Thomas Personal Agent

Privacy policy

This policy explains how the privately operated assistant handles Google user data.

Information accessed and its purpose

With the account holder's authorization, the Gmail integration reads message headers, subjects, bodies, snippets, labels, and attachment metadata. These are used to find mail, summarize messages, and help with personal organization. Calendar access reads details of events in explicitly shared calendars to support schedules, planning, and reminders.

Google permissions are read-only. Access credentials allow continued authorized access and are kept on the private server, separately from this public website.

Processing and service providers

The application is hosted on a private server. Relevant message or calendar content may be sent to OpenAI for inference when needed to answer a request. Responses and summaries sent through Telegram are processed by Telegram. These providers may process data outside the user's country under their applicable service terms and privacy policies.

The operator does not sell Google user data or use it for advertising. Transfers to service providers are for delivering the assistant's requested functionality. The application does not use Google user data to train generalized artificial-intelligence or machine-learning models.

Thomas Personal Agent's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Storage, access, and retention

Conversation history, working notes, operational logs, and any deliberately saved summaries may be retained on the private server. Credentials are stored in access-restricted files. Retained application data is not automatically deleted on a fixed schedule; the operator manages its retention and deletion. Any backup copies must also be considered separately.

The operator administers the server. Profiles are organized separately, but they share infrastructure and should not be understood as complete security isolation.

Control and deletion

You can revoke Gmail access through your Google Account connections. Calendar access can be removed in each calendar's sharing settings. Revoking access stops future access but does not erase data already retained in conversations, notes, or provider systems. Contact the operator to request deletion of locally retained data; provider-held data is handled under each provider's controls and policies.

This information website

Cloudflare hosts these static pages and processes ordinary request information, such as IP addresses, to deliver and protect the website. The site does not access Gmail or calendar data, and contains no application analytics, advertising, forms, or tracking scripts.

Contact and changes

For questions or deletion requests, use the support email shown on the Google consent screen or your existing direct contact with the operator. Changes to this policy will be published here.