About this policy
Koda is a personal assistant operated and used privately by Ruben Brandão. This policy covers the assistant, its connected services, and this public information website.
Messages and saved context
Koda processes the messages and information the owner shares in conversation. This can include preferences, saved notes, reminder details, and results from connected tools. When voice-note transcription is used, the audio and its transcript are also processed.
Saved context helps Koda answer questions and follow up on tasks. Reminder records include their text, schedule, status, and delivery history. Messaging account identifiers are used to restrict access and deliver replies to the owner.
Calendar information
After the owner authorizes a Google account, Koda can access:
- The list of calendars the account subscribes to, including their names, identifiers, and access roles.
- Calendar properties such as descriptions and time zones.
- Event details such as titles, descriptions, start and end times, locations, recurrence, reminders, and attendees where present.
The event permission granted by Google covers reading and changing events, including deletion. Koda's current assistant tools expose event creation and updates; they do not expose event deletion.
Google handles account sign-in. Koda receives authorization tokens and does not receive or store the owner's Google password.
Mail and task information
With a separate Google authorization, Koda can search and read Gmail messages, including sender and recipient details, dates, subjects, labels, snippets, and available plain-text bodies. It does not send mail, change labels, mark messages as read, or extract attachments.
Koda can also read Google task lists and task details, including titles, notes, due dates, and completion states. This connection does not create, edit, or complete Google Tasks.
How information is used
Koda uses this information to answer questions, help with planning and research, manage requested calendar events, deliver reminders, and provide occasional check-ins. Relevant tool results may appear in conversations. Preferences and notes the owner chooses to save can be used in later conversations.
Personal data is not sold, used for advertising, or provided to data brokers. The project does not build shared model-training datasets from Google user data. Use and transfer of Google user data are limited to the features described here and must follow the Google API Services User Data Policy, including its Limited Use requirements.
Connected services
These services process information as part of using Koda:
- Google stores calendar, mail, and task data, handles authorization, and receives requests within the permissions granted by the owner.
- OpenAI processes messages, relevant saved context, and tool results to interpret requests and generate responses. Audio supplied for transcription is sent to OpenAI. Its handling of that content depends on the OpenAI service and the account's data controls.
- Discord processes messages and attachments exchanged with Koda through its private Discord connection, including replies, reminders, and check-ins. Replies can contain information requested from connected services.
- Web-search providers and websites receive the search queries or page requests needed for web research. Koda's instructions prohibit including private mail or saved personal context in public search queries.
Google, OpenAI, and Discord operate under their own privacy policies: Google, OpenAI, and Discord. Other people are not given access to the owner's Koda installation through this website.
Storage and retention
Koda's application state is stored on the owner's device. OAuth credentials are kept in local application storage with restricted file permissions, separate from the assistant's workspace memory. Connections to Google and OpenAI use HTTPS.
Conversation history, tool results, saved preferences, reminder and delivery records, and private backups may remain until the owner removes them. There is no automatic deletion period configured for those local records. Authorization tokens remain until replaced, removed, expired, or revoked.
Deleting local data does not automatically remove calendar events, mail, tasks, or copies held by connected providers under their own retention policies.
Revoke access or delete data
The owner can revoke Koda from the Google Account connections page. This prevents future authorized requests to the revoked Google services. It does not delete events already created or information already saved locally.
Reminders and occasional check-ins can be paused through Koda. Calendar events, mail, and tasks can be managed directly in their respective Google services. Local conversations, saved notes, reminder records, credentials, and backups can be removed from the Koda installation. For help with access or deletion, contact Ruben Brandão.
This website
This is a static information website. It has no account sign-in, contact forms, advertising, analytics scripts, or application cookies. Fonts and other assets are served with the site.
The hosting provider may process basic request information, such as IP address, browser details, and requested page, to deliver and protect the website. The public website does not receive Calendar contents or Koda's authorization tokens.
Contact and changes
Questions about this policy or Koda's handling of information can be directed to Ruben Brandão through his personal website.
This policy will be updated when the application's data practices change. The revision date appears at the top of this page.