
- Your Google Calendar events (if you approve Calendar scopes)
- Your Outlook mail (if you approve Microsoft Mail scopes)
- Your Microsoft Calendar events (if you approve Calendar scopes)
- Your Microsoft Teams chats and messages (if you approve Teams scopes)
The CLI only requests scopes you explicitly pass to it. You approve each scope in the provider's native consent screen before the CLI can access anything.
3. Where Data Is Stored
Tokens (access tokens and refresh tokens) are stored only on your device, in one of the following locations:
- Your operating system keychain (macOS Keychain, Windows Credential Manager, or Linux Secret Service), where available
- An encrypted file at
~/.config/all-purpose-login/datawhen a system keychain is not available
User data retrieved from the APIs (email contents, calendar events, chat messages, etc.) is returned directly to your terminal or the script you pipe it into. The CLI does not persist that data anywhere unless you write it to disk yourself.
4. Limited Use — Google API Services
All Purpose Login's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Data accessed via Google APIs is used only to provide the CLI's user-facing features on your machine.
- Data is not transferred to any server operated by Deemwar or any third party, except as required by the Google APIs themselves.
- Data is not used for advertising purposes.
- No human at Deemwar reads your data. The CLI runs entirely on your device.
- Data is not sold to anyone.
5. Microsoft Identity Platform
For Microsoft accounts, All Purpose Login uses the Microsoft identity platform's OAuth 2.0 authorization code flow with PKCE. Tokens and user data are subject to Microsoft's own privacy policies and your organization's tenant configuration. Deemwar does not receive or process tokens or user data obtained through Microsoft APIs.
6. Third Parties
All Purpose Login communicates only with:
- Google's official OAuth and API endpoints (
accounts.google.com,googleapis.com) - Microsoft's official identity and Graph endpoints (
login.microsoftonline.com,graph.microsoft.com)
It does not send analytics, telemetry, crash reports, or any other data to Deemwar or third parties.
7. Revoking Access
You can revoke All Purpose Login's access at any time:
- Google: visit myaccount.google.com/permissions and remove "All Purpose Login"
- Microsoft: visit myaccount.microsoft.com/Consent and remove the app
- Local cleanup: run
apl logout <provider> --as <label>to wipe the stored token on your machine
8. Children
All Purpose Login is a developer tool and is not directed at children under 13.
9. Changes to This Policy
We may update this policy as the product evolves. Material changes will be reflected in the "Last Updated" date above.
10. Contact
Questions about this policy or the CLI? Reach us at io@deemwar.com.