Masol Family Assistant · Effective September 14, 2026
This Privacy Policy describes how the Masol Family Assistant ("the Assistant") accesses, uses, stores, and shares information obtained from the Google APIs and the Oura API. The Assistant is a private, self-hosted tool operated by the Masol family for personal household use. It is not offered to the public and has no commercial purpose.
When an individual connects their own Google Account to the Assistant, and only then, the Assistant may access the following categories of Google user data belonging to that individual, using these Google OAuth scopes:
gmail.readonly, gmail.modify, gmail.send —
read incoming email, apply labels, prepare drafts, and send messages when directed.calendar — read calendars and create or update events and reminders.drive — locate, read, and organize files stored in the user's own Drive.spreadsheets — read and update the user's own spreadsheets.documents — read and update the user's own documents.contacts — read the user's contacts in order to address messages correctly.The Assistant accesses only the Google Account of the person who explicitly granted access. It cannot access any other Google Account.
When an individual connects their own Oura account to the Assistant, and only then, the Assistant may access the following categories of that individual's Oura data, using these Oura OAuth scopes:
daily — daily summaries of sleep, activity, and readiness.heartrate — heart rate and heart-rate variability measurements recorded by the ring.workout — summaries of auto-detected and user-entered workouts.session — guided and unguided sessions recorded in the Oura app.stress — daily stress and recovery summaries.
The Assistant accesses only the Oura account of the person who explicitly granted access.
It cannot access the Oura data of any other person, and it does not access or request the
personal scope (which contains height, weight, age, and gender).
Data obtained through Google and Oura is used solely to provide the Assistant's features to the account owner who granted access — that is, to brief them on their email, help them draft and send correspondence, manage their calendar, maintain their own lists and documents, and summarize their own sleep, recovery, and activity data.
Data obtained through Google and Oura is not used for advertising, is not sold, and is not used to train or improve generalized artificial intelligence or machine learning models.
The Assistant runs on a private home server controlled by the Masol family. Data retrieved from Google and Oura is stored locally on that server, including conversation history used to maintain continuity for the account owner. OAuth access and refresh tokens are stored locally on that server and are protected by operating-system file permissions and file-access restrictions. Data is transmitted to and from Google and Oura over encrypted connections (HTTPS/TLS).
Data obtained through Google and Oura is not shared with third parties for advertising, marketing, or any unrelated purpose. Two limited exceptions apply, and both exist only to operate the Assistant's features:
The Assistant does not transfer data obtained through Google or Oura to third parties for purposes unrelated to providing its features, and does not transfer such data to third parties for advertising, selling, or re-targeting.
The Assistant's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Health data obtained through the Oura API is treated as sensitive personal information and is subject to the following additional commitments:
Data retrieved from Google and Oura is retained locally only as long as it is useful for providing the Assistant's features to the account owner, and is removed from the local data store on request. The account owner may revoke the Assistant's access at any time from their Google Account permissions page (myaccount.google.com/permissions) or from their Oura account settings. Revoking access immediately prevents any further access to that account's data.
To request deletion of locally stored data, contact the address below and the request will be honored promptly.
Access is limited to the account owner and the operator of the home server. Credentials, tokens, and client secrets are stored with restricted file permissions. The Assistant never sends email or makes changes to a connected account without the account owner's direction.
The Assistant is intended for use by adult members of the household and is not directed to children.
This policy may be updated to reflect changes in how the Assistant operates. Material changes will be reflected by a revised effective date on this page.
Questions about this Privacy Policy, or requests regarding stored data, may be directed to wmasol@gmail.com.