This policy explains what information MyAgentOS collects, why, and how you stay in control of it — including any Google or iCloud data you choose to connect.
MyAgentOS ("the Service", "we", "us") is a personal capture-and-recall assistant. You send it short notes by text message (SMS) or voice memo, and it files them, extracts useful details (dates, people, commitments), and can surface older notes back to you when they become relevant — for example, in a daily brief that also lists your upcoming calendar events, if you have chosen to connect a calendar.
When you are onboarded, we store your name, phone number, and time zone. Your phone number is how the Service recognizes you when you text it and is how we send you a login link for the web dashboard.
The text of messages you send, and voice memos you record, are stored as you sent them. We use an AI language model to extract structured details from that content — for example a task, a due date, a person's name, or a commitment you made — so the Service can remind you or find it later. The original message is never edited or deleted by this process; only the extracted details can be regenerated if our extraction improves.
If you choose to connect your Google account, we request access to exactly two categories of Google data, using Google's own sign-in and consent screen:
We request Google access only after you explicitly click "connect" and grant these permissions on Google's own consent screen. We never request or receive your Google password.
If you choose to connect iCloud instead of (or alongside) Google, you provide an Apple ID and an Apple-generated, app-specific password (never your normal Apple password). We use it to read the same two categories described above — upcoming calendar events and whether a promised email was sent, checked against your Sent Mail folder — through Apple's own calendar and mail protocols. The app-specific password is stored encrypted, never in plain text, and is used only for this purpose.
All of the information above exists to do one thing: help the Service file what you tell it, remind you of it at a useful moment, and (only if you connect a calendar) tell you what your day looks like. We do not use any of it to build an advertising profile, and we do not use it for any purpose unrelated to providing you the Service.
To be direct about the requirements Google asks every application to state plainly:
The permissions we request, and nothing beyond them:
calendar.readonly — read your calendar so the morning brief knows what your day holds.calendar.events — add an event when you ask for one by naming a day and a time. Used for nothing else: we do not delete events, and we do not add guests, so no invitation is ever sent to anyone in your name.gmail.readonly — check whether a message you promised to send was actually sent, so a commitment is closed on evidence rather than on a guess, and read the message you are replying to so your reply goes back in the same conversation. We cannot change or delete mail.gmail.send — send an email from your own address, and only one you asked for. Either you wrote the recipient, the subject and the words yourself, or the Service drafted it and did nothing at all until you replied to send it. Nothing is sent because time passed or because software decided it should be, with one exception you set yourself: if you tell it to send at a named hour, it sends then and tells you it did.MyAgentOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data is stored in an encrypted database with tenant isolation enforced at the database level, so one person's information is not readable through another's session. Apple app-specific passwords are encrypted at rest. Access to the administrative tools that manage the Service is restricted by a separate credential from the one that gates your own read access. No storage or transmission system is perfectly secure, and we cannot guarantee absolute security, but we take these precautions seriously and continue to improve them.
We keep your information for as long as your account is active, so the Service can keep recalling things for you. If you request deletion (section 9), your account and the data tied to it are permanently removed and cannot be recovered.
We rely on a small number of infrastructure and processing providers to run the Service:
These providers process data on our behalf, under their own terms, and do not use it for their own independent purposes.
You can revoke MyAgentOS's access to your Google account at any time from Google Account → Security → Third-party access. Revoking access there immediately stops us from being able to read your calendar or Gmail; it does not delete data already extracted, which you can remove separately as described below.
To disconnect a connected Google or iCloud account, revoke access from the provider's own settings (section 8) or contact us using the details in section 13 and we will disconnect it for you. To request deletion of your account and all associated data — captures, extracted facts, connected-account credentials, and everything else tied to your account — contact us using the details in section 13. Deletion is permanent and cannot be undone.
The web dashboard uses a single, essential cookie to keep you signed in after you follow your SMS login link. We do not use advertising or tracking cookies, and we do not use any analytics or tracking pixels on the parts of the Service that require login.
MyAgentOS is not directed at children and is not knowingly used by anyone under the age of 18. We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will remove it.
If we make a material change to how we handle your information, we will update this page and change the "Last updated" date above. We encourage you to check back periodically.
For privacy questions, access requests, or to request deletion of your data: