Privacy Policy
AI Secretary ("the app") is a private assistant built for and operated by a single person, the owner of balandin-e.pro. It is not offered to the public. This policy explains how the app handles data, including data received from Google APIs.
1. Data the app accesses
- Gmail (scope
https://www.googleapis.com/auth/gmail.readonly). Message metadata (sender, recipients, subject, date, labels, thread), message bodies and the text of PDF/DOCX attachments of the owner's own mailbox. - The app requests no other Google scopes. It cannot send, delete, move, label or otherwise modify email.
2. How the data is used
- To classify new messages (for example: task, event, bill, information, ignore) and judge urgency.
- To alert the owner about urgent messages and include other messages in a daily digest, delivered to the owner's private Telegram chat.
- To suggest tasks and events that the owner confirms or rejects manually.
- To let the owner search, read and summarize their own email through the assistant.
Email content is treated as data only. Instructions contained in an email are never executed, and nothing is created from an email without the owner's explicit confirmation.
3. Sharing and third-party processing
Google user data is not sold, rented or shared with anyone for advertising, marketing, profiling or any purpose other than providing the features above to the owner. To provide these features, limited parts of the data are processed by the following service providers:
- OpenRouter and the language-model provider it routes to: the subject and an excerpt of a message are sent for classification and summarization. Only providers that do not train on or retain request data are allowed.
- OpenAI (embeddings API): short text fragments are converted to vectors for search. Data sent through the API is not used for model training.
- Telegram: alerts and digests are delivered to the owner's private chat.
- Cloudflare: network access to the owner's web interface and storage of encrypted backups. Cloudflare cannot read backup contents.
No other third parties receive Google user data. The app uses no analytics, tracking, advertising or error-reporting services.
4. Storage and security
- Data is stored in a database on the owner's private server, reachable only inside a private network.
- OAuth refresh tokens are encrypted in the application; the key is stored separately from the database.
- Application logs contain metadata only, never the content of messages.
- Backups are encrypted before leaving the server.
5. Retention and deletion
- Synchronized email data is kept while the Gmail account is connected, so that the owner can search it.
- Disconnecting the account removes its stored OAuth token and synchronized messages; encrypted backups expire on a rolling schedule of no more than 12 months.
- Access can be revoked at any time at myaccount.google.com/permissions.
6. Google API Services User Data Policy
AI Secretary's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve or train generalized AI or machine-learning models, and it is not read by humans except by the owner, or when needed for security or to comply with law.
7. Changes
If this policy changes, the updated version will be published on this page with a new effective date.
8. Contact
Questions or requests: rockundrollor@gmail.com