Nana / Privacy Policy
Privacy Policy
Last updated: 16 September 2026
This Privacy Policy explains how Nana ("the Application") accesses, uses, stores, and shares information obtained from Google APIs. Nana is a private, self-hosted software assistant operated by a single individual for their own personal use.
1. Scope and single-user nature
Nana is not a public product and is not offered to the general public. There is no sign-up, no user registration, and no multi-tenant access. The Application is operated by, and on behalf of, exactly one person: its owner and operator (referred to below as "the Operator", "I", or "my").
The only Google account the Application is authorized to access is the Operator's own Google account. The Application has no ability to access the Google accounts, data, or content of any other person. No third parties are served, and no third-party data is processed.
2. Google user data accessed
The Application requests the minimum scopes needed for its functions. Specifically:
https://www.googleapis.com/auth/calendar
Access. Read and write the Operator's own Google Calendar events
Purpose. To include the day's events in a private personal briefing, and to mirror the Operator's own dated to-do items onto a dedicated private calendar
https://www.googleapis.com/auth/googlehealth.sleep.readonly
Access. Read-only access to the Operator's own sleep records (Fitbit)
Purpose. To report the Operator's own sleep duration and stages in their private morning summary
https://www.googleapis.com/auth/gmail.readonly
Access. Read-only access to the Operator's own Gmail
Purpose. To count unread messages and read message headers (sender and subject) so the Operator can see at a glance what needs attention. Message bodies are not used for this purpose.
The Application does not request, and cannot access, any Google data beyond the scopes listed above. It does not access contacts, Drive files, photos, location history, or payment information.
3. How Google user data is used
Google user data is used solely to provide the Application's personal automation features to the Operator โ that is, to assemble and display the Operator's own information back to the Operator. Specifically, the data is used to:
- generate a private daily briefing (calendar events, sleep summary, unread mail count);
- create and maintain calendar entries for the Operator's own personal reminders;
- identify unread messages by sender and subject so the Operator knows what to review.
Google user data is not used for advertising, marketing, profiling, analytics, or to train or improve machine learning or artificial intelligence models. It is not used to determine creditworthiness or for lending purposes.
4. How Google user data is stored and protected
All Google user data is stored locally, on hardware owned and controlled by the Operator โ a private personal server on the Operator's own premises. The Application does not operate any cloud service, and does not store Google user data on any third-party platform.
- OAuth tokens and credentials are stored in local files on the Operator's server with restricted file permissions and are never committed to public source control.
- Data in transit between the Application and Google APIs is protected by TLS.
- No Google user data is transmitted to, stored on, or processed by any third-party service, including any commercial AI or model provider, for routine operation.
5. Sharing and disclosure
The Application does not share, sell, rent, trade, or otherwise disclose Google user data to any third party. There is no advertising, no data broker, and no analytics provider involved.
The only disclosure of Google user data that occurs is delivery of the Operator's own summary back to the Operator, through a private messaging channel configured by the Operator (for example a direct message channel in Discord or iMessage) that is accessible only to the Operator.
Google user data may be disclosed only if strictly required by law, and only to the extent legally required.
6. Data retention and deletion
Google user data is retained only as long as necessary for the Application's functions.
- Live data is fetched from the Google APIs on demand; the Application does not maintain a long-term copy of the Operator's calendar, sleep, or mail content.
- Cached or derived local data (for example, a briefing summary already delivered) is retained on the Operator's server for a short period for the Operator's own reference and can be deleted at any time.
- The Operator may revoke the Application's access to their Google account at any time at myaccount.google.com/permissions. Doing so immediately and permanently ends the Application's ability to access any Google user data. The Operator may also delete all locally stored tokens and derived data simply by removing those files from their own server.
7. Compliance with the Google API Services User Data Policy
Nana's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data is used only to provide or improve the Application's user-facing features that are prominent in the Application's interface.
- Google user data is not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with notice to users.
- Google user data is not used for serving advertisements.
- Google user data is not used for any purpose not disclosed in this policy.
8. Children's privacy
The Application is not directed to children and is not accessible to any person other than its single adult Operator. It does not knowingly collect information from children.
9. Changes to this policy
Because the Application serves a single user, this policy will be updated only if the Application's data practices change. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be reflected here before the corresponding change takes effect.
10. Contact
Questions about this policy or about the Application's handling of Google user data may be directed to: