Privacy Policy
Effective July 31, 2026
MarnieOS is a personal assistant that reads your calendar and email to keep track of your schedule and your subscriptions. That means it handles genuinely personal information. This policy explains exactly what is collected, what it is used for, who else sees it, and how to get rid of it. It is written to be read, not to be skimmed past.
1. Who we are
MarnieOS (“we”, “us”, the “Service”) is operated by Blaine White, a sole proprietor located in Minnesota, United States. For the purposes of data protection law, we are the controller of the personal data described in this policy.
Questions, requests, or complaints: support@marnieos.com
2. What we collect
Everything below is either something you typed, something you explicitly connected, or something generated by your use of the Service. We do not buy personal data, and we do not track you across other websites.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address and authentication credentials. | You, at sign-up. Credentials are handled by our authentication provider — we never see or store your password. |
| Profile | Name, occupation, life stage, wake/sleep and working hours, weekend structure, communication and tone preferences, timezone, home ownership, household members, assistant name and personality, reminder and briefing preferences, topics to avoid. | You, during onboarding and in Profile settings. |
| Health & fitness | Workout location and equipment, fitness goals and level, physical limitations, eating style, dietary restrictions, meal planning and cooking style, and any workouts you log. | You, optionally. This section can be left blank. |
| Work | Work status, industry, tools you use, description of a productive day, biggest work challenges, recurring tasks. | You, optionally. |
| Calendar & events | Event titles, dates, types, and notes. | You, and — if you connect a calendar — your Google, Outlook, or Apple calendar. |
| Contracts & subscriptions | Service name, provider, category, renewal date, monthly cost, notes, and whether you have marked it paid. | You, and — if you connect Gmail — subscription details extracted from your email (see section 3). |
| Birthdays | Names, relationships, and dates of people you ask us to remind you about. | You. Note this is information about other people; see section 8. |
| Conversations | The messages you exchange with the assistant. | You, by using chat or voice. |
| Memories | Short factual statements the assistant derives from your conversations so it can remember context between sessions — for example a stated preference, goal, or habit. Includes numeric embeddings of those statements used for search. | Generated automatically from your conversations. You can view and delete these at any time. |
| Billing | Subscription status, plan tier, trial dates, and identifiers issued by our payment processor. | Our payment processor. We never receive or store your full card number. |
| Technical & usage | Request counts and timestamps used for rate limiting and cost control, and push notification subscription details if you enable notifications. | Generated by your use of the Service. |
A note on sensitive information. The health and fitness section, and anything you happen to mention in conversation, can amount to information about your health, habits, or household. The assistant is designed to remember statements of that kind when you make them, because that is what makes it useful. If you would rather it did not, do not enter it — and see section 7 for how to have a memory removed.
3. Google Calendar and Gmail
Connecting a Google account is entirely optional and can be withdrawn at any time. If you do connect one, we request read-only access and nothing more. We cannot send email, delete anything, or modify your calendar.
| Permission | Why we ask for it | What we do with it |
|---|---|---|
| calendar.readonly | To show your schedule in your dashboard and daily briefing. | Events from the calendars you select are copied into your account so they can be displayed and referenced. Disconnecting removes them. |
| gmail.readonly | To find recurring subscriptions and renewals you may have forgotten about. | See directly below — this one deserves detail. |
How the Gmail scan actually works
This is the most invasive permission the Service asks for, so here is precisely what happens when you run a subscription scan:
- We retrieve only the subject line, sender, date, and the short preview snippet of matching messages. We do not request, receive, or store the body of your emails.
- Those summaries are held in memory for the duration of the scan only. They are never written to our database.
- They are sent to our AI provider to identify subscriptions. The only thing saved afterwards is the extracted subscription record — service name, provider, category, cost, renewal date, and a confidence score.
- Attachments are never downloaded. Contacts are never harvested. Nothing is read for advertising, and there is no advertising in this product.
Limited Use disclosure
Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data for advertising; we do not sell it; we do not transfer it to others except as needed to provide or improve this Service, to comply with law, or as part of a merger or acquisition; and no human reads it except with your explicit permission, for security purposes, or where required by law.
You can disconnect either integration from Profile at any time, which deletes our stored access tokens. You can also revoke access directly from your Google account permissions page.
4. What we use it for
Your data is used to operate the Service you signed up for, and for nothing else:
- To generate your daily briefing, reminders, and assistant responses.
- To let the assistant remember context about you between conversations.
- To find and track your subscriptions and warn you before they renew.
- To display your calendar and send notifications you have asked for.
- To process your subscription payment and manage your trial.
- To keep the Service running — rate limiting, cost control, debugging, and preventing abuse.
We do not sell your personal data. We do not share it with advertisers. There is no advertising in this product. We do not use your data to build profiles for anyone other than you.
On AI training: we do not train any model on your data. Your content is sent to the AI providers listed below purely to generate a response to you. Those providers state that data submitted through their business APIs is not used to train their models. We rely on their commitments here and cannot independently guarantee their internal practices.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | Kept while your account is open. |
| Conversations and memories | Kept while your account is open. Older memories are periodically condensed into summaries and the originals retired. To remove a specific memory, see section 7. |
| Calendar and Gmail access tokens | Deleted immediately when you disconnect the integration or request account deletion — not after any delay. |
| Events synced from a calendar | Deleted when you disconnect that calendar. |
| Everything, on account deletion | Retained for 30 days, then permanently erased. See below. |
| Billing records | Retained by our payment processor as required by tax and financial regulations, independently of your account. |
The 30-day window. When you delete your account we mark it and stop using it, but we do not erase it immediately — accidental deletion is common and irreversible deletion is unforgiving. For 30 days you can sign back in and restore everything. After 30 days an automated job permanently deletes your account and every record attached to it, and at that point we cannot recover it for you.
Two things do not wait for that window: your Google tokens are revoked and destroyed the moment you request deletion, and any active subscription is set to stop renewing straight away.
7. Your rights and how to use them
You can do all of the following yourself, without emailing anyone:
| Right | How |
|---|---|
| Access a copy of your data | Profile → Data & Account → Download my data. Returns everything we hold about you as a JSON file. |
| Correct your information | Profile → edit any field. |
| Delete specific memories | Email us and we will remove any individual memory you identify. Your full list of memories is included in the data export above. (Self-service removal is not yet built.) |
| Withdraw integration access | Profile → disconnect Google Calendar, Outlook, Apple Calendar, or Gmail. |
| Delete your account entirely | Profile → Data & Account → Delete my account. |
| Turn off notifications | Revoke notification permission for this site in your browser settings. You can also change what the daily briefing contains under Profile → Morning Briefing. |
Depending on where you live you may also have the right to object to or restrict certain processing, to receive your data in a portable format (the export above satisfies this), and to lodge a complaint with your data protection authority. California residents have the right to know, delete, correct, and to opt out of sale or sharing — we do not sell or share personal data as those terms are defined under the CCPA, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
To exercise anything not covered by a button above, email support@marnieos.com. We will respond within 30 days.
8. Information about other people
Some of what you enter is about other people — birthdays, household members, names that come up in conversation, senders of your email. You are responsible for the information you choose to add about others, and you should only add what they would reasonably expect you to. We use it solely to provide the Service to you, we never contact those people, and it is deleted along with your account.
9. Security
Concretely, what protects your data:
- All traffic is encrypted in transit with TLS.
- Every table enforces row-level security at the database, so one account cannot read another’s rows even if the application had a bug.
- OAuth tokens are encrypted before they are stored.
- Passwords are handled entirely by our authentication provider and are never visible to us.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data we will notify you and any required authority without undue delay.
10. Children
The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us personal data, email support@marnieos.com and we will delete it.
11. Changes to this policy
If we change this policy we will update the effective date above. For any change that materially affects how your data is used — a new category of data, a new purpose, a new provider receiving it — we will notify you in the app or by email before it takes effect, rather than quietly editing this page.
12. Contact
Blaine White, a sole proprietor located in Minnesota, United States
support@marnieos.com