Privacy Policy — External Brain

Last updated: 2026-09-28

External Brain is a private, single-user personal assistant used only by its owner. This policy describes how it handles data.

Data accessed

With the owner's explicit consent, the application accesses the owner's own Google account data through the Gmail API and the Google Tasks API: email messages and metadata, and task lists. No other Google data is accessed, and no data belonging to anyone other than the owner is accessed.

How data is used

Google data is used solely to answer the owner's own requests — for example, listing unread email, reading a message, sending a reply the owner dictated, or listing and updating tasks. Data is not sold, shared, transferred or disclosed to any third party, and is not used for advertising or to train machine-learning models.

Storage and security

OAuth credentials and tokens are stored encrypted in AWS Secrets Manager (eu-central-1). Content retrieved from Google is processed in the owner's private AWS account and, where cached, is stored in encrypted private storage. Nothing is made publicly accessible.

Retention

Email and task content is fetched on demand. Transcripts and assistant answers generated from voice requests are kept in the owner's private knowledge base for the owner's own reference. Google data can be deleted at any time by the owner.

Revoking access

The owner can revoke this application's access to his Google account at any time at myaccount.google.com/permissions.

Contact

mucha.vaclav@gmail.com