Privacy Policy
Last updated: 28 August 2026
Willoughby (“we”, “us”, “the service”) is a personal AI work planner. This policy explains what information we collect, how we use it, and the choices you have. It is written for people using the product and for Google’s OAuth verification of our app.
Contact for privacy questions: williamcstaley@gmail.com.
1. Who we are
Willoughby is operated as a small, invitation-style web application. When you sign in, you create a private workspace keyed to your Google account. We do not run a public social network and we do not sell accounts or user lists.
2. Information we collect
Account and sign-in
When you sign in with Google we receive:
- Your Google account identifier
- Name, email address, and profile photo (if Google provides them)
- OAuth tokens needed to call Google APIs you authorized
We also store product activity such as when you signed in, how many times you have signed in, and when you last used the app, so we can operate and debug the service.
Google user data (Calendar and Gmail)
At sign-in we request read-only access to Google Calendar and Gmail. We use this access only to power features you see in the product:
- Calendar. Meeting times, titles, and related metadata so we can plan your day, show a calendar, and avoid scheduling over busy time.
- Gmail. Message metadata and bodies are read in memory so we can produce a short work summary. We store distilled summaries and triage labels — not full email bodies.
You can turn Gmail sync off, limit lookback, and cap how many threads are processed in Settings. Calendar access is used for the Today, Calendar, and planning features.
Other integrations you connect
- Asana. If you paste a personal access token, we store it encrypted and sync tasks assigned to you (subject to workspace/project filters you set).
- Slack. If you connect Slack, we sync DMs, @mentions, and channels you opt into. We store distilled summaries, not raw thread bodies.
Content you create in the app
Manual tasks, meeting notes, chat messages with the assistant, settings (timezone, working hours, sync limits), and mail-triage preferences (including sender hints when you move a thread between buckets).
Derived data
We generate embeddings, pattern clusters (“pattern brain”), daily plans, and importance scores so chat and Today can retrieve and rank your work. Optional JSON archives may be written to object storage for later retrieval.
3. How we use information
We use the information above to:
- Authenticate you and keep your workspace private to your account
- Build your daily plan, catch-up recap, calendar, tasks, and mail views
- Answer questions in chat using retrieval over your indexed work
- Improve reliability (sync, caching, debugging, security)
We do not use your data to show you third-party ads, and we do not sell your data.
4. Google API Services User Data Policy (Limited Use)
Willoughby’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide or improve user-facing features of Willoughby that are prominent in the app (planning, calendar, mail triage, and related retrieval).
- We do not use Google user data for advertising, including personalized, retargeting, or interest-based ads.
- We do not transfer Google user data to third parties except (a) as necessary to provide the features you requested (for example, sending distilled text to our AI processor), (b) to comply with law, or (c) in a merger or sale of the service where the successor is bound by this policy.
- We do not allow humans to read your Google user data unless you give affirmative consent for a specific message or item, it is necessary for security or legal compliance, or the data is aggregated and no longer associated with you.
- Gmail content is not used to train generalized AI/ML models. Distillation and chat use your data to generate answers and summaries for you in the product.
5. AI processing
Planning briefs, mail/Slack distillation, pattern naming, and chat may be processed by a third-party large language model provider (currently OpenAI). Prompts include the minimum work context needed to answer or summarize. That provider processes data as our processor under their terms and data-use policies. Do not treat model output as legal, financial, or professional advice.
6. Storage, security, and location
Account data, indexes, and settings are stored in Amazon Web Services (DynamoDB). Optional archives and pattern packs may be stored in Amazon S3. Integration secrets (Google and Slack tokens, Asana personal access tokens) are encrypted at rest. We use HTTPS in production. No method of transmission or storage is 100% secure; we take reasonable measures appropriate to a small production app.
7. Sharing
We share data only with:
- Infrastructure providers (AWS) that host the app
- The AI processor described above, when a feature needs it
- Google, Asana, or Slack when we call their APIs on your behalf
- Authorities if required by law
We do not sell or rent personal information.
8. Retention
We keep your workspace for as long as your account exists so the product can keep working (plans, indexes, and history). OAuth tokens are kept until you disconnect the integration or stop using the service. If you want data deleted, email us from the same address you use to sign in and we will delete your stored workspace, including Google-derived indexes, within a reasonable period (typically 30 days), except where we must retain a record for security or legal reasons.
9. Your choices
- Disconnect Asana or Slack in Settings → Integrations.
- Disable Gmail or Slack sync, or tighten lookback and caps, in Settings.
- Revoke Willoughby’s Google access at Google Account permissions. After revoke we cannot call Calendar or Gmail until you sign in again.
- Sign out of the app at any time.
- Request deletion or an export of your stored data by emailing williamcstaley@gmail.com.
10. Children
Willoughby is intended for working adults. We do not knowingly collect personal information from children under 16 (or under 13 where that is the applicable age).
11. Changes
We may update this policy as the product changes. The “Last updated” date at the top will change. Continued use after an update means you accept the revised policy. Material changes to how we use Google user data will be reflected here before those changes take effect.
12. Contact
Privacy and data requests: williamcstaley@gmail.com.
This policy applies to the Willoughby web application at the URL where you signed in.