Privacy policy · effective 26 August 2026
What Zari reads, where it lives, and who sees it.
Zari is operated by one person (the "operator") and connects only to accounts he owns. There are no other users, so there is no user data other than his own. This policy describes how that data is handled anyway, because Google asks and because it should be written down.
What Zari accesses
When a Google account is connected, Zari requests the gmail.modify scope. With it, Zari:
- reads incoming and archived mail, including attachments, to sort and summarize it;
- creates draft replies for the operator to review, edit and send;
- archives or labels messages the operator has told it to file;
- sends mail only after the operator explicitly approves a draft.
Zari never deletes mail, never changes account settings, and never sends anything on its own initiative.
Where data is stored
Mail content, summaries and drafts are stored in a database on a single computer in the operator's home. Access tokens are stored on that same machine in files readable only by the operator's account. No copy is kept in any cloud storage, analytics tool or third-party server.
How data is processed
To summarize and draft, Zari sends the text of individual messages to an AI language model provider (Anthropic) under the operator's own account with that provider. Those requests are used to produce a response and are not used to train models. No other third party receives message content.
Sharing
Zari does not sell, rent, publish or share Google user data with anyone. It does not serve advertising and does not build profiles of anyone other than the operator's own contacts, for his own use.
Google API Services — Limited Use
Zari's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the assistant features described above, is not transferred to others except as necessary to provide those features, is not used for advertising, and is never read by a human other than the operator.
Retention and deletion
Data stays on the operator's machine until he deletes it. Disconnecting an account removes its tokens immediately; revoking access at myaccount.google.com/permissions has the same effect from Google's side. Deleting the local database removes every stored message and summary.
Contact
Questions about this policy go to createneptie@gmail.com.