PRIVACY & DATA USE
Privacy Policy
Last updated: October 10, 2026
Personal AI Agent is a self-hosted personal assistant project operated for the developer's own use. The public website describes the project; it does not provide public account registration. The Google integrations are operated privately for the account owner's use, and are not offered as a public service.
1. Google data and permissions
With explicit account authorization, this service reads Gmail messages and metadata to categorize incoming mail and propose replies, and reads Google Calendar lists and events to summarize schedules. The authorization requests Gmail read-only, Gmail compose, Calendar events, and Calendar list read-only scopes. Although Gmail compose technically permits sending, the current integration does not automatically send email, create drafts in Gmail, or modify calendar events. Those actions would require separate implementation and safeguards.
2. Purpose of processing
The inbox is checked every 30 minutes. Incoming messages may be analyzed by a self-hosted language model to estimate importance, whether a reply is needed, and whether calendar or task follow-up is advisable. Important or actionable results are sent to the account owner's private Discord notification channel. On-demand requests can retrieve email metadata and calendar events. Google data is not used for advertising or sale.
3. Storage and security
The service runs on infrastructure controlled by the developer. Google OAuth credentials and refresh tokens are stored as restricted Kubernetes secrets, not in the website repository. Email text is analyzed temporarily by the local model and is not intentionally persisted in its entirety as part of mail triage. Stored execution records may contain sender addresses, subjects, short email snippets, classifications, summaries, proposed replies, event details, and task suggestions. Processed message identifiers are stored as SHA-256 fingerprints and normally retained for 7 days. Execution records currently have no automatic deletion deadline; the operator can remove them from local storage.
4. Disclosure and services
Authorized API requests retrieve the account owner's data from Google. Email content for automated classification is processed by a locally hosted AI model rather than sent to a third-party AI model provider. When messages are deemed important or actionable, sender, subject, summary and any proposed reply or follow-up may be transmitted to Discord through a configured webhook. Discord is a third-party messaging service subject to its own privacy terms. The project does not sell data or share it with advertising networks. Any future external AI provider integration will be reviewed and documented before use.
5. User control and deletion
The account owner can revoke Google access from Google Account settings. Revoking access prevents further authorized API access but does not automatically delete any previously stored local records. Local credentials and retained records can be removed by the operator from the self-hosted environment. No automated end-user deletion portal is currently provided.
6. Google API Services User Data Policy
The integration is designed to handle Google user data in accordance with the Google API Services User Data Policy, including its Limited Use requirements where applicable. Storage permissions and notification-channel access must be reviewed periodically.
7. Changes
This policy will be updated if the project's integrations, data flows, or storage practices materially change.
8. Contact
For questions about this personal project or this policy, contact the developer via the project's GitHub issue tracker. Do not include private Google account or message data in public issues.