Privacy Policy
Effective date: August 8, 2026
Ida is a personal productivity application that allows authorized users to access information from connected services. Ida is operated by Jordan Nissinoff. This policy explains what information Ida accesses from a connected Google account, how that information is used, how it is protected, and how a user can revoke access or request deletion.
Ida does not access any information from a connected service until the user chooses to connect that service and authorizes it through that service's own consent screen.
1. Google account data Ida may access
If a user connects a Google account, Ida may access the following, and only the following:
- Basic account identity — the email address of the Google account being connected, used to confirm which account is connected. Ida never receives a Google password.
- Gmail — messages and message threads in the connected mailbox, including sender and recipient addresses, subject, date, Gmail labels, message body text, and attachment details such as file name, file type, and size. Ida does not download attachment contents.
- Google Calendar — the names of the calendars in the connected account, and the events on the calendars the user selects, including event title, start and end times, location, organizer name and email address, the number of attendees, a shortened excerpt of the event description, and a link back to the event in Google Calendar. Ida does not store the attendee list, and does not store the full text of an event description.
Ida requests these Google OAuth scopes and no others:
openid, email,
gmail.readonly,
calendar.calendarlist.readonly, and
calendar.events.readonly. Gmail and Google Calendar are
separate connections; connecting one does not connect the other.
2. Gmail and Google Calendar access is read only
Ida's access to Gmail and Google Calendar is read only. Ida does not request, and cannot obtain through these scopes, permission to send, compose, reply to, modify, label, archive, or delete email, or to create, change, or delete calendars or calendar events. Ida makes only read requests to the Gmail and Google Calendar APIs.
Ida checks the permissions actually granted when a Google account is connected. If the granted permissions are broader or narrower than the scopes listed above, Ida refuses the connection.
3. How Ida uses this information
Ida uses information from a connected Google account only to:
- display the user's own recent email and calendar information back to them inside Ida;
- let the user search and review their own messages, threads, and events within Ida;
- produce summaries, and identify items that may need the user's attention, when the user asks Ida to do so;
- confirm which Google account is connected and keep the connection working.
When a user invokes a feature that uses AI, a bounded portion of the relevant content is sent to Ida's AI model provider solely to carry out that request and return a result to the user. Ida does not use Google user data for advertising, for marketing, for profiling unrelated to the user's own request, or to develop, improve, or train generalized artificial intelligence or machine learning models. Ida does not sell Google user data.
Ida does not send email, reply to email, or change a calendar on a user's behalf. Where Ida drafts suggested text, that text is shown to the user for review and is not sent.
4. How credentials and connected data are protected
- Google authorization is performed through Google's own OAuth consent flow. Ida never asks for, receives, or stores a Google password.
- OAuth access and refresh tokens are encrypted using AES-256-GCM before they are stored, and the encryption keys are held as server-side environment secrets. Tokens are never sent to the browser and are not included in any client-side code.
- Connected data is stored in Ida's database with owner-scoped access controls, so a signed-in user can reach only their own records.
- All traffic between the user, Ida, and Google is over HTTPS.
- Ida is a personal application under active development. No method of storage or transmission is perfectly secure, and this policy makes no claim of any security certification or audit.
5. Whether information is shared
Ida does not sell personal information, does not share it with data brokers, and does not display advertising. Information from a connected Google account is shared only with the service providers Ida needs in order to operate, and only for that purpose:
- Vercel — application hosting.
- Supabase — authentication, database, and file storage.
- Anthropic and OpenAI — AI model processing, when the user invokes a feature that uses AI.
Each of these providers handles the information it receives under its own terms and privacy practices. Ida may also disclose information if required by law, or to investigate and address security or abuse. Ida does not otherwise transfer Google user data to any other party.
6. Data retention and deletion
Ida keeps information imported from a connected Google account for as long as the user keeps the connection and the associated content in Ida, so that the features the user relies on continue to work.
Disconnecting a Google account in Ida stops all further access to that account. Deleting an Ida account removes the connection records and the stored OAuth tokens held for that account. A user may also ask for their information to be deleted at any time, as described below. Deletion requests are handled subject to security, legal, backup, and technical constraints, so this policy does not state a fixed deletion deadline.
7. How users revoke access
A user can revoke Ida's access to their Google account at any time:
- In Ida — disconnect the Google connection from Ida's connection settings. Ida then asks Google to revoke the token it holds.
- In the Google account — go to myaccount.google.com/permissions, select Ida, and remove its access. This revokes Ida's access directly with Google.
Revoking access stops future access. It does not by itself delete information already imported into Ida; to have that removed, use the deletion request below.
8. How users request deletion
To request access to, correction of, or deletion of information Ida holds, email docjniss@gmail.com from the email address associated with the Ida account, and state what should be deleted. Requests are confirmed before they are carried out.
9. Google API Services User Data Policy
Ida's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in accordance with the Limited Use requirements:
- Ida uses Google user data only to provide and improve the user-facing features described in this policy.
- Ida does not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with the user's consent.
- Ida does not use Google user data for serving advertisements of any kind.
- Ida does not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
- Ida does not allow humans to read Google user data unless the user has given affirmative consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized.
10. Changes to this policy
This policy may be updated as Ida changes. The effective date above shows when it was last revised.
11. Contact
Questions or requests about this policy or about information Ida holds: docjniss@gmail.com.
Ida