Privacy
Privacy is part of N.I.A., not legal decoration. This page is plain English on purpose.
What we don't do
- We do not sell your data.
- We do not show advertising or build advertising profiles.
- We do not use your data to train AI models.
- We do not log the content of your AI prompts, your message drafts, your calendar event titles, or your check-in notes.
What we store
- Your email and Google account ID, so we can sign you in.
- Your OpenAI API key, encrypted at rest with AWS KMS, used only for your requests.
- Your Google Calendar OAuth refresh token, encrypted at rest, used only to fetch your calendar (read-only).
- Your tasks, classifications, daily plans, and check-ins — stored to make N.I.A. work.
Your OpenAI key
You bring your own OpenAI API key. We encrypt it before saving. After saving we never display it back; only the last four characters are visible. We decrypt it only at the moment your request is sent to OpenAI, and we drop the plaintext from memory immediately after. We never use your key to serve another user.
ChatGPT subscriptions do not pay for API usage in N.I.A. A ChatGPT Plus, Pro, or Team subscription does not cover OpenAI API calls made from N.I.A.. To use OpenAI here, you need an OpenAI API key, and OpenAI may bill API usage to your OpenAI account. N.I.A. is not responsible for third-party provider billing, policy changes, or data processing.
OpenAI's privacy policy applies to how OpenAI handles the request itself; we link to it from inside N.I.A. and cannot speak for them. As of writing, OpenAI's API terms forbid them from training models on API content.
Optional Google & Microsoft integrations
Signing in with Google grants only identity scopes (name, email, profile picture) — exactly what's needed to log you in. No calendar, no Gmail, no Drive, no contacts. Nothing read from your Google account beyond identity.
If you choose to connect Google services (Gmail starred messages → task suggestions, Google Calendar events → calendar view) or Microsoft services (Outlook Calendar only — N.I.A. does not request access to Outlook mail), N.I.A. will open a separate consent screen. Each scope is granted explicitly. The OAuth refresh token returned by Google/Microsoft is encrypted at rest with AWS KMS (key alias alias/nia-oauth-tokens) and decrypted only at the moment a call to Gmail / Calendar is made on your behalf.
Read-only across the board. N.I.A. never sends mail, never modifies a calendar event, never marks anything read. We list flagged or starred items and offer them as task drafts that you decide whether to import.
Revoke either integration at any time: Disconnect inside N.I.A. → Settings → Google services / Microsoft, or at myaccount.google.com/permissions for Google / account.microsoft.com/consent for Microsoft. Disconnecting removes the encrypted refresh token from our database.
Future AI providers
N.I.A. may add support for additional AI providers (e.g., Google Gemini) in the future. Some providers offer a free tier. Free-tier use may involve your prompts, responses, or related content being processed by that provider and potentially used to improve their products, depending on the provider's then-current terms. If we add a free-tier option, it will be opt-in, the privacy tradeoff will be shown explicitly, and you will have to acknowledge it before enabling it. N.I.A. does not control any third-party provider's data practices, retention, billing, or policy changes.
Your calendar
We request read-only access to your Google Calendar. N.I.A. never writes, modifies, deletes, declines, or reschedules anything on your Google Calendar. If you mark a recovery block in N.I.A., your colleagues will still see you as available in their Google view. That's intentional. N.I.A. manages your view of your day, not theirs.
Logging
We use AWS CloudWatch for operational logs. We never log: your OpenAI key, your Google tokens, the content of your AI prompts, the content of your message drafts, the content of your check-in notes, calendar event titles or descriptions, or any of your free-text input. We log: which user made which request, when, how long it took, and whether it succeeded.
Logs are retained for 30 days, then deleted automatically.
Deleting your account
Settings → Delete account. One click, two confirmations, and we erase: your profile, your encrypted OpenAI key, your encrypted Google refresh token, your calendar cache, your tasks, your daily plans, your check-ins, your draft messages, and your audit log entries. We also revoke your Google OAuth token with Google. The only thing that survives is a counter that increases by one, with no identifier. There is no soft delete and no grace period.
Sharing
N.I.A. does not have any sharing feature in this version. The data model is built so we can add it later — for example, letting a trusted person see your calendar status without seeing details — but no UI exposes that today. When sharing is built, every shared view will be auditable, granular, and revocable. Sharing will always require your explicit, deliberate confirmation.
What N.I.A. is not
N.I.A. is not therapy. N.I.A. is not a crisis service. N.I.A. is not a medical device. If you are in danger or thinking about harming yourself, please go to our safety page for real human help.
Contact
Operated by Luca Intini. Until N.I.A. has a real support address, reach the operator at the same email used for the Terms of Service contact line.
Last updated: 2026-05-06.
