LANAI

Privacy policy

How LANAI accesses, uses, stores and protects its owner's data, including data from Google.

Last updated 27 September 2026.

1. Who uses LANAI

LANAI is a private assistant with a single user, its owner. Every request to LANAI's servers must carry a Google sign-in token that belongs to the owner's Google account; requests from any other account are refused. LANAI is not offered to the public.

2. Google data LANAI accesses

LANAI requests the following Google permissions (OAuth scopes). Each is used only for the purpose shown.

PermissionUsed byPurpose
gmail.readonlyPhone app; LANAI BrainRead and search the owner's email when the owner asks (for example "check my latest email").
gmail.composeLANAI BrainCreate email drafts in the owner's mailbox. Saving a draft to Gmail requires the owner's approval.
gmail.sendPhone appSend an email. The full message is shown to the owner, and it is sent only after the owner confirms it.
calendar.readonlyPhone app; LANAI BrainRead the owner's calendar to answer questions and find free time.
calendar.eventsPhone app; LANAI BrainCreate or change an event after the owner confirms it on the phone.
contacts.readonlyPhone app (optional)Look up a person's email address or phone number when the owner asks.
openid, emailPhone app; LANAI BrainConfirm that the signed-in account is the owner's account.

The owner can grant or withhold each permission on Google's consent screen, and can disconnect Google in the app at any time.

3. How the data is used

4. AI processing

LANAI's voice and chat features use the OpenAI API. When the owner speaks or types to LANAI, the audio and text of the request are sent to OpenAI to produce the answer. When a request needs the owner's email, calendar or contacts, the relevant parts of the results (for example a list of recent email subjects and senders, or the text of an email the owner asked to read) are sent to OpenAI to produce the answer. Text requests are made with response storage turned off (store: false). OpenAI's own API data-usage and retention policies apply to this processing. Google data is not sent to OpenAI unless the owner's request needs it.

5. Where data is stored and for how long

On the owner's phone

Conversations, notes, memories and files the owner adds are kept in the app's private storage on the device. Google sign-in on the phone is handled by Google Play services; the app does not store Google passwords or refresh tokens.

LANAI voice service (Google Cloud, region me-central1)

Keeps the owner's assistant profile (names and language), the most recent 40 conversation turns and up to 128 saved memories in Cloud Firestore, so conversations can continue between sessions.

LANAI Brain (Google Cloud, region me-central1)

When the owner links it, LANAI Brain receives a Google refresh token for the permissions listed as "LANAI Brain" above. The token is encrypted with Google Cloud Key Management Service before storage, bound to the owner's account, and stored in a dedicated Firestore database. Only the Brain's own service identity can decrypt it. It is never sent back to the phone, never given to an AI model and never written to logs. Unlinking deletes the encrypted copy.

At the time of this update, the Brain uses this access only to check that the link is still valid. It does not yet read email or calendar content. This policy will be updated before that changes.

The Brain also stores records of actions LANAI has prepared for the owner and the owner's decisions on them (identifiers, status and times).

Logs

Server logs are technical and limited to codes, counts and timings. They do not contain email or calendar content, message text, or tokens.

6. Security

7. Sharing

LANAI does not share, sell or transfer the owner's data to anyone, except to the service providers that run it on the owner's behalf: Google (Google Cloud and Google APIs) and OpenAI (AI processing, as described above), and only as needed to provide the features the owner uses.

8. The owner's controls

9. Google API Services User Data Policy

LANAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10. Changes and contact

This policy is updated whenever LANAI's handling of data changes, with a new date at the top. Questions: lanai@etmamai.com.