Privacy policy
What we hold, where it sits, and who else sees it.
Last updated 8 September 2026
The short version
- — Fylgja reads your mail and calendars so it can answer you, write you a brief and draft replies. That is the only reason it reads them.
- — What it reads becomes part of your conversation, and that conversation is encrypted where it is stored.
- — It is not kept for long either. What it read out of your mail and calendars is cleared after 7 days, and the conversation itself after 90 days unless you ask for a different period. What it remembers about you, and the record of what each request cost, are kept — the first because you curate it, the second because it holds no message content.
- — Your Google sign-in credentials and your Anthropic API key are encrypted before they are written down.
- — It goes to Anthropic to produce each answer, and nowhere else except the services named below. We do not sell it, we do not advertise against it, and we run no analytics on you.
- — Ask us and we delete it.
Who we are
Fylgja is built and run by Loman Group LLC, a small software company in the United States. We are the people who decide what happens to the information described on this page, and the people you write to when you want it changed or removed.
Write to privacy@fylgja.work. A person reads that address.
Fylgja is in early access and is invitation-only. There is no public sign-up: accounts are created by us for people we have invited.
What we collect
Your workspace with us
Your name, your email address, your time zone, and a hashed password if you set one. If you joined the waitlist first, we hold the address and name you gave us there.
What you tell the assistant
Everything you type to it, and everything it says back. Also the things you ask it to remember, the preferences you set (writing style, whether it should draft replies, quiet hours, where you are based, how much travel time to leave), and any file you attach to a message.
What it reads in your Google accounts
Mail and calendar entries, as described in the next section. When the assistant reads a message, the message it read becomes part of the conversation, and the conversation is stored. This is the part people are usually surprised by, so it is set out in full under Where it is stored below.
A record of what ran
Every request to the model is written down with the time it happened, how long it took, how much usage it consumed and what it cost. That ledger holds no message content. Alongside it we keep a log of the actions the assistant took in your workspaces, and anything waiting for your approval — which includes the text of a draft it wants to send.
Ordinary technical records
Sign-in sessions record the IP address and the browser you signed in from. The server keeps normal web logs, with passwords, keys and sign-in credentials filtered out of them.
The Google permissions we ask for
You connect a Google account to Fylgja yourself, one per part of your working life, and Google shows you exactly what you are granting before you agree. Fylgja acts only through those connections and only in the accounts you have connected. Here is each permission and why it is there.
Your name, address and profile picture
email, profile — to know which Google account you just connected, to label it in the interface, and to sign you in.
Read and manage your Gmail
gmail.modify — to search your mail and read whole messages so it can tell you what needs you; to write drafts and send the ones you approve; to apply labels and archive what you have dealt with. This permission does not allow permanent deletion: anything the assistant removes from the inbox is archived or goes to the trash, where you can get it back.
Read and manage your calendar
calendar — to read your day and put it in the brief, to see conflicts and travel time, and to create or move events when you ask for one.
Google Docs that Fylgja itself created
drive.file — to write a long piece of work into a document and add to it later. This is the narrow Drive permission: it reaches only the files Fylgja made or that you handed to it. The rest of your Drive stays invisible to us.
Fylgja checks connected mailboxes on a schedule so a brief has something to say. It does not touch any Google workspace you have not connected, and it does not read the Google accounts of the people who write to you beyond the messages they sent you.
Google API Services Limited Use
Fylgja's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google Workspace user data and developer policy, including the Limited Use requirements.
In plain terms, four commitments, and what each one means here.
We use it only for the features you can see
Your mail and calendar are read to answer the question in front of you, to build your brief, to draft a reply, or to run a scheduled job you set up. There is no other use.
We do not pass it on
The only transfer is the one that makes the feature work: your conversation goes to Anthropic so that the model can answer. Beyond that we would transfer it only for security reasons, such as investigating abuse, or where the law requires it. If the company were ever sold we would ask you first.
Never for advertising, and never to train a model
We run no advertising and sell nothing to advertisers, data brokers or anyone else. We do not use your data to build, train or improve any model of ours. Anthropic states that it does not train its models on inputs or outputs from its API unless you give it feedback or otherwise agree.
People do not read it
Nobody at Loman Group reads your mail as a matter of course. We can reach the database, because it is our server, and we do look in three situations: when you ask us to help with something and agree to it, when we are investigating a fault or possible abuse, and where the law requires it. Automatic error reports sent to us when something breaks can carry a fragment of your data with them.
Where it is stored, and for how long
One server, in Virginia
Everything lives on a single server we rent from Hetzner in Ashburn, Virginia, in the United States. The database is a SQLite file on that machine. If you are outside the United States, connecting a workspace means your information is held there.
Encrypted: your keys and sign-in credentials
The credentials Google gives us when you connect a workspace, your Anthropic API key, and the credentials for any outside tool server you connect are encrypted before they are stored, and are unreadable in the database without our encryption key.
Also encrypted: the conversation, and what is in it
Your conversation with the assistant contains what it read while answering you, so the contents of the emails and calendar entries it looked at end up stored alongside it. Those are encrypted too: the messages, the text of any draft it wrote, anything waiting in your approval queue, the things it remembers about you, and the record of what each run did. All of it is unreadable in the database without our encryption key.
What that protects, plainly: a copy of the database taken off the server is unreadable, and so is a backup. What it does not protect against is someone who compromises the server itself, because the key is held there in order to do the work. The labels we use to find and count things are not encrypted: who a message belongs to, when it was written, which workspace it came from, and what a request cost.
How long we keep it
Not indefinitely, which is what it used to be. Once a day we clear text that has passed the period below. The rows themselves stay, so your history still reads as a list of conversations with their dates and titles; what goes is the writing inside them. Here is each thing and its period.
- — What it read in your mail and calendars: 7 days. The messages and entries it read back while answering you are copies of other people's writing, and by volume they are most of what we hold. They are cleared after a week whatever else you choose.
- — Your conversations: 90 days. What you typed, what it said back, and any file you attached — the file itself is deleted, not just the mention of it. You can set a different period, from a week to ten years, or ask for them to be kept with no expiry at all. That choice covers your own words; it does not extend the week above.
- — An email you send us: a week for the message itself, then only what you wrote. You can answer one of Fylgja's briefs by replying to it. The raw email arrives here whole — headers, your reply, and the brief quoted underneath it — and that copy is destroyed after seven days. What you actually wrote is kept as part of the conversation, on the period above, with the quoted brief cut off rather than stored a second time. The address a reply goes to is unique to that one conversation and stops working after thirty days, and answering by email can read and explain but cannot act on your workspaces.
- — What a piece of work you set going was told to do, and what it wrote: the same period as your conversations. This covers anything that runs on your behalf rather than in the chat — something on a schedule, or a longer job you started and left running. The instructions, the written result and the running notes it kept along the way all go, and so does the reference to any workspace it was given at Anthropic. That it ran, when, how long it took, what it was allowed to spend and what it actually cost stays.
- — Any code such a job wrote and ran, and the files you gave it: the same period as your conversations. A job running in a workspace can write a small program and run it there — to add up a spreadsheet you handed it, or convert a file — and we keep what it ran and what that produced so you can read them and check the answer for yourself. Both go on this clock, and so do the files themselves. What stays is that it ran something, which tool, whether it worked and how much it printed.
- — When it asked you for a tool it does not have: the same period as your conversations. If you ask for something it cannot do, it writes down what you wanted, why it could not, and any services it found that might. Some of that last part is copied off web pages it read while looking, which is the reason it does not sit here for ever. What stays is that it asked, when, and whether you connected anything or turned it down.
- — What an outside tool server says it offers: the same period as your conversations. A server you connect is asked, on a schedule, what it can do, and the list it gives back — the names and descriptions of its tools — is stored so that the assistant does not have to ask it again mid-sentence. It is written by whoever runs that server, and it is kept encrypted like everything else. Nothing of yours is in it, and it is rewritten every hour, so the clock only ever catches a listing for a server that has gone away.
- — A tool you told it to stop asking about: the same period as your conversations. When you answer an approval with “always”, what is written down is that one tool on that one server — not the server, so a tool it starts offering later still asks you. The name in it was written by whoever runs that server, which is why it travels on the same clock as the rest of what they told us. When it expires the tool simply asks you again. You can see the list, and take any of it back, on your connections page at any time.
- — Anything that waited for your approval: 7 days after it is decided or lapses. The text of the draft it wanted to send goes once it can no longer be sent. That you were asked, and what you answered, stays.
- — What it remembers about you, and your preferences: until you delete them. These are small, you can read all of them in the app, and you curate them yourself, so they are not cleared on a clock. Delete any of them in the settings.
- — The record of what each request cost: kept. It holds no message content at all — a time, a duration, a model name and an amount — and it is what your daily spending limit and your usage page are computed from. Trimming it would lose the cost history and protect nothing.
Internal job records are cleared after two weeks. None of this waits on a clock when you act yourself: deleting a conversation, a memory or a connected workspace removes it there and then.
Backups
The database is copied continuously to object storage in San Francisco, run by DigitalOcean. The copies are encrypted with a key we hold and the storage provider is not given, so they are unreadable to anyone who obtains the storage itself. They also carry the same encryption as the live database, so the content inside a restored copy still needs our key on top of that.
Deletion is the one place backups matter to you. When something passes its retention period, or you delete it yourself, it goes from the live database immediately. The replicated copy follows the database rather than piling up snapshots of it, but older restore points can still hold the deleted content for a short window before they age out. So "deleted" is immediate where it counts and takes a little longer to become absolute.
Who else receives it
A short list, and it is the whole list.
Anthropic — the model behind the assistant
Every answer is produced by Claude, so the instructions, the conversation and whatever the assistant just read are sent to the Anthropic API. When you have given us your own Anthropic API key, the request is made with your key, the usage is billed to your own Anthropic account, and your agreement with Anthropic governs it. Until you give us one, requests are made with ours. Anthropic states that it does not train its models on API inputs or outputs by default.
A longer job can be set to run inside a workspace Anthropic hosts rather than on our server. You choose that when you start the job, and it is not the default. When you do, what you asked it to do and whatever it gathers while working are held in a container at Anthropic for the length of the run, and the container and its record of the run are deleted when the run ends. Such a job has no access to your mail, calendar or documents — only a machine of its own and the open web.
When you start one of those jobs you can also hand it files to work on — a spreadsheet to add up, a document to convert — and it can write a small program and run it against them inside that machine. Those files are the only thing of yours it can open: it has no key, password or connection to any of your accounts, so there is nothing else of yours for the program it writes to reach. The files you hand it are uploaded to Anthropic, put into the container, deleted from Anthropic when the run ends, and set to expire there within an hour in case that deletion fails. We keep the program it wrote and what that program produced, on our own server, so that you can read them.
Google — your own accounts
Reading and writing happens through Google's APIs under the connection you granted. Mail the assistant sends is sent from your mailbox, by you, through Google.
Hetzner — the server
They host the machine. They do not use what is on it.
MailerSend — email we send you
Briefs, notifications and password resets are delivered to your own address through MailerSend, so the content of a brief passes through them. Fault reports we send ourselves go the same way.
Brave Search, and pages the assistant opens
When a question needs the web, the search terms go to Brave Search — the terms only, never your mail, though the assistant writes them and they can echo what you asked for. If it then opens a page, that website sees a request from our server.
Your browser's push service
If you turn on notifications, they are delivered through the push service your browser uses (Google, Mozilla or Apple, depending on the browser). The message is encrypted for your browser before it leaves us, so the push service relays it without being able to read it.
Any outside tool server you connect yourself
If you add one in the settings, whatever the assistant sends it goes to whoever runs it, under their terms and not ours.
There is no advertising, no third-party analytics, no tracking pixels and no marketing tools in Fylgja. We have never sold anyone's data and we are not going to.
What protects it
Only the things we actually do.
- — Google credentials, your Anthropic key and tool-server credentials are encrypted at rest with a key held outside the database.
- — Traffic to the site and to every service above runs over HTTPS.
- — Each connected workspace carries its own permission settings, and every action the assistant takes is checked against the settings for the workspace it would run in before it happens.
- — Anything not set to automatic waits in an approval queue for you. Mail to recipients outside the domains you have named is refused outright by default, and the preset briefs run with the writing and sending abilities removed altogether.
- — A daily spending limit stops the assistant making further requests once the day's usage reaches it, which also bounds how much can happen in a day if something goes wrong.
- — Everything it does in your accounts is written to a log you can read.
What we are not: certified against SOC 2, ISO 27001 or anything else. No independent auditor has looked at this. It is a small product on one server, run carefully, and you should weigh it as that.
What you can do about it
Disconnect a Google account
One button in the settings. The credentials we hold for that workspace are deleted immediately and Fylgja can no longer reach it. What it already read stays in your conversation history until that is deleted or expires as described above. You can also cut us off from Google's side at myaccount.google.com/permissions, and we would encourage it if you are leaving.
Choose how long it is kept
Ask the assistant for a different retention period, or set retention_days yourself on the preferences page: a whole number of days from 7 to 3650, or the word forever. Whatever you pick, what it read out of your mail is still cleared after a week.
Delete what it remembers
Memories, preferences and whole conversations can each be deleted individually in the settings, and deleting a conversation deletes the messages in it.
Delete a workspace
Deleting one of your accounts removes its Google connection, its memories, its preferences, its approvals and its activity log. Your chat history belongs to you rather than to any one workspace, so it is not removed by this — delete those conversations as well, or ask us.
Delete everything
There is no button for this yet. Write to privacy@fylgja.work and we will delete your user and everything attached to it. We will confirm when it is done.
Ask what we hold
Most of it is already visible to you in the app. For anything else, ask at the same address and we will tell you, correct it, or send you a copy.
A few last things
Not for children
Fylgja is for adults at work. It is not directed at children, we do not knowingly let anyone under 18 use it, and if we learn that a user is under 18 we will delete their data.
When this page changes
We will change the date at the top and, if the change matters — a new recipient of your data, a new permission, a new use — we will email you before it takes effect. The page is versioned in our source control, so the history is real.
Contact
privacy@fylgja.work for anything on this page. Our terms are at fylgja.work/terms.