1. About this policy
This policy explains what data the Aidan personal AI assistant processes, why it is needed, how it is protected, and what controls are available to users.
2. Data Aidan processes
- Account data: name, email address, user identifier, and preferences.
- Beta testing requests: name, contact email, occupation, selected platforms, and a description of intended use cases; optionally, task frequency, time spent, and the current workflow.
- User content: messages, tasks, notes, attachments, and memories intentionally provided to Aidan.
- Technical data: session, device, error, and feature-usage information required to operate and secure the service.
- Connected-service data, only after the user gives separate permission.
3. Google user data
When a user connects Google Workspace, Aidan requests their name, email address, and only the permissions they select: read-only Calendar events, files selected or created through Aidan in Drive/Docs/Sheets/Slides, Google Tasks, read-only Contacts, or Gmail sending after explicit approval. Aidan does not request access to read the Gmail inbox.
Aidan uses Workspace data only for user-requested features: showing meetings and tasks, working with selected files, finding a recipient, and performing explicitly approved actions.
4. Storage of Google user data
Aidan stores the connected account email, granted scopes, last sync time, and a refresh token. The refresh token is encrypted with AES-GCM and is not exposed to the client application.
Event titles, times, attendees, links, and other event details are fetched when needed and are not stored permanently in Aidan's database. The nearest event's title and time may be processed transiently to deliver a morning notification to the user's devices.
5. Sharing and Limited Use
Aidan does not sell Google user data or use it for advertising, profiling, lending decisions, surveillance, or data-broker services.
Data is processed only by infrastructure providers required to deliver a user-selected feature, such as secure cloud storage and notification delivery. Humans do not read Google user data unless required for security, legal compliance, or when the user explicitly asks for investigation of a specific problem.
6. Purposes of processing
Data is used to provide Aidan's features, synchronize devices, complete delegated work, protect accounts, diagnose failures, and comply with law. Google Workspace and each individual service are optional and connected only through an explicit user action.
7. Retention and deletion
Data is retained only as long as needed for the relevant feature or a legal obligation. Beta testing request data is used only to select participants, contact them about testing, and arrange early access. A request can be deleted by replying to an invitation or using the published support channel.
Users can disconnect Google Workspace in Aidan settings; Aidan will attempt to revoke the Google token and delete the stored connection record. Access can also be revoked from the Google Account connections page. Users control local data on their own devices.
8. Security
Aidan uses HTTPS, secret encryption, row-level access controls, authenticated sessions, and least-privilege OAuth scopes. No security method eliminates all risk, so the system is designed to handle token revocation and expiration safely.
9. User controls and requests
Users can export their data or permanently delete their account under Settings → Account, disconnect integrations, terminate sessions, and revoke third-party permissions. Step-by-step instructions are also available on the account deletion page.
10. Policy changes
If data practices change materially, Aidan will update this page and, when required, request new consent before using data for a new purpose.