MYREE
·

Privacy Policy

Last updated: 12 September 2026

MYREE stores your memory and uses the OpenAI API to think over it. Here is exactly what we collect, where it lives, and how you stay in control of it.

01 · Who we are

MYREE is a personal "second brain" operated by Aclas. The data controller for this instance can be reached at hello@aclas.io. This policy explains what data we collect, how we use it, and the rights you have.

02 · Data we collect

Account data: your email address, a hashed (one-way encrypted) version of your password, your display name and, if you upload one, your profile photo. If you sign in with Google, we receive your email address and an account identifier to recognise you — we never receive your Google password.

Content you create: notes, decisions, memory atoms, conversations with the assistant, content pieces and drafts, diary entries, your Identity Card and your settings. This is the data you deliberately put into the app.

In your browser we store only a session cookie (to keep you signed in) and your theme and language preferences. The session cookie is HttpOnly, meaning it cannot be read by JavaScript running on the page. We use no advertising cookies and no third-party tracking or analytics.

03 · Where your data lives

Your notes, atoms, conversations and settings live in MYREE's own PostgreSQL database, on the server this instance runs on, scoped to your account. They are never shared with other users.

04 · AI processing

Chat replies, content generation and atom extraction are produced by OpenAI's API (gpt-4o-mini and text-embedding-3-small). For each request, only the text it needs — your message and the relevant memory — is sent to OpenAI to produce the response.

Per OpenAI's API data policy, content sent through the API is not used to train their models. Your full database is never uploaded anywhere: only what a given request needs ever leaves the server.

05 · Third parties

We share data only with the providers needed to run the service: OpenAI (AI processing) and our email provider, used solely for transactional messages such as password resets and account verification. We do not sell your data and we do not use it for advertising.

If you sign in with Google, authentication is handled by Google under their privacy policy. We use Google sign-in only to verify your identity; we do not read or store any other data from your Google account unless you explicitly connect a service such as Google Calendar (see the dedicated section).

06 · How MYREE accesses, uses, stores and shares Google user data

This section is our complete disclosure of how we handle Google user data. MYREE requests a single sensitive Google scope, “https://www.googleapis.com/auth/calendar.events”, and only if you choose to connect Google Calendar from Settings → Connectors. If you never connect it, MYREE accesses no Google user data beyond the email address and account identifier used to sign you in.

DATA WE ACCESS. With that scope, our application accesses the events on your primary Google Calendar: the title, the start and end date and time, and the link to the event. We do not access Gmail, Drive, Contacts, Photos or any other Google service, and we request no other scopes.

HOW WE USE THIS DATA. We use your calendar data solely to provide and improve the app features you asked for: showing your commitments alongside your memories in the Calendar tab, and creating, changing or deleting the events you explicitly ask us to. Every write is shown to you as a proposal first and happens only after you confirm it. We do not use Google user data for advertising, profiling, market research, resale, or to train artificial intelligence models, whether ours or anyone else's. In particular, we do not use data obtained through Google Workspace APIs (including Google Calendar) to develop, improve, or train non-personalized or generalized artificial intelligence (AI) and/or machine learning (ML) models.

HOW WE STORE IT. Calendar events are NOT stored. They are fetched from Google live, only for the date range you are looking at, shown on screen and then discarded: they are never written to our database, never become memories or atoms, and are never indexed for search. The only information we retain to keep the connection working is the email address of the connected Google account and an OAuth refresh token, which is encrypted at rest.

HOW WE SHARE IT. We do not share Google user data with anyone. In particular, your calendar data is never sent to OpenAI or to any other provider or third party, is never sold, and is not transferred except where required by law or where you explicitly ask us to.

RETENTION AND DELETION. You may revoke this access at any time, without losing any other feature of the app. Disconnecting the calendar from Settings → Connectors immediately deletes the refresh token from our database and revokes the access at Google; you can also revoke it from Google's “Third-party apps with account access” page (myaccount.google.com/permissions). Because we store no events, no calendar data remains to be deleted.

LIMITED USE. MYREE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

07 · Data protection and security

Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information, including sensitive data such as Google access tokens and account credentials.

In concrete terms: all traffic between your browser and MYREE is encrypted in transit over HTTPS/TLS; the Google refresh token is encrypted at rest in the database and is never exposed to the browser; passwords are stored only as one-way hashes (bcrypt) and are never readable, including by us; the session lives in an HttpOnly cookie, so it cannot be reached by JavaScript on the page; requests that change data require an anti-CSRF header; and a Content Security Policy with a per-request nonce blocks unauthorised scripts.

Every row of data is scoped to its own account, and isolation between users is enforced in the database query itself, not only in the interface: another user's data is not reachable even if its identifier is known. Access is limited to the personnel who need it to operate the service. You can end a session on any device, or on all of them, from Settings.

No system is perfectly secure. If we became aware of a breach affecting your data, we would notify you without undue delay.

08 · Retention & deletion

We retain your personal information for the length of time needed to fulfil the purposes outlined in this privacy policy — that is, for as long as your account is active — unless a longer retention period is required or permitted by law. When the retention period expires for a given type of data, we delete it.

You can export everything as a JSON archive at any time from “Export data”, or permanently wipe your data from “Logout & data”. Deletion permanently removes your account and its linked content from the database. You may also request that your data be deleted by writing to hello@aclas.io.

09 · Your rights

You have the right to access your data, export it and delete it — directly in the app or by writing to hello@aclas.io. We respond to reasonable requests within a reasonable time.

10 · Changes to this policy

If we update this policy we will change the “Last updated” date above. If we change how MYREE uses Google user data, we will notify you before the change takes effect, by email to the address on your account and with a notice in the app. Other material changes will be announced in the app.

11 · Contact

For any question about privacy or data, write to hello@aclas.io.

← Back to MYREE/privacy/terms