This Privacy Policy describes how Maiar Limited (“Maiar”, “we”, “us”) handles information in connection with its internal persistent personal AI programme, currently known as SKIPPY.
When a user explicitly connects a Google account, the current SKIPPY Gmail adapter may access Gmail data permitted by the https://www.googleapis.com/auth/gmail.readonly scope. This can include message metadata and message content needed to search for and read email in response to the user’s requests.
The current dedicated Gmail adapter does not expose Gmail send, reply, modify, label, trash, delete or draft actions, and it does not download attachments.
Google user data is used solely to provide functionality requested by the authorized user, such as finding relevant email, reading a selected message, summarising information, or answering a user question based on email content.
We do not use Google user data for advertising, profiling for advertising, sale to data brokers, or sale to third parties. We do not use Google user data to train or improve generalized or non-personalized AI or machine-learning models.
SKIPPY is an AI system. When needed to perform a user-requested task, relevant data may be processed by infrastructure or AI model service providers acting to deliver that functionality. Such processing is limited to providing the requested service and is not authorized by Maiar for independent advertising, resale, or training of generalized AI models.
OAuth credentials required to maintain the authorized connection are stored in restricted server-side credential storage for the SKIPPY runtime. Access is limited to the runtime components that require those credentials.
The Gmail adapter does not maintain a separate long-term copy of the user’s mailbox. Message data may be processed transiently to fulfil a request. If a user explicitly asks SKIPPY to retain information in its own state or memory, that retention is a separate, user-directed action and is governed by the system’s controlled-memory mechanisms.
Maiar does not sell Google user data. We may disclose data only to service providers necessary to operate SKIPPY, when directed by the user, or where required by law. Service-provider access is limited to what is necessary to provide the relevant service.
Maiar applies access controls and least-privilege principles to the SKIPPY prototype. The Gmail integration is designed to fail closed when unauthenticated and to reject OAuth tokens that contain broader Gmail permissions than the single read-only scope requested by SKIPPY.
Users can revoke SKIPPY’s Google account access at any time through their Google Account security settings. A user may also contact Maiar to request deletion of SKIPPY-held credentials or other personal information associated with the prototype, subject to legal or security retention requirements.
SKIPPY’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We may update this policy as SKIPPY evolves. If the way the system uses Google user data changes materially, this policy will be updated before that new use is introduced.
Maiar Limited
New Zealand
Email: whangarei@sleepy.co.nz