Privacy Policy
ASA OS (Mephisto) · Effective 6 September 2026
This policy describes what ASA OS does with data, written from how the system is actually built. ASA OS is a personal assistant system that Asa Beeri (the "operator") runs for himself, on a server he rents and controls. It has one user: the operator. There is no public sign-up, no other account and no customer. The Google account it connects to is the operator's own.
1. What ASA OS accesses from Google
| Service | Permission | What is actually done with it |
|---|---|---|
| Gmail | Read messages (gmail.readonly) | Once an hour the system reads the operator's most recent inbox messages (up to 50) and most recent sent messages (up to 200). Inbox messages are sorted into needs attention now, can wait and noise for a daily brief and for urgent alerts. Sent messages are used only to derive the list of people the operator has written to, so that a message from a known correspondent is treated differently from one from a stranger. |
| Gmail | Send messages | The system holds permission to send mail on the operator's explicit request. That function is currently switched off in the automation layer and sends nothing. |
| Google Calendar | Read and write events | Reads the operator's events to answer questions such as "what do I have tomorrow" and to avoid conflicts. Creates an event when the operator asks for one. Moving or cancelling an event happens only after the operator confirms. |
2. Where processing happens
All processing runs on a single server the operator rents, located in Germany. The Google connection itself is held by an automation layer (n8n) on that server; the application code that reads and reasons about the data runs on the same server and holds no Google credential of its own.
3. What is stored, and for how long
- Copies of examined messages. The raw text of messages the brief examined is kept on the server as evidence, so that every statement the brief makes can be traced back to the exact line it came from. A copy is deleted automatically 30 days after the message was last examined: the hourly run removes every copy older than that. The operator can delete them earlier at any time.
- The correspondent list. Email addresses derived from the operator's sent mail, kept on the server and rebuilt from the mailbox on each run.
- Conversation memory. What the operator says to the assistant, in writing or by voice, and what the assistant answers, is kept on the server in an append-only, integrity-checked store. Calendar events the assistant read or created are part of those turns.
- Backups. The conversation memory is backed up once a day, encrypted on the server before it leaves, to a storage box the operator rents from Hetzner. The encryption key stays on the server with the operator; the storage provider receives only ciphertext.
- Operational logs. The server keeps technical logs — timings, counts, decision classes — that contain no message text, no calendar text and no audio.
4. What leaves the server, and to whom
The system does not sell data, does not use it for advertising, and does not share it with anyone other than the processors listed here, each for the stated purpose only.
- AI model providers. Parts of the data are sent to Google's Gemini API to be analysed, through the automation layer on the server. For mail, this is header-level information — sender, subject, date, addressing and mailing-list headers — and never message bodies; the code asserts that no body content is included. For the brief's wording, the model receives the shape of the sentences without the facts, and it cannot add a fact of its own. For conversation, the model receives the operator's message, the recent turns of that conversation, and the calendar events referenced in them, so that it can work out what was asked. The system is built to also use Anthropic's Claude API as a second engine; that engine is not enabled today, and if it is enabled it would receive the same kinds of data for the same purposes.
- Telegram. The daily brief and urgent alerts are delivered to the operator as Telegram messages, so their text passes through Telegram's service.
- Cloudflare. Traffic to this site and to the application at app.asaos-ai.com passes through Cloudflare. The application sits behind Cloudflare Access, which handles the operator's sign-in and sees the sign-in identity.
5. Voice
When the operator speaks to the assistant, the audio is transcribed on the server by a speech-recognition model that runs locally. The audio is held in memory only for the duration of the transcription; it is never written to disk, never logged and never sent to any third party. The resulting text is treated exactly like typed text.
6. Google API Services User Data Policy
ASA OS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the operator's own assistant functions described above. It is not used for advertising, is not sold, and is not transferred to anyone except as needed to provide those functions (the processors in section 4), to comply with the law, or with the operator's explicit consent.
7. Revoking access and deleting data
- Google access can be revoked at any time at myaccount.google.com/permissions. Revoking it stops all reading of mail and calendar immediately.
- Stored copies of messages, the correspondent list, the conversation memory and its backups can be deleted by the operator, who has direct control of the server and the storage box. A request to the contact below is honoured by the same person.
8. Children
ASA OS is not directed at children and has no users other than its adult operator.
9. Changes
When the system changes in a way that changes what this page says, this page is updated and the effective date above moves.
10. Contact
Asa Beeri, the operator — [email protected].