Privacy policy
Your accounts.
Your control.
Effective September 21, 2026. This policy describes the personal-use Chelsea assistant and this public information website.
Information accessed
With explicit Google authorization, Chelsea accesses Gmail message metadata and message contents, and Google Calendar events. She uses Gmail sending permission to send an email only after the owner approves its exact contents and recipient. OAuth credentials let the application access these services; Chelsea does not ask for the owner's Google password.
How information is used
Account data is used to answer the owner's requests, summarize email, prepare calendar and email briefings, identify important unread messages and prepare replies. Email monitoring is limited to configured searches and does not guarantee detection of every important message.
Storage and processing
The assistant processes summaries using a local AI model on the owner's Mac. OAuth credentials, saved chats, briefing summaries and monitoring state are stored on that Mac. Local backups may contain these records. Connected devices access the private assistant through an authenticated connection. No Gmail or Calendar contents are collected by this public website.
Sharing
Google receives API requests needed to read authorized data and send approved emails. Approved outgoing email is delivered to the selected recipients. Optional phone alerts use ntfy and the device's push infrastructure; the configured alerts contain only generic update notices, without email contents, subjects, senders or calendar details. The private remote connection uses Tailscale. Website hosting providers may process ordinary request metadata such as IP addresses for delivery and security.
Google user data is not sold, used for advertising, or used to train general-purpose AI models. Chelsea's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Saved chats and briefings remain until the owner deletes them. The monitor retains a bounded list of recently observed message IDs to prevent duplicate alerts. Credentials remain locally until removed or replaced. Revoking Google access stops future authorized API access but does not erase already saved local chats, backups or emails previously sent. The owner can delete local records and backups through the Mac's application storage.
Choice and access
The owner can stop the background worker, disable notifications and revoke access through Google Account connections. This is an owner-operated personal application, not a service offered to other users. Privacy questions and deletion requests are handled by the owner through the support email displayed on Chelsea's Google consent screen.
Changes
This policy will be updated if Chelsea's data access, storage or sharing practices change.