top of page

Privacy Policy — My-AI Assistant

Effective 13 August 2026 · Last updated 13 August 2026

My-AI Assistant ("the application") is private software developed and operated by Karl Botha, trading as IQ Draughting, South Africa. It is a personal productivity and document-analysis assistant that runs entirely on the owner's own computer.

The short version. The application runs locally on a single personal computer. It reads your Google data only to show it to you, stores everything on that computer, and transmits nothing to the developer or to any third party. There is no server, no analytics, no advertising, and nothing is ever sold.

1. Who this policy covers

The application is not offered to the public, has no user accounts, and is not distributed as a service. The only user is the owner of the Google Account that authorises it. If you are reading this because you are being asked to grant access, you are that owner.

2. Google user data the application accesses

Access is granted by you through Google's standard OAuth consent screen, and each scope below is requested because a specific feature needs it. You may decline, and you may withdraw consent at any time (section 6).

gmail.readonly — List, search and read your messages so they can be summarised, searched and answered about.

gmail.send — Send an email you have composed and explicitly confirmed. Nothing is ever sent without a separate confirming action.

gmail.modify — Apply labels, mark as read, archive or trash, only when you ask for it.

drive.file — Create and update only the files the application itself creates. It cannot open your other Drive files with this scope.

drive.metadata.readonly — Search file names so you can find a document by asking for it.

calendar and calendar.events — Read your schedule, and create or update events at your request.

spreadsheets — Read and write spreadsheets you direct it to.

documents — Read and write documents you direct it to.

contacts — Look up a contact's address when you ask to email someone by name.

3. How the data is used

Google user data is used solely to provide the features you invoke: searching, summarising, drafting, scheduling and answering questions about your own material. It is not used to train, fine-tune or improve any machine learning model. The application performs no model training of any kind.

4. Where the data is stored

Authorisation credentials (the OAuth refresh token) are stored in the Windows Credential Manager, the operating system's protected credential store. They are never written to a file, a configuration entry, or source control.

Retrieved content (for example a local cache of mail headers, or text extracted from a document you supplied) is stored in local SQLite database files on the same computer.

Nothing is uploaded. There is no remote database, no cloud storage and no backend operated by the developer.

5. Sharing and disclosure

Google user data is never sold, rented, traded, or transferred to any third party. It is not shared with advertisers, data brokers, analytics providers, or any other person. The developer has no technical means of accessing it, because it never leaves the owner's machine.

Language processing is performed by a large language model running locally on the same computer. Your Google data is not sent to any external AI provider.

6. Retention, revocation and deletion

Revoke access at any time at https://myaccount.google.com/permissions. Revocation takes effect immediately and the application can no longer reach your Google data.

Delete the stored credential by removing the "myai-assistant" entry from Windows Credential Manager.

Delete cached content by deleting the application's local database files, or by deleting the application directory entirely. No copy exists anywhere else.

7. Security

The application's web interface refuses to start on any address other than the local loopback interface (127.0.0.1). This is enforced in code, not by configuration, so it is not reachable from the network or the internet. Requests additionally require a locally generated bearer token. Outbound requests are screened to prevent the application from being directed at private network addresses.

No system is perfectly secure, and the data's protection also depends on the physical and account security of the computer it runs on.

8. Google API Services User Data Policy

The application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Specifically, and in the language of that policy: data obtained through Google Workspace APIs is not used to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models; it is used only to provide or improve the user-facing features that are prominent in the application's interface; it is not transferred or sold for advertising, marketing, credit assessment or any similar purpose; and no human reads the data except the owner themselves.

9. Children

The application is not directed at children and is not made available to anyone other than its owner.

10. Changes to this policy

If this policy changes, the effective date above will be updated and the revised policy published at this same address before the change takes effect.

11. Contact

Questions about this policy or about data handling: karlbothasa@gmail.com — Karl Botha, IQ Draughting, South Africa.

My-AI Assistant is private, single-user software. This policy describes the application's actual behaviour as implemented. It is not legal advice.
 

GET IN 
TOUCH
  • Link-Linkedin

Address: 7 Santa Anna, 229 Ouklipmuur Ave, Equestria, Pretoria, 0184

Tel: +27 78 762 7349

Email: draughtingoffice@iqdraughting.com

© 2020 by Karl Botha (IQDraughting (PTY) Ltd)

bottom of page