Privacy policy
How LANAI accesses, uses, stores and protects its owner's data, including data from Google.
Last updated 27 September 2026.
1. Who uses LANAI
LANAI is a private assistant with a single user, its owner. Every request to LANAI's servers must carry a Google sign-in token that belongs to the owner's Google account; requests from any other account are refused. LANAI is not offered to the public.
2. Google data LANAI accesses
LANAI requests the following Google permissions (OAuth scopes). Each is used only for the purpose shown.
| Permission | Used by | Purpose |
|---|---|---|
gmail.readonly | Phone app; LANAI Brain | Read and search the owner's email when the owner asks (for example "check my latest email"). |
gmail.compose | LANAI Brain | Create email drafts in the owner's mailbox. Saving a draft to Gmail requires the owner's approval. |
gmail.send | Phone app | Send an email. The full message is shown to the owner, and it is sent only after the owner confirms it. |
calendar.readonly | Phone app; LANAI Brain | Read the owner's calendar to answer questions and find free time. |
calendar.events | Phone app; LANAI Brain | Create or change an event after the owner confirms it on the phone. |
contacts.readonly | Phone app (optional) | Look up a person's email address or phone number when the owner asks. |
openid, email | Phone app; LANAI Brain | Confirm that the signed-in account is the owner's account. |
The owner can grant or withhold each permission on Google's consent screen, and can disconnect Google in the app at any time.
3. How the data is used
- Only to provide features the owner uses: answering the owner's questions, reading and searching mail and calendar on request, preparing drafts and bookings, and looking up contacts.
- Actions that affect other people or external systems (sending an email, saving a Gmail draft from the server, creating, changing or cancelling a calendar event) require the owner's explicit confirmation of the exact content every time. Deleting or forwarding email and making payments are not supported.
- Google data is not sold, not used for advertising, not used to build profiles for anyone else, and not used to train AI models.
- No person other than the owner reads the owner's data. The owner, as operator of the system, can access its technical records.
4. AI processing
LANAI's voice and chat features use the OpenAI API. When the owner speaks or types to LANAI, the audio and text of the request are sent to OpenAI to produce the answer. When a request needs the owner's email, calendar or contacts, the relevant parts of the results (for example a list of recent email subjects and senders, or the text of an email the owner asked to read) are sent to OpenAI to produce the answer. Text requests are made with response storage turned off (store: false). OpenAI's own API data-usage and retention policies apply to this processing. Google data is not sent to OpenAI unless the owner's request needs it.
5. Where data is stored and for how long
On the owner's phone
Conversations, notes, memories and files the owner adds are kept in the app's private storage on the device. Google sign-in on the phone is handled by Google Play services; the app does not store Google passwords or refresh tokens.
LANAI voice service (Google Cloud, region me-central1)
Keeps the owner's assistant profile (names and language), the most recent 40 conversation turns and up to 128 saved memories in Cloud Firestore, so conversations can continue between sessions.
LANAI Brain (Google Cloud, region me-central1)
When the owner links it, LANAI Brain receives a Google refresh token for the permissions listed as "LANAI Brain" above. The token is encrypted with Google Cloud Key Management Service before storage, bound to the owner's account, and stored in a dedicated Firestore database. Only the Brain's own service identity can decrypt it. It is never sent back to the phone, never given to an AI model and never written to logs. Unlinking deletes the encrypted copy.
At the time of this update, the Brain uses this access only to check that the link is still valid. It does not yet read email or calendar content. This policy will be updated before that changes.
The Brain also stores records of actions LANAI has prepared for the owner and the owner's decisions on them (identifiers, status and times).
Logs
Server logs are technical and limited to codes, counts and timings. They do not contain email or calendar content, message text, or tokens.
6. Security
- All traffic between the app, LANAI's services and Google uses TLS.
- Each service runs under its own Google Cloud service identity with only the permissions it needs.
- Google refresh tokens held by LANAI Brain are encrypted with Cloud KMS; the client secret is kept in Google Secret Manager.
- Content from emails, calendar entries, files and web pages is treated as data only; it can never authorize an action.
7. Sharing
LANAI does not share, sell or transfer the owner's data to anyone, except to the service providers that run it on the owner's behalf: Google (Google Cloud and Google APIs) and OpenAI (AI processing, as described above), and only as needed to provide the features the owner uses.
8. The owner's controls
- Disconnect Google, or unlink LANAI Brain, from the app's Settings → Connected services.
- Withdraw LANAI's access at any time at myaccount.google.com/permissions.
- Delete data kept on the phone by clearing the app's data or uninstalling it; data in LANAI's cloud services can be deleted on request.
9. Google API Services User Data Policy
LANAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
10. Changes and contact
This policy is updated whenever LANAI's handling of data changes, with a new date at the top. Questions: lanai@etmamai.com.