← Back home

Privacy Policy

Last updated 25 August 2026

SafePersonalAI is software that runs on your own Mac. This policy describes what it does with the data it reads — email, calendar, iMessages, financial documents, and anything else you connect it to — because that is the honest answer, not because we collect any of it ourselves.

We do not operate a server that stores your data

SafePersonalAI is not a hosted service. There is no SafePersonalAI database holding your emails, messages, or financial records. Your data is read from your own Google account and your own Mac, and written back to files on your own machine (and, if you choose, your own Google Drive). We — the people who make SafePersonalAI — never receive a copy.

What it connects to, and why

With your explicit Google authorization, SafePersonalAI can read and act on:

  • Gmail — to read messages and draft replies. It never sends a reply without you approving it.
  • Google Calendar — to read and create events on your own calendar. It never adds attendees or invites anyone.
  • Google Drive — to file documents (statements, invoices) into folders you control.
  • iMessage (read locally on your Mac) — to understand messages you send yourself as reminders, or from senders you've explicitly trusted.

You grant each of these individually during setup, and you can revoke access at any time from your Google Account's security settings — SafePersonalAI has no separate mechanism that survives that revocation.

Bring-your-own AI key

Understanding your messages requires sending their content to an AI provider — Anthropic, OpenAI, Google, or a model you run locally via Ollama. You supply your own API key, and that content goes directly from your Mac to the provider you chose, under their own privacy policy and data-handling terms. We do not proxy, inspect, or retain a copy of anything sent that way.

Nothing acts without your approval

Every reply, calendar event, filed document, or payment record SafePersonalAI proposes is staged as a pending action. Nothing is sent, filed, or scheduled until you click Approve. This isn't a policy we ask you to trust blindly — it's a hard boundary in the code itself, and the source is open for anyone to check.

No advertising, no analytics resale, no data brokers

SafePersonalAI does not run ad tracking and does not sell, rent, or share your data with third parties for marketing purposes. If you purchase a paid module, payment is handled entirely by our Merchant of Record (e.g. Lemon Squeezy) — we receive confirmation that a purchase was made, not your card details.

Changes to this policy

If this policy changes in a way that matters — a new data connection, a new third party in the processing chain — we'll update this page and change the date above. Continuing to use SafePersonalAI after a change means you've seen the update.

Contact

Questions about this policy or your data can be sent to the support address listed on your purchase receipt, or on the SafePersonalAI GitHub repository.