Privacy policy

Privacy policy

Aidenly is designed so your raw email stays in Google. We store the intelligence needed to make the assistant useful, not a copy of your inbox.

Contact support

Plain-English summary

Aidenly reads your Gmail and Google Calendar using read-only Google APIs — it can never send, delete, or change anything. It reads your mail to extract the facts worth remembering and stores that derived intelligence (summaries, memory entries, preferences, and message metadata) — not a copy of your inbox. We do not sell your data.

What we access

Aidenly accesses your Google account identity (for login and account setup), read-only access to your Gmail messages, and read-only access to your Google Calendar events. These are the only Google permissions Aidenly requests, and all data access is read-only — Aidenly never writes to your Gmail or Calendar.

What we store

Aidenly stores encrypted OAuth tokens, account metadata, derived intelligence such as AI summaries and memory entries, user-confirmed preferences, style guidance, and message metadata such as message IDs, labels, and timestamps. Aidenly does not store raw email bodies as persistent backend data — raw content is processed transiently to extract memory and is then discarded.

Where your data lives

Your raw Gmail content remains in your Google account. Aidenly reads it via read-only Google APIs only when needed, processes it transiently to extract memory, and does not persist the raw content. Aidenly stores derived data and account metadata in Supabase-backed application storage. Recent request results may be cached briefly for continuity.

Who can access it

Access is limited to you, Aidenly systems that need the data to provide the service, and service providers used to operate the product. Human access for support or operational investigation is limited to what is necessary for the request and should avoid raw content whenever possible.

How we share your data

We do not sell your data, and we do not share it for advertising. We do not transfer or disclose your Google user data to third parties except as described below.

To operate Aidenly, we share data with a small set of service providers (subprocessors) who process it on our behalf, under contract, and only to provide the service — never for their own purposes:

  • Google Cloud Platform (Cloud Run) — hosting and compute that runs the Aidenly backend.
  • Supabase — the database that stores your derived memory (summaries, preferences, metadata). It does not store raw email content.
  • AI model providers — Anthropic, OpenAI, and Google — email and calendar content is sent to these providers transiently to extract memory and generate responses. It is processed in memory for the request and is not retained by us as raw content.

We may also disclose data if required by law, to protect our rights or users' safety, or in connection with a merger or acquisition (in which case we will notify you and this policy will continue to govern your data).

Use of AI models and model training

Aidenly uses third-party AI models (from Anthropic, OpenAI, and Google) to read and reason over your content. Your Google user data is sent to these providers only through their business/API offerings, under terms that do not permit your data to be used to train or improve their models. Aidenly does not use your Google Workspace data (Gmail or Calendar content) to train, develop, or improve any generalized or non-personalized AI/ML models. Any learning Aidenly performs is specific to your account — to serve you — and is deleted when you delete your data.

Limited use of Google user data

Aidenly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide and improve Aidenly's user-facing features. We do not use it for serving advertisements, and we do not transfer or sell it to data brokers, information resellers, or for any other purpose.

Retention

Derived intelligence stored by Aidenly is retained until you delete it or request account deletion. Raw content fetched from Gmail is processed in memory for the duration of the request. Session cache data is short-lived, with a target lifetime of roughly 5 to 10 minutes.

Revocation and deletion

You can revoke Aidenly's Google access in your Google account permissions at any time. You can also email privacy@aidenly.ai to request deletion of stored derived data and account metadata. We respond to verified data access, deletion, or correction requests within 5 business days.

Email privacy

Google API scopes used by Aidenly

Aidenly requests only the Google scopes listed below, and every data-access scope is read-only. Aidenly reads your Gmail and Calendar to power the assistant; it never sends, deletes, drafts, or modifies your mail, and never creates, edits, or deletes calendar events. Aidenly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • openid

    Verify your Google identity during sign-in.

  • email

    Read the email address on your Google account to identify you.

  • profile

    Read your display name and basic profile info for account setup.

  • https://www.googleapis.com/auth/gmail.readonly

    Read-only access to your Gmail messages, threads, and labels. Aidenly reads your mail to extract the facts worth remembering and to answer your questions with context. It never sends, deletes, drafts, or modifies your mail.

  • https://www.googleapis.com/auth/calendar.events.readonly

    Read-only access to the events on your Google Calendar. Aidenly displays your upcoming events so the assistant understands your day. It never creates, edits, or deletes calendar events.

Contact

This policy applies to Aidenly, Inc., a Delaware corporation (incorporation in progress). Privacy and data requests should be sent to privacy@aidenly.ai. Legal notices related to this policy should be sent to legal@aidenly.ai.

Email privacy