Personal Assistant

Privacy Policy

Last updated September 17, 2026

Who we are

This policy describes how Personal Assistant (“we”, “us”), the service at www.pragyan.ca also known as Pragyan, handles information when you use the product.

Questions about privacy: shamikroy2001@gmail.com.

What the service does

Personal Assistant is a SaaS product. You sign in, name your assistant, spend assistant credits when you ask, and may connect tools so the assistant can help with mail, calendars, websites, and messages you choose.

Depending on what you enable, the product can:

  • Read Gmail on your behalf (read-only) and prepare summaries you asked for
  • Read Calendar events (read-only) when you connect Calendar
  • Send Telegram messages to a chat you connect
  • Watch websites you list and notice when a page changes
  • Use AI to reply to your asks and to summarize connected content

Gmail send, draft, label, archive, trash, and modify are not enabled. We do not request those Google scopes.

Information we collect

Account. Sign-in is handled by Clerk. We store your Clerk user id, email, plan, trial dates, and account status so we can run the product.

Assistant profile. Name, personality, response style, timezone, and language that you set.

Asks and tasks. The text you send, replies we return, status, and credit amounts charged. Scheduled jobs store the cadence and payload you configure.

Credits and billing. A ledger of assistant credits (trial, monthly, rollover, and any access-code grants). If you subscribe, Stripe may process payment details. We do not store full card numbers. Paid checkout is only used when billing is turned on for the environment.

Gmail (when you connect it). We request Google OAuth scopes gmail.readonly, openid, and email. We store OAuth access and refresh tokens encrypted on the server, plus the Google account email as a label. When a read or summary job runs, we retrieve message metadata and content from Google as needed to complete that job. We do not keep a full mailbox copy as a primary archive. Summaries and short attention items derived from mail may be stored in your account so you can see them in the app.

Calendar (optional). If you connect Calendar, we request calendar.events.readonly plus openid/email, store encrypted tokens on the server, and may list events or propose (not write) changes. We do not request calendar write scopes.

Telegram (optional). We store an encrypted chat identifier for the chat you connect. The bot credential stays on our servers, not in the browser.

Website monitoring. URLs you add, a hash used to detect change, and check timestamps. We fetch those pages on a schedule. We may store a short notice when a change is found.

Attention and notices. Titles, summaries, and status for items the product thinks are worth a look (for example a site change or a mail summary).

Logs and audit. We keep operational logs and an audit trail of external actions (connect, disconnect, proposed calendar actions). Logs are written without OAuth tokens, API keys, or raw email bodies.

How we use information

We use this information to:

  • Provide the assistant, credits, connections, and monitoring you asked for
  • Authenticate you (via Clerk) and keep accounts isolated from each other
  • Process asks and generate mail or site summaries with AI processors
  • Charge assistant credits and, when enabled, handle subscriptions
  • Secure the service, debug failures, and comply with law

We do not sell personal data. We do not use Gmail or Calendar content to serve ads.

Google user data and Limited Use

Google user data (Gmail and, if connected, Calendar) is used only to provide or improve user-facing features in Personal Assistant: reading mail you asked us to read, preparing summaries and attention items, listing events, and showing connection status. It is not used for advertising, credit scoring, or sale to data brokers.

We do not allow humans to read Google user data unless you give affirmative consent for specific messages, it is necessary to investigate abuse or security, we must comply with law, or the data is aggregated and de-identified for internal operations.

Personal Assistant's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we share information

We share data with processors only as needed to run the product:

  • Clerk, for sign-in and session
  • Google, when you connect Gmail or Calendar (OAuth and the APIs those scopes allow)
  • Our hosting and database providers (the web app, API, workers, and encrypted storage)
  • AI processors, with the prompt or connected content needed to complete a request
  • Stripe, if you start a paid subscription when billing is enabled
  • Telegram, if you connect a chat and we send a message you configured

We may disclose information if required by law or to protect the service and its users. We do not sell personal data, and we do not transfer Google user data except as needed to provide these features, for security, to comply with law, or as part of a merger or sale of the service with notice.

Storage and security

OAuth tokens for Gmail and Calendar are stored encrypted on the server. They are not returned to the browser or shown in the app. Telegram chat identifiers are stored encrypted. Credentials are never displayed on the Connections screen.

Accounts are tenant-isolated. We use industry-standard transport encryption (HTTPS). This policy does not claim a particular third-party audit or certification.

Retention

We keep account, profile, task, credit, and notice data while your account is open and as needed for billing, security, and legal records.

Encrypted Google tokens are kept only while the connection is active. Disconnecting Gmail or Calendar revokes the Google token (when Google accepts the revoke) and clears stored credentials for that connection. Telegram disconnect clears the stored chat identifier.

Summaries and attention items derived from mail or sites may remain until you dismiss them or we delete the account. Website monitors keep the URL and change hash until you remove the monitor.

Your choices

You can disconnect Gmail, Calendar, or Telegram from Connections at any time. You can remove website monitors you added. You can change assistant profile fields in the app.

The app does not currently offer a one-click export of all stored data or a full self-serve account deletion screen. To request deletion of your account and stored personal data (including Google tokens and derived summaries), email shamikroy2001@gmail.com. We will disconnect Google connections and delete or de-identify account data we control, except records we must keep for security, billing, or law.

You can also revoke Google access in your Google Account permissions. That stops new API access; please also disconnect in the app so we can delete stored tokens.

Children

The service is not directed at children under 13, and we do not knowingly collect personal information from them.

Changes

We may update this policy. The “Last updated” date at the top will change. Material changes will be reflected on this page at www.pragyan.ca/privacy.

Contact

Privacy questions and deletion requests: shamikroy2001@gmail.com.