Privacy Policy
Effective 28 August 2026 · Last updated 28 August 2026
Jenny is a private AI assistant operated by one individual for their own personal use. It is not a commercial product and it has no customers. This policy describes what data the software touches and what happens to it, and what happens to the details you leave if you join the waitlist on this website.
Built and run for one person. Jenny serves a single individual, its owner, who is also the operator of the software and the person who granted it access. The assistant has no other users and no accounts. The website also has a waitlist, which is described in section 5. If you have reached this page from a calendar invitation, see Information about other people below.
1. Google account data
Jenny connects to Google Calendar through Google's OAuth system. It requests calendar permissions only. It does not request access to Gmail, Google Drive, Contacts, or any other Google service.
| Permission | What it is used for |
|---|---|
calendar.readonly |
Reading the owner's calendar so the assistant can answer questions about their schedule, find free time, and detect conflicts before proposing a new commitment. |
calendar |
Creating and editing events on the assistant's own separate calendar — holds, reminders and invitations. This permission also allows reading a calendar's sharing list, which the software checks before creating an event so it never places something on a calendar visible to people the owner did not intend. |
The assistant does not write to anyone else's calendar. When the owner should see an event, the assistant invites them to it rather than writing into their calendar directly.
Limited use
Jenny's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Google user data is used only to provide the assistant features described on this page. It is not sold, not transferred to others except as described in section 3, not used for advertising, and not used to train generalized artificial-intelligence or machine-learning models.
2. Other information handled
Beyond calendar data, and only for the owner, the assistant handles:
- Messages exchanged with the assistant, and the assistant's replies
- Contact details the owner has asked it to remember
- Email that the owner's own account receives, where the owner has asked for it to be summarised
- Transcripts and outcomes of phone calls the owner asked it to make or receive
- Operational logs recording what the assistant did and when
None of this includes waitlist data. A waitlist address is never given to the assistant, never combined with Google account data, and is kept separately, as section 5 describes.
3. Who else sees this data
Jenny is not a business and shares nothing for commercial purposes. Data is never sold or rented, and there is no advertising of any kind. However, the assistant is built on services operated by other companies, and providing its features necessarily means sending some content to them:
- AI model providers. To generate a reply, the assistant sends the relevant conversation and context — which can include calendar details — to a large language model API. Those providers process the request under their own terms and privacy policies.
- Google. Calendar reads and writes go to Google's own API.
- Messaging and voice providers. Messages and phone calls are carried by the relevant messaging platform and telephony provider.
- Server hosting. The software runs on a rented private virtual server.
Data may also be disclosed where required by law.
This section describes the assistant. The website is a separate thing with its own providers, listed in section 5.
4. Information about other people
Because the assistant handles the owner's calendar, messages and calls, it inevitably holds information about people the owner interacts with — names, email addresses, phone numbers and the substance of arrangements made with them. This information is used only to carry out the owner's own requests. It is not used to build profiles for any other purpose, is never sold, and is not shared beyond the providers listed in section 3.
If you have received an invitation from this assistant and want the information about you removed, write to the address at the bottom of this page and it will be deleted.
This section is about the assistant. If you joined the waitlist on this website, that is a separate thing and section 5 covers it.
5. The waitlist
This website has a form for joining a waitlist. It is the only part of the site where you deliberately submit anything.
| What is collected | Why |
|---|---|
| Your email address | So that you can be contacted about Jenny if it opens more widely. |
| Your name, if you choose to give it | Optional. Only so a message would not have to open with nothing. |
| The date and time you submitted the form | A record of when you agreed, and to which version of this policy. The date of the version in force is at the top of this page. |
The form asks for nothing else. There is no account and no password, and this site runs no analytics, no advertising and no tracking scripts of any kind. Cloudflare, which carries all traffic to this site, keeps its own security and traffic records, described below.
Joining the waitlist is not a promise. It does not create an account and it does not guarantee access. Jenny may never open more widely. If that is what happens, the list is intended to be discarded rather than used for anything else.
Where it is stored
Waitlist entries are received and stored by Cloudflare, acting as a service provider for this website, and processed under its own terms and privacy policy. Cloudflare runs a global network: the storage can be asked to prefer a region, but its location is not guaranteed, so an entry may be processed outside your own country. Entries are not stored alongside the assistant's own data, and the assistant has no access to them.
Cookies and security checks
This site sets no cookies of its own and runs no scripts. Cloudflare's security checks, which are what protect the waitlist form from automated abuse, may set a cookie in your browser for that purpose. It is used to tell automated traffic from real visitors, and for nothing else.
Who else sees it
The owner, who is the person who would be writing to you, and Cloudflare, as the provider that receives and stores the entry. Nobody else. Waitlist addresses are not sold, not rented and not used for advertising. They are not sent to the AI model providers in section 3, are not used to train any artificial-intelligence or machine-learning model, and are not combined with Google account data.
Your consent, and how to withdraw it
The lawful basis for holding your address is your consent, given by submitting the form. You can withdraw it at any time and for any reason, without giving one, by writing to the address in section 10. Your entry is then deleted.
One practical note, so it is not a surprise: that contact address is an email inbox, so a removal request necessarily passes through the mail providers on both ends before it is read.
How long it is kept
Until you ask for it to be removed, or until the list is discarded, whichever comes first. The list is reviewed at least once a year and deleted if it is not going to be used. Cloudflare's own security and backup records follow its retention schedule, not this one.
6. Storage, retention and security
The assistant's data is stored on a private server controlled solely by the owner. Waitlist entries are the exception and live with Cloudflare, as section 5 explains. Credentials for Google are held in files readable only by the specific system account that needs them; the permission that allows writing to a calendar is deliberately kept isolated so that the assistant's general-purpose components cannot reach it.
Conversation and calendar data is retained on that server for as long as it remains useful to the owner, and is deleted at the owner's discretion. There is no fixed retention schedule for it. Waitlist addresses are the one thing here that belongs to other people, and they are handled differently: see section 5.
No system is perfectly secure. This one is a single-user personal deployment, and it is maintained on a best-effort basis.
7. Withdrawing access
Google access can be revoked at any time from the Google account permissions page. Doing so immediately stops all calendar reading and writing. Any data already retrieved and stored on the server is deleted on request.
8. Children
The assistant is used by one adult and is not directed at children.
9. Changes to this policy
If this policy changes, the updated version will be posted on this page with a new "last updated" date.
An address already on the waitlist will not be used for a materially different purpose than the one in section 5 without asking you first.
10. Contact
Questions, a request to leave the waitlist, or a request to delete information about you: jennybot.assistant@gmail.com