Privacy Policy

Privacy Policy

Effective date: September 17, 2026

Overview

Simon is a personal productivity and chief-of-staff automation system built and operated by James Logan Lyle ("I," "me," "my") for personal, non-commercial use. This policy explains what data Simon accesses, how it's used, and how it's protected. It applies only to Simon and to the Google account(s) I personally authorize to connect to it — it is not a public-facing service, and no one else's data is processed without their own explicit authorization.

Who can use Simon

Access is limited to Google accounts I personally own or explicitly authorize as the account owner/administrator. It is not distributed, marketed, or made available to the general public.

What data Simon accesses

Simon connects to five Google accounts I personally own, via a Google Cloud OAuth application I administer. For those accounts, it requests:

  • Gmail (gmail.modify) — message content and metadata, to read, search, and organize mail (labels, archiving, trash/ restore), draft messages, and send email where explicitly authorized. Does not permit permanently deleting mail, bypassing Trash.
  • Calendar (calendar) — event details across connected calendars, to read, and to create, edit, reschedule, or cancel events where explicitly authorized.
  • Drive (drive) — files across the connected account, to search and read existing files, create new files, and organize, move, or update files where explicitly authorized.
  • Docs (documents) and Sheets (spreadsheets) — to read, create, and edit documents and spreadsheets where explicitly authorized.
  • Contacts (contacts) — personal contacts, to read, create, and update entries where explicitly authorized.
  • Tasks (tasks) — task lists and tasks, to read and manage them.
  • Basic account identity (email, profile, openid) — to confirm which account is connected.

This is the complete list — no other Google data or product is requested or accessible through this application. If that changes, this policy and the scope list above will be updated first, before the new access is requested.

Separately, for my own primary Google account only, I use Google's first-party connector for Claude to read Calendar and Drive data. That connection is a distinct OAuth grant, authorized and operated directly by Anthropic under its own terms — it is not requested or controlled by this application, and is described here only for completeness.

No data is collected beyond what's needed for the specific productivity workflow it supports.

How data is used

Data from connected accounts is used exclusively to power personal productivity workflows I've defined — for example, summarizing my inbox into a daily briefing, tracking follow-up items, or drafting a message for my own review. Data may be processed by Anthropic's Claude API as part of these workflows, under Anthropic's own API terms and data-handling commitments.

Where data is stored

Retrieved data and derived working state (for example, a list of open follow-up items) are stored on infrastructure I personally control, and are not stored by or shared with any third party beyond the infrastructure and API providers necessary to run the application.

What Simon does not do

  • Does not sell any data, in any form.
  • Does not use data for advertising or ad targeting.
  • Does not share data with third parties for their own purposes.
  • Does not use data to train third-party models beyond what's inherent to processing a single request through Anthropic's API under its standard terms.
  • Does not permanently delete mail, files, contacts, or calendar events unless explicitly authorized for that specific action — routine removals use normal reversible mechanisms (e.g. Gmail Trash) wherever the underlying Google product offers one.

Data retention and deletion

Working state derived from connected accounts (for example, a tracked follow-up item) is retained only as long as it's useful to the workflow it supports, and is routinely reviewed and deleted or overwritten as items are resolved. There is no fixed automatic retention schedule; data is deleted promptly on request.

Revoking access

Access can be reviewed or revoked at any time via Google Account → Security → Third-party apps with account access . Revoking access immediately stops Simon from accessing that account going forward; any already-retrieved data is deleted promptly on request.

Changes to this policy

If Simon's data practices change materially, this page will be updated and the effective date above will change.

Contact

loganlyle55@gmail.com