Privacy policy

How NanoClaw handles your data

Last updated 8 September 2026

This policy covers the NanoClaw installation operated by Jan Bartůněk, which authenticates through the Google OAuth client named NanoClaw.

Who operates this application

Jan Bartůněk, Czech Republic. Contact: jan@bartunek.dev.

NanoClaw is self-hosted software. This installation runs on hardware operated by me, and the only person whose Google account is connected to it is me. It is not offered as a hosted service, and it does not have other users. Where I install NanoClaw for someone else, that installation runs on their own machine, under their own Google Cloud project and their own OAuth client, and is not covered by this policy.

What Google data this application accesses

Only the permissions listed here are requested, and each one exists for the feature named beside it.

Signing in also uses Google's basic identity permissions (openid, email address, and profile name), solely to confirm which account is connected.

Mailboxes held with providers other than Google are accessed over IMAP using a mailbox-specific password, which is a separate arrangement between that mail provider and the operator, and is not covered by any Google permission.

How the data is used

Mail, calendar, and task data is used for one purpose: producing the daily briefing and answering questions the operator asks the assistant in chat. It is not used for advertising, profiling, resale, or any purpose unrelated to those features.

Where it is processed and stored

Processing happens on self-hosted hardware in the Czech Republic. Conversation history and the briefings produced from it are stored locally in files and databases on that machine. Access tokens are held in a local credential vault on the same machine and are supplied to the software per request; they are never written into chat messages or into the assistant's prompt.

To produce a briefing, the relevant content is sent to Anthropic's Claude API, which generates the summary. That is a transfer to a third-party processor and is disclosed here for that reason. No other third party receives this data.

What is shared

Nothing. Google user data obtained through this application is not sold, rented, published, shared with advertisers or data brokers, or used to train machine-learning models. The only outbound transfer is the one named above.

How long it is kept

Calendar and task data is fetched when a briefing runs or when a question is asked, and is not stored as a separate copy beyond the conversation record it appears in. Conversation records persist on the operator's machine until deleted, and are deleted on request. Nothing is retained after access is revoked.

How to revoke access

Access can be withdrawn at any time from the Google Account permissions page at myaccount.google.com/permissions. Revoking it stops all further access immediately. To have stored conversation records deleted as well, write to jan@bartunek.dev and they will be removed.

Security

Each agent runs in an isolated container with its own workspace and its own credential set, so one agent cannot read another's data or use another's tokens. Credentials are stored in a local vault rather than in configuration files or environment variables, and are injected per request.

Limited Use

NanoClaw's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Changes to this policy

If the permissions requested or the way data is handled change, this page is updated and the date at the top changes with it.