Privacy Policy
Auri — AI Executive Assistant
At a Glance
Local-first architecture
Much of your workspace data stays on your device. Selected data is stored or processed in the cloud when you use sync, collaboration, SMS, hosted integrations, or cloud assistant features.
OpenAI with controls
When external AI is enabled, Auri may send relevant context to OpenAI for summaries, drafts, briefings, reasoning, and transcription.
No data selling
We never sell, rent, or trade your personal information.
You're in control
You can disable external AI, restrict sensitive context, disconnect integrations, manage meeting retention, leave shared work, delete your account, or turn off optional SMS.
1.Introduction
This Privacy Policy (“Policy”) describes how Auri (“Company,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects your personal information when you use the Auri desktop application and related services (collectively, the “Service”). This Policy applies to all users of the Service, including users and the executives they support.
We are committed to protecting your privacy and handling your data transparently. Please read this Policy carefully. By using the Service, you consent to the data practices described herein.
2.Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Display name
- Firebase user identifier (UID)
- Authentication provider (Google, Microsoft, or email/password)
2.2 Executive Profile Information
When you create executive profiles within the Service, the following data is collected and stored:
- Full name, email address, job title, and company name
- Phone number and timezone
- Workday start and end times
- Associated Google account email address(es)
- Naming prefix preferences
2.3 Google Workspace Data
When you authorize Google Workspace integration, we access the following data through Google APIs using OAuth 2.0:
Gmail
- Email message metadata (message ID, thread ID, sender, recipients, subject, date)
- Email body content and snippets
- Email labels and read/unread status
- Attachment filenames and metadata
- Email signatures and "send as" configurations
Google Calendar
- Event titles, descriptions, locations, and attendees
- Event start and end times, including all-day events
- Recurrence patterns and organizer information
- Free/busy status and calendar access control lists
Google Drive
- File names, types, and metadata
- File sharing permissions and recent file activity
- File content (for Google Docs and Sheets when accessed)
Google Docs & Sheets
- Document content (when read or appended)
- Spreadsheet values (when read or written)
Google People API
- Contact names, email addresses, and phone numbers
- Profile information
Google OAuth Scopes Requested
gmail.readonly— Read email messages and metadatagmail.modify— Send emails, modify labels, trash emailscalendar— Full calendar accesscalendar.events— Create and modify calendar eventsdrive.readonly— Read Drive file metadata and contentdrive.activity.readonly— View Drive file activitydocuments— Read and write Google Docsspreadsheets— Read and write Google Sheetsuserinfo.email— Read your email addressuserinfo.profile— Read your basic profile information2.4 Slack Data
When you authorize Slack integration, we access:
- Authenticated user ID and display name
- Team/workspace name
- User presence status (online, away, do not disturb)
- Conversation and channel names
- Message history from conversations you have access to
- Replies, reactions, read state, and search results
- User display names (cached locally, up to 200 entries)
Auri may also post messages, add or remove reactions, mark conversations read, or open a direct message when you request or approve those actions.
2.5 Notion Data
When you authorize Notion, Auri may access workspace and user information; search and read pages, databases, blocks, properties, and comments; and create, update, append to, comment on, or archive content when you request those actions.
2.6 Asana Data
When you authorize Asana, Auri may access your Asana profile and authorized workspaces, projects, sections, tasks, assignees, tags, dates, completion state, notes, and task relationships. Auri can create or update tasks and synchronize task changes when you request or enable those actions.
2.7 Microsoft 365 Data
When you authorize Microsoft 365, Auri may access basic profile information and authorized Outlook mail, calendars, contacts, OneDrive files, and Microsoft To Do tasks. Depending on the permissions you grant and the action you request, Auri may read, create, update, organize, or send content through Microsoft Graph.
2.8 Apple Contacts and Reminders Data
With macOS permission, Auri may access contact names, email addresses, and phone numbers through Apple Contacts, and may read or update reminder titles, notes, dates, priority, recurrence, completion state, and lists through Apple Reminders.
Apple Contacts and Reminders are accessed through local macOS frameworks. Relevant information may be included in an AI request or cloud action only when you invoke a feature that needs that context.
2.9 Email Analytics Data
The Service collects and computes the following email analytics locally on your device:
- Email sent, received, and reply counts
- Average response times
- Communication volume by hour and day of week
- Top senders and recipients by frequency
- Up to 1,000 email analytics events stored locally
2.10 Email Tracking Data
When read receipt tracking is enabled, the Service collects:
- Tracking identifier (UUID)
- Associated email message and thread identifiers
- Recipient email address(es) and email subject line
- Sent timestamp, open count, and open timestamps
- Delivery status (pending, sent, failed, opened)
2.11 Writing Style Data
The Service analyzes your sent emails to extract writing style characteristics, including formality level, tone patterns, common phrases, sentence structure, and average sentence and paragraph length.
The resulting writing style profile is stored locally. Email samples and/or the extracted style description may be sent to the configured AI provider when you analyze your style or apply it to an AI-generated draft.
2.12 Tasks, Collaboration, and Cloud Workflows
Auri may process and store task and project titles, notes, dates, status, priority, tags, assignees, dependencies, reminders, comments, provider bindings, and supporting action metadata. When you invite another Auri user to shared work, we also process the inviter and recipient identifiers, email address, display name, role, invitation status, resource title, and timestamps.
Cloud assistant features may process selected message snippets, summaries, draft subjects and bodies, briefing content, indexes, action previews, approval state, execution receipts, and error information needed to prepare, route, approve, or complete an action.
2.13 Meetings, Audio, and Transcripts
When you use meeting features, Auri may process microphone or system audio, meeting titles, calendar links, participant or speaker labels, timestamps, transcripts, consent or disclosure status, summaries, decisions, commitments, and follow-up items.
Processing may occur locally, through OpenAI, or through an organization-managed relay according to the mode you select. Voice input and cloud-enabled transcription may upload audio for transcription. Local meeting files remain on your Mac unless a selected mode or sharing action requires cloud processing.
2.14 Travel Data
When you use travel features, the Service processes flight numbers, travel dates, passport country codes, destination country codes, and airport codes (IATA). This data is sent to third-party travel APIs as anonymous queries without personally identifiable information.
2.15 User Preferences and Settings
The Service stores your preferences locally, including application theme, default event duration, read receipt preferences, smart send preferences, undo send delay, availability time blocks, budget categories, and split inbox rules.
2.16 AI Interaction Data
When you interact with Auri's AI features, the Service may process your text prompts and selected email, calendar, task, meeting, contact, Slack, Notion, document, file, or travel context, along with extracted topics of interest and audio you submit for transcription.
Depending on your configuration, relevant context may be sent to OpenAI either directly from the app or through an Auri-managed relay endpoint in order to generate summaries, drafts, briefings, reasoning, web-search-assisted answers, and voice transcriptions.
External AI is configurable by feature. Auri includes controls that let you disable OpenAI globally, disable it for specific domains such as email or calendar, and separately restrict sensitive email context.
2.17 SMS Mobile Information
If you enable SMS, we use your mobile phone number to send briefings, email or draft notices, task reminders, and assistant action updates. You may also reply with questions or commands, create or review tasks, and continue a recent Auri conversation by text.
We process inbound and outbound message content, sender and recipient numbers, delivery identifiers and status, timestamps, routing information, and related account or action context. Auri may use a bounded set of recent delivered messages to understand a follow-up. Twilio and mobile carriers process messages to deliver the service.
Message frequency varies based on your settings and Auri activity. Message and data rates may apply.
We do not share mobile phone numbers, SMS opt-in data, or SMS consent status with third parties or affiliates for marketing or promotional purposes.
You can turn SMS off in Auri Settings at any time. You can also reply STOP to opt out or HELP for help.
2.18 Website and Operational Data
When you use our website or cloud endpoints, we and our hosting providers may process page URLs, referrers, approximate location, browser, operating system, device type, timestamps, IP address, request metadata, and error or security logs. Our public website uses Vercel Web Analytics for aggregated traffic measurement.
3.How We Use Your Information
Providing the Service
Managing connected mail, calendars, contacts, files, documents, messages, tasks, projects, meetings, and travel workflows.
External AI Processing
When enabled, sending relevant prompts, approved workspace context, and optional voice recordings to OpenAI to fulfill the AI feature you invoked.
Tasks and Collaboration
Synchronizing tasks, routing invitations, applying collaborator roles, and supporting shared task, project, and calendar work.
Meetings
Recording or transcribing meetings, generating meeting intelligence, and preserving audio according to your selected processing and retention settings.
SMS
Sending optional briefings, email and task notices, receiving your replies and commands, and maintaining enough recent context to understand follow-ups.
Cloud Assistant Workflows
Preparing and routing drafts, briefings, approvals, actions, status updates, and execution records for cloud-enabled features.
Email Tracking
Recording when recipients open tracked emails and providing open analytics and delivery status.
Smart Send
Analyzing recipient response patterns to suggest optimal email send times.
Writing Assistance
Analyzing your writing style to generate email drafts that match your tone.
Calendar Sync
Syncing calendar data to our cloud infrastructure for multi-device access, availability sharing, and collaboration.
Service Improvement
Diagnosing technical issues and maintaining the Service.
We do not use your data for:
Advertising or ad targeting, selling to third parties, training external AI models, or profiling for purposes unrelated to the Service.
4.How We Store Your Information
4.1 Local Storage (On Your Device)
| Data Type | Storage | Protection |
|---|---|---|
| OAuth tokens and connection state | macOS Keychain and app storage | Keychain and app-sandbox protections |
| Email & calendar cache | In-memory / UserDefaults | App-sandboxed |
| Writing style profiles | Local file cache | App-sandboxed |
| Email analytics | UserDefaults (max 1,000) | App-sandboxed |
| Smart send patterns | Local file cache | App-sandboxed |
| Auto-draft cache | Local file cache | App-sandboxed |
| User preferences | UserDefaults | App-sandboxed |
| Contact/presence cache | In-memory (max 200) | App-sandboxed |
| Meeting transcripts and audio | Application Support | App-sandboxed; retention selected in Auri |
4.2 Cloud Storage (Firebase Firestore on GCP)
| Data Type | Information | Retention |
|---|---|---|
| Account and executive profiles | Names, email, profile, settings, entitlement, and device/account identifiers | While active or as needed to provide the Service |
| Calendar sync | Event titles, times, locations, attendees | 30-day rolling window |
| Email tracking | Tracking ID, message ID, recipient, subject | Until manually deleted |
| Hosted integrations | Provider account metadata, access and refresh tokens, expiry, and connection state | Until disconnected, revoked, or no longer needed |
| Tasks and collaboration | Task/project content, invitations, participants, roles, comments, bindings, and status | While shared work or the account remains active, or as needed for the workflow |
| SMS | Phone number, preferences, message transcript, delivery and routing metadata | While enabled or as needed for the account, support, security, and message workflow |
| Cloud assistant workflows | Selected snippets, summaries, drafts, briefings, indexes, previews, approvals, actions, receipts, and errors | For the workflow lifecycle and as otherwise described in this Policy |
| Calendar collaboration | Availability, directory, invitation, connection, and thread records | While the connection or account remains active |
4.3 Local-First Does Not Mean Cloud-Free
Auri does not generally create a wholesale cloud copy of your entire mailbox, Slack workspace, contact database, or local files. Selected excerpts, summaries, drafts, message bodies, indexes, task or meeting context, and action metadata may nevertheless be processed or stored when required for an AI request, hosted integration, SMS conversation, collaboration feature, or cloud workflow you use.
5.How We Share Your Information
5.1 Third-Party Service Providers
| Service | Data Shared | Purpose |
|---|---|---|
| Google APIs | Your authorized data via OAuth | Email, calendar, document management |
| Microsoft Graph | Your authorized Microsoft 365 data via OAuth | Mail, calendar, contacts, files, and task management |
| Slack API | Your authorized Slack data and actions via OAuth | Reading, searching, posting, reactions, presence, and conversation management |
| Notion API | Your authorized workspace data and actions via OAuth | Searching, reading, creating, updating, and organizing Notion content |
| Asana API | Your authorized profile, workspace, project, task, and action data via OAuth | Task and project synchronization and management |
| Firebase / GCP | Account, profile, integration, collaboration, sync, SMS, and cloud workflow data | Authentication, storage, hosting, processing, and real-time sync |
| Vercel | Website analytics and request metadata; hosted integration records and requests | Website hosting, aggregated analytics, and hosted OAuth endpoints |
| OpenAI API (directly or through Auri relay) | Prompts, approved workspace or meeting context, uploaded audio, and model outputs | AI chat, summaries, drafting, briefings, meeting intelligence, reasoning, web search, and transcription |
| Twilio | Phone number, SMS consent, message content, and delivery metadata | Delivering and receiving optional two-way SMS |
| FlightRadar24 | Flight numbers, travel dates | Real-time flight status |
| Travel advisory APIs | Country codes | Visa & travel advisories |
| Google News RSS | Interest-based search queries | News article retrieval |
5.2 Collaboration Sharing
When you connect with another Auri user, relevant executive names, availability, calendar data, connection status, and collaboration messages may be shared with that connection. When you invite a user to a task or project, the invited and accepted collaborators can access the shared resource and may update it according to their viewer or editor role.
Not shared automatically: connecting or collaborating does not by itself grant access to your entire mailbox, Slack workspace, contact list, or unrelated tasks and projects.
5.3 Email Recipients
When read receipt tracking is enabled, a tracking pixel is embedded in outgoing emails. The tracking pixel URL contains only a UUID-based tracking identifier and does not expose your personal information to the recipient.
5.4 We Do Not Sell Your Data
We do not sell, rent, or lease your personal information to third parties.
5.5 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Auri, our users, or others.
5.6 SMS Marketing Restrictions
We do not share mobile phone numbers, SMS opt-in data, or SMS consent status with third parties or affiliates for marketing or promotional purposes.
6.Data Security
Encryption in Transit
Network data is transmitted using HTTPS/TLS. Supported hosted OAuth flows use PKCE and signed, time-limited state.
Storage Protections
Local secrets use macOS Keychain where supported; cloud providers apply access controls and encryption at rest; selected server-side Google refresh-token paths use additional application-layer encryption.
App Sandboxing
Restricted to user-selected files, HTTPS-only network, scoped Keychain access, and explicit Contacts permission.
Token Security
Tokens and connections are scoped by user and executive, refreshed when needed, and revoked or deleted where supported when you disconnect.
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
7.Data Retention
7.1 Active Use
We retain your data for as long as your account is active and as necessary to provide the Service.
7.2 Local Data
Locally stored data persists until you delete it, clear it in Auri, or uninstall the application. Specific limits include: email analytics (rolling window of up to 1,000 events), contact/presence cache (in-memory only, cleared on restart), travel advisory cache (1-hour TTL), news article cache (30-minute TTL), and calendar/email cache (refreshed each session).
7.3 Cloud Data
Cloud data is retained while your account, connection, shared work, message conversation, or workflow remains active and for as long as reasonably needed to provide, secure, troubleshoot, and document the Service. Some records may be deleted sooner by feature-specific lifecycle rules.
7.4 Email Tracking Data
Email tracking records are retained indefinitely unless you request deletion.
7.5 OpenAI and External AI Retention
Auri generally configures supported OpenAI requests with storage disabled. This does not eliminate provider abuse-monitoring logs, legal or security exceptions, or retention associated with a different feature or configuration. OpenAI states that API data is not used to train its models by default unless the customer opts in and that abuse-monitoring logs may be retained for up to 30 days by default. See OpenAI's current API data controls.
7.6 Meetings and SMS
For meetings, transcript-only mode deletes raw audio after successful finalization; short-replay mode keeps local raw audio for up to seven days; and organization-managed mode follows the applicable organization policy. SMS transcript and delivery records may remain while SMS or the account is active and as needed for workflow continuity, support, security, or legal obligations.
7.7 Account Deletion
When you request account deletion, we delete or deidentify personal information associated with the account that is no longer needed and revoke or delete stored integration credentials where supported. Some information may remain temporarily in backups or where retention is required for security, fraud prevention, dispute resolution, legal compliance, or technical integrity. Local data must be deleted in Auri or by uninstalling the application.
8.Your Rights and Choices
Access & Portability
Request access to your personal information in a structured, commonly used format.
Correction
Update or correct your account information and executive profiles at any time through the Service.
Deletion
Request deletion of your account and data by contacting us. Processed within 30 days.
Revoke Third-Party Access
Disconnect Google, Microsoft, Slack, Notion, Asana, and other supported providers in Auri or through the provider.
Disable Email Tracking
Disable read receipt tracking globally or on a per-email basis through Settings.
Disable SMS Alerts
Turn SMS alerts off in Auri Settings at any time, or reply STOP to opt out and HELP for help.
Manage Collaboration
Disconnect calendar connections, decline invitations, leave shared work, or revoke task and project access.
Manage Meeting Data
Choose local or cloud processing where available, select a retention profile, and delete local recordings or transcripts.
9.Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.
10.International Data Transfers
The Service stores cloud data on Google Cloud Platform (Firebase Firestore), which may process data in the United States and other jurisdictions. By using the Service, you consent to the transfer of your data to these jurisdictions. We rely on Google Cloud's data processing agreements and standard contractual clauses for international data transfers where applicable.
11.Third-Party Links and Services
The Service may detect and present links to third-party services (such as Zoom, Microsoft Teams, or Google Meet meeting links). Clicking these links will open your default web browser. We do not control and are not responsible for the privacy practices of these third-party services.
12.Analytics and Telemetry
No advertising analytics
The Auri desktop app does not use Firebase Analytics or advertising trackers.
Our public website uses Vercel Web Analytics to measure aggregated page visits. Vercel may process the page URL, referrer, coarse location, browser, operating system, device type, and timestamp and states that it does not use third-party cookies for this service. Cloud hosting providers may also retain request, IP address, user-agent, error, and security logs needed to operate and protect the Service.
Email analytics such as response times, volume patterns, and top contacts are computed and stored locally. Auri may keep bounded local operational telemetry such as model name, token or cost estimates, duration, tool names, outcomes, and error details to diagnose workflows.
13.Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or via email. The “Last Updated” date at the top indicates when it was last revised. Your continued use of the Service after changes are posted constitutes your acceptance of the updated Policy.
14.Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
Auri
Email: privacy@auriassist.com
Website: auriassist.com
You may also reach the founding team directly:
- Neel Sharma: neel@auriassist.com
- Nicklas: nicklas@auriassist.com
For data deletion requests, email privacy@auriassist.com with the subject line “Data Deletion Request” and include your account email address.
15.Jurisdiction-Specific Provisions
15.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell personal information. No opt-out is required.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at privacy@auriassist.com.
15.2 European Economic Area (GDPR)
If you are located in the EEA, you have additional rights under the GDPR:
- Legal Basis: We process data based on consent (OAuth), contractual necessity, and legitimate interests.
- Data Protection Rights: Access, rectification, erasure, restriction, portability, and objection to processing.
- DPO Contact: privacy@auriassist.com
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.
15.3 United Kingdom (UK GDPR)
Residents of the United Kingdom have equivalent rights under the UK GDPR. The provisions of Section 15.2 apply.
16.Google API Services User Data Policy Compliance
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the Service's functionality as described in this Policy.
- We do not transfer Google user data to third parties except as necessary to provide the Service, as required by law, or with your explicit consent.
- We do not use Google user data for advertising purposes.
- We do not allow humans to read your Google user data unless: (a) you have given explicit consent, (b) it is necessary for security purposes, (c) it is required by law, or (d) the data is aggregated and anonymized.
17.OpenAI and External AI Providers
17.1 How Auri Uses OpenAI
Auri uses OpenAI-backed services for optional AI features such as chat assistance, summaries, drafting, briefings, reasoning, web-search-assisted answers, and voice transcription. Depending on deployment configuration, these requests may be sent directly to OpenAI or first routed through an Auri-managed relay endpoint.
17.2 What May Be Sent
When external AI is enabled and you invoke an AI feature, the request may include your prompt together with relevant context needed to complete that task, such as selected email or thread content, calendar, task, meeting, contact, Notion, document, file, Slack, or travel context, or audio submitted for transcription.
17.3 Training and Retention
We do not use your content to train Auri's own models, and we do not sell your data. OpenAI states that data sent to the OpenAI API is not used to train or improve OpenAI models by default unless the customer explicitly opts in.
Auri generally sets supported API requests not to store application state. OpenAI states that abuse-monitoring logs may still be retained for up to 30 days by default, subject to exceptions. Provider terms and technical controls may change, so review the linked API data controls for current details.
17.4 Your Controls
You can disable OpenAI-backed features globally or by feature area in the app. Auri also includes a separate control for sensitive email context. Auri does not send email on your behalf without your approval, and calendar write behavior remains subject to the approval controls you configure.
By using Auri, you acknowledge that you have read and understood this Privacy Policy.