Information and control

Privacy policy

PersonalHub is operated for one owner. This notice explains the private application's data flow and the separate public information site.

Last updated

Information accessed

With the owner's Google consent, PersonalHub can read Gmail message content, headers and attachments; calendar events, participants, times and joining links; and the list of available calendars. These Google permissions are read-only: they do not allow the app to send mail or edit calendars.

The separate Drive connection uses account identification to verify the intended account and read-only Drive permission to retrieve individually selected documents and their metadata. The current document workflow uses an explicit selection of file IDs rather than a whole-Drive import.

Other approved sources can include email accounts, paired WhatsApp accounts, selected local documents and locally confirmed call recordings. The hub also stores owner-created tasks, preferences, source references, connection state and device push subscriptions.

How information is used

Eligible information supports the owner's agenda, meeting preparation, answers with source references, summaries and suggested follow-ups. Suggested tasks require the owner's acceptance. The application does not sell personal information, serve advertising or provide a public directory of communications.

New content is checked on the owner's PC before admission to the hub or use by a remote AI model. Banking and investment material is excluded by the configured policy. Operational finance can be eligible when it does not contain excluded material. Uncertain or failed checks hold the item outside the hub. Automated classification can make mistakes; privacy review and withdrawal controls are part of the operation.

Processing, storage and service providers

Local transcription and privacy classification run on the PC. Admitted records and OAuth credentials are encrypted in the private server's application store. Local credentials and recovery bundles use Windows user-bound protection; portable recovery exports are encrypted for the owner's recovery key.

For AI features, relevant admitted excerpts, the owner's question and supporting context can be sent through OmniRoute on the PC to OpenRouter and a selected model provider. A server-side OpenRouter route is available when configured. Model requests use an approved model list and request providers that decline data collection. Routing controls are not a guarantee of zero retention or of every provider's training practices; the selected services' applicable terms still govern their handling.

The deployment uses Hetzner server infrastructure and Cloudflare for hosting, network and access services. Browser push services receive subscription and delivery data; notification previews are designed to omit private meeting details. The application operator can administer the private deployment and its recovery material. These services may process technical metadata, including network addresses and request timing, to provide their functions.

Retention and recovery copies

  • Imported messages have a 90-day retention window measured from their original timestamp. A connector's practical history coverage can be shorter.
  • Admitted call transcript segments expire after 90 days. Optional eligible raw call audio stays on the PC for up to 7 days, with an aggregate 2 GiB storage cap that can remove it sooner.
  • Summaries, tasks, selected-document records and project context remain while useful to the owner, until removed or invalidated by their source or retention rules. Removing a source can remove dependent records sooner.
  • OAuth tokens and connection settings remain while the connection is maintained. Disconnecting in the hub removes its stored grant; removing access in the provider's account settings prevents further provider access.
  • Encrypted recovery copies have a separate, operator-managed lifecycle. A deletion in the live hub does not immediately rewrite an existing backup. Recovery procedures include sanitation and restore checks before use. Opaque identifiers of withdrawn items can be retained without an expiry to prevent their reimport; these markers do not contain the withdrawn message text.

Owner controls

The owner can pause a source to stop new synchronization, revoke a connection, remove retained records and their linked derivatives, and manage device notifications in the private hub. Pausing leaves existing eligible context available. Hub removal does not delete the original email, document or conversation at its provider.

Calls require local recording confirmation. The owner is responsible for informing participants and obtaining any required permission. Document selection and source approval can be changed separately. For connection or privacy questions, use the operator support contact shown on the Google consent screen; the private owner also controls the deployment directly.

This public website

These informational pages contain no account login, upload form, analytics script, advertising or application data. They set no application cookies and load no third-party page assets. The hosting and network services still receive ordinary request metadata. Changes to the application's data practices should be reflected in this notice and the private interface before new use begins.