Privacy Policy

Privacy Policy

Auri — AI Executive Assistant

Effective: February 17, 2026Last updated: May 13, 2026

At a Glance

Local-first architecture

Much of your workspace data stays on your device, with cloud sync used only for account and product features that require it.

OpenAI with controls

When external AI is enabled, Auri may send relevant context to OpenAI for summaries, drafts, briefings, reasoning, and transcription.

No data selling

We never sell, rent, or trade your personal information.

You're in control

You can disable external AI globally or by feature, restrict sensitive email context, revoke access, delete your account, or turn off optional SMS alerts.

1.Introduction

This Privacy Policy (“Policy”) describes how Auri (“Company,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects your personal information when you use the Auri desktop application and related services (collectively, the “Service”). This Policy applies to all users of the Service, including users and the executives they support.

We are committed to protecting your privacy and handling your data transparently. Please read this Policy carefully. By using the Service, you consent to the data practices described herein.

2.Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Display name
  • Firebase user identifier (UID)
  • Authentication provider (Google, Microsoft, or email/password)

2.2 Executive Profile Information

When you create executive profiles within the Service, the following data is collected and stored:

  • Full name, email address, job title, and company name
  • Phone number and timezone
  • Workday start and end times
  • Associated Google account email address(es)
  • Naming prefix preferences

2.3 Google Workspace Data

When you authorize Google Workspace integration, we access the following data through Google APIs using OAuth 2.0:

Gmail

  • Email message metadata (message ID, thread ID, sender, recipients, subject, date)
  • Email body content and snippets
  • Email labels and read/unread status
  • Attachment filenames and metadata
  • Email signatures and "send as" configurations

Google Calendar

  • Event titles, descriptions, locations, and attendees
  • Event start and end times, including all-day events
  • Recurrence patterns and organizer information
  • Free/busy status and calendar access control lists

Google Drive

  • File names, types, and metadata
  • File sharing permissions and recent file activity
  • File content (for Google Docs and Sheets when accessed)

Google Docs & Sheets

  • Document content (when read or appended)
  • Spreadsheet values (when read or written)

Google People API

  • Contact names, email addresses, and phone numbers
  • Profile information

Google OAuth Scopes Requested

gmail.readonlyRead email messages and metadata
gmail.modifySend emails, modify labels, trash emails
calendarFull calendar access
calendar.eventsCreate and modify calendar events
drive.readonlyRead Drive file metadata and content
drive.activity.readonlyView Drive file activity
documentsRead and write Google Docs
spreadsheetsRead and write Google Sheets
userinfo.emailRead your email address
userinfo.profileRead your basic profile information

2.4 Slack Data

When you authorize Slack integration, we access:

  • Authenticated user ID and display name
  • Team/workspace name
  • User presence status (online, away, do not disturb)
  • Conversation and channel names
  • Message history from conversations you have access to
  • User display names (cached locally, up to 200 entries)

2.5 Apple Contacts Data

When you explicitly enable Apple Contacts integration, we access contact names, email addresses, and phone numbers.

Apple Contacts data is accessed through the macOS Contacts framework, processed locally, and is never transmitted to external servers or our cloud infrastructure.

2.6 Email Analytics Data

The Service collects and computes the following email analytics locally on your device:

  • Email sent, received, and reply counts
  • Average response times
  • Communication volume by hour and day of week
  • Top senders and recipients by frequency
  • Up to 1,000 email analytics events stored locally

2.7 Email Tracking Data

When read receipt tracking is enabled, the Service collects:

  • Tracking identifier (UUID)
  • Associated email message and thread identifiers
  • Recipient email address(es) and email subject line
  • Sent timestamp, open count, and open timestamps
  • Delivery status (pending, sent, failed, opened)

2.8 Writing Style Data

The Service analyzes your sent emails to extract writing style characteristics, including formality level, tone patterns, common phrases, sentence structure, and average sentence and paragraph length.

Writing style data is processed and stored entirely on your device and is never transmitted externally.

2.9 Travel Data

When you use travel features, the Service processes flight numbers, travel dates, passport country codes, destination country codes, and airport codes (IATA). This data is sent to third-party travel APIs as anonymous queries without personally identifiable information.

2.10 User Preferences and Settings

The Service stores your preferences locally, including application theme, default event duration, read receipt preferences, smart send preferences, undo send delay, availability time blocks, budget categories, and split inbox rules.

2.11 AI Interaction Data

When you interact with Auri's AI features, the Service may process your text prompts, selected email and thread context, calendar event context, Slack summaries, document context, travel context, extracted topics of interest, and voice recordings you submit for transcription.

Depending on your configuration, relevant context may be sent to OpenAI either directly from the app or through an Auri-managed relay endpoint in order to generate summaries, drafts, briefings, reasoning, web-search-assisted answers, and voice transcriptions.

External AI is configurable by feature. Auri includes controls that let you disable OpenAI globally, disable it for specific domains such as email or calendar, and separately restrict sensitive email context.

2.12 SMS Mobile Information

If you enable SMS alerts, we use your mobile phone number only to send Auri SMS alerts for email draft notifications and scheduled morning briefings. Message frequency varies based on your Auri activity and briefing schedule. Message and data rates may apply.

We do not share mobile phone numbers, SMS opt-in data, or SMS consent status with third parties or affiliates for marketing or promotional purposes.

You can turn SMS alerts off in Auri Settings at any time. You can also reply STOP to opt out or HELP for help.

3.How We Use Your Information

Providing the Service

Managing your emails, calendar, contacts, and connected workspaces; generating summaries, drafts, briefings, and analyses; providing travel intelligence; and enabling A2A scheduling.

External AI Processing

When enabled, sending relevant prompts, approved workspace context, and optional voice recordings to OpenAI to fulfill the AI feature you invoked.

SMS Alerts

Sending optional text alerts for email draft notifications and scheduled morning briefings when you enable SMS alerts.

Email Tracking

Recording when recipients open tracked emails and providing open analytics and delivery status.

Smart Send

Analyzing recipient response patterns to suggest optimal email send times.

Writing Assistance

Analyzing your writing style to generate email drafts that match your tone.

Calendar Sync

Syncing calendar data to our cloud infrastructure for multi-device access and A2A collaboration.

Service Improvement

Diagnosing technical issues and maintaining the Service.

We do not use your data for:

Advertising or ad targeting, selling to third parties, training external AI models, or profiling for purposes unrelated to the Service.

4.How We Store Your Information

4.1 Local Storage (On Your Device)

Data TypeStorageProtection
OAuth tokensmacOS KeychainEncrypted by macOS
Email & calendar cacheIn-memory / UserDefaultsApp-sandboxed
Writing style profilesLocal file cacheApp-sandboxed
Email analyticsUserDefaults (max 1,000)App-sandboxed
Smart send patternsLocal file cacheApp-sandboxed
Auto-draft cacheLocal file cacheApp-sandboxed
User preferencesUserDefaultsApp-sandboxed
Contact/presence cacheIn-memory (max 200)App-sandboxed

4.2 Cloud Storage (Firebase Firestore on GCP)

Data TypeInformationRetention
Assistant profilesDisplay name, share code, creation dateUntil account deletion
Executive profilesName, email, title, company, phone, timezoneUntil manually deleted
Calendar syncEvent titles, times, locations, attendees30-day rolling window
Email trackingTracking ID, message ID, recipient, subjectUntil manually deleted
A2A connectionsConnected assistant IDs, statusUntil manually deleted
OAuth refresh tokensEncrypted refresh tokensUntil revoked

4.3 Data Not Stored in the Cloud

The following categories are not intentionally stored in our Firebase/Firestore cloud database as part of normal account storage: full email body content, Slack message content, writing style profiles, email analytics, and Apple Contacts data. However, when you enable and use external AI features, relevant excerpts or context from some of these categories may be transmitted to OpenAI or an Auri relay in order to fulfill your request.

5.How We Share Your Information

5.1 Third-Party Service Providers

ServiceData SharedPurpose
Google APIsYour authorized data via OAuthEmail, calendar, document management
Slack APIYour authorized data via OAuthConversation history & presence
Firebase / GCPAccount data, profiles, sync dataCloud storage, auth, real-time sync
OpenAI API (directly or through Auri relay)Prompts, approved workspace context, uploaded audio, and model outputsAI chat, summaries, drafting, briefings, reasoning, web search, and transcription
TwilioMobile phone number, SMS opt-in data, and SMS consent statusDelivering optional SMS alerts you enable
FlightRadar24Flight numbers, travel datesReal-time flight status
Travel advisory APIsCountry codesVisa & travel advisories
Google News RSSInterest-based search queriesNews article retrieval

5.2 Assistant-to-Assistant (A2A) Sharing

When you connect with another Auri user, calendar event data, executive profile names, and connection status are shared between connected accounts.

Not shared through A2A: email content or metadata, Slack messages, contact lists, writing style profiles, or user preferences.

5.3 Email Recipients

When read receipt tracking is enabled, a tracking pixel is embedded in outgoing emails. The tracking pixel URL contains only a UUID-based tracking identifier and does not expose your personal information to the recipient.

5.4 We Do Not Sell Your Data

We do not sell, rent, or lease your personal information to third parties.

5.5 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Auri, our users, or others.

5.6 SMS Marketing Restrictions

We do not share mobile phone numbers, SMS opt-in data, or SMS consent status with third parties or affiliates for marketing or promotional purposes.

6.Data Security

Encryption in Transit

All data transmitted uses HTTPS/TLS encryption. OAuth flows employ PKCE for additional security.

Encryption at Rest

macOS Keychain for tokens, AES-256 via Google Cloud for cloud data, App Sandbox for local caches.

App Sandboxing

Restricted to user-selected files, HTTPS-only network, scoped Keychain access, and explicit Contacts permission.

Token Security

Short-lived access tokens, encrypted Keychain storage, 30-minute refresh buffer, per-executive scoping.

While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

7.Data Retention

7.1 Active Use

We retain your data for as long as your account is active and as necessary to provide the Service.

7.2 Local Data

Locally stored data persists until you uninstall the application or manually clear the data. Specific retention periods include: email analytics (rolling window of up to 1,000 events), contact/presence cache (in-memory only, cleared on restart), travel advisory cache (1-hour TTL), news article cache (30-minute TTL), and calendar/email cache (refreshed each session).

7.3 Cloud Data

Cloud-stored data in Firebase Firestore is retained until you manually delete it, request account deletion, or we delete inactive accounts.

7.4 Email Tracking Data

Email tracking records are retained indefinitely unless you request deletion.

7.5 OpenAI and External AI Retention

When you use OpenAI-backed features, relevant request and response content may be retained by OpenAI in accordance with OpenAI's API policies. As of April 16, 2026, OpenAI states that API data is not used to train OpenAI models by default unless the customer explicitly opts in, that abuse-monitoring logs may be retained for up to 30 days by default, and that data sent through the Responses API may be stored as application state for at least 30 days by default.

We do not currently promise a shorter OpenAI retention period unless we explicitly state so in writing. If you need different retention terms, contact us before using OpenAI-backed features for sensitive workflows.

7.6 Account Deletion

Upon account deletion, we will delete your assistant profile, all executive profiles, calendar sync data, email tracking records, A2A connection data, and revoke stored OAuth refresh tokens. Local data must be removed by uninstalling the application.

8.Your Rights and Choices

Access & Portability

Request access to your personal information in a structured, commonly used format.

Correction

Update or correct your account information and executive profiles at any time through the Service.

Deletion

Request deletion of your account and data by contacting us. Processed within 30 days.

Revoke Third-Party Access

Revoke Google or Slack access via their settings or within the Service at any time.

Disable Email Tracking

Disable read receipt tracking globally or on a per-email basis through Settings.

Disable SMS Alerts

Turn SMS alerts off in Auri Settings at any time, or reply STOP to opt out and HELP for help.

Opt Out of A2A

Disconnect from other assistants at any time to stop calendar data sharing.

9.Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.

10.International Data Transfers

The Service stores cloud data on Google Cloud Platform (Firebase Firestore), which may process data in the United States and other jurisdictions. By using the Service, you consent to the transfer of your data to these jurisdictions. We rely on Google Cloud's data processing agreements and standard contractual clauses for international data transfers where applicable.

11.Third-Party Links and Services

The Service may detect and present links to third-party services (such as Zoom, Microsoft Teams, or Google Meet meeting links). Clicking these links will open your default web browser. We do not control and are not responsible for the privacy practices of these third-party services.

12.Analytics and Telemetry

Firebase Analytics is disabled

We do not collect app usage analytics through Firebase or any third-party analytics platform.

The Service does not integrate with any third-party analytics, advertising, or tracking SDKs. Email analytics (response times, volume patterns, top contacts) are computed and stored entirely on your device and are not transmitted to us or any third party.

13.Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or via email. The “Last Updated” date at the top indicates when it was last revised. Your continued use of the Service after changes are posted constitutes your acceptance of the updated Policy.

14.Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:

Auri

Email: privacy@auriassist.com

Website: auriassist.com

You may also reach the founding team directly:

For data deletion requests, email privacy@auriassist.com with the subject line “Data Deletion Request” and include your account email address.

15.Jurisdiction-Specific Provisions

15.1 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out of Sale: We do not sell personal information. No opt-out is required.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at privacy@auriassist.com.

15.2 European Economic Area (GDPR)

If you are located in the EEA, you have additional rights under the GDPR:

  • Legal Basis: We process data based on consent (OAuth), contractual necessity, and legitimate interests.
  • Data Protection Rights: Access, rectification, erasure, restriction, portability, and objection to processing.
  • DPO Contact: privacy@auriassist.com
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.

15.3 United Kingdom (UK GDPR)

Residents of the United Kingdom have equivalent rights under the UK GDPR. The provisions of Section 15.2 apply.

16.Google API Services User Data Policy Compliance

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide and improve the Service's functionality as described in this Policy.
  • We do not transfer Google user data to third parties except as necessary to provide the Service, as required by law, or with your explicit consent.
  • We do not use Google user data for advertising purposes.
  • We do not allow humans to read your Google user data unless: (a) you have given explicit consent, (b) it is necessary for security purposes, (c) it is required by law, or (d) the data is aggregated and anonymized.

17.OpenAI and External AI Providers

17.1 How Auri Uses OpenAI

Auri uses OpenAI-backed services for optional AI features such as chat assistance, summaries, drafting, briefings, reasoning, web-search-assisted answers, and voice transcription. Depending on deployment configuration, these requests may be sent directly to OpenAI or first routed through an Auri-managed relay endpoint.

17.2 What May Be Sent

When external AI is enabled and you invoke an AI feature, the request may include your prompt together with relevant context needed to complete that task, such as selected email or thread content, calendar context, document context, Slack summaries, travel context, or an audio recording you submit for transcription.

17.3 Training and Retention

We do not use your content to train Auri's own models, and we do not sell your data. OpenAI states that data sent to the OpenAI API is not used to train or improve OpenAI models by default unless the customer explicitly opts in.

OpenAI also states that certain API data may be retained for abuse monitoring and application state. In particular, OpenAI states that abuse-monitoring logs may be retained for up to 30 days by default and that Responses API data may be stored for at least 30 days by default unless different enterprise retention controls apply.

17.4 Your Controls

You can disable OpenAI-backed features globally or by feature area in the app. Auri also includes a separate control for sensitive email context. Auri does not send email on your behalf without your approval, and calendar write behavior remains subject to the approval controls you configure.

By using Auri, you acknowledge that you have read and understood this Privacy Policy.