TARSPersonal assistant

App information

TARS privacy policy

Prepared 29 September 2026. Effective when these pages are published.

TARS is operated by its owner for personal use. This policy explains how its current Google connection works. For privacy or access questions, use the support contact shown on TARS's Google consent screen.

What TARS accesses and why

The owner authorizes Google accounts using Google's sign-in and consent screens. TARS requests Gmail read-only permission and, for the primary account, Calendar read-only permission. It uses this information to help the owner review commitments, understand their schedule and prepare plans or drafts.

Reads are requested by the owner. The owner can choose a five-item sample or a complete read within a defined date range. Gmail reads cover selected INBOX messages from the past 30 days, including subject, sender, recipient, date, message text, labels and thread identifier. Other replies in a conversation may fall outside the INBOX or date range and are not included; attachments are not downloaded. Calendar reads cover primary-calendar events overlapping seven days ago through 21 days ahead, including event title, dates, timezone, description and recurrence details. Attendee lists and locations are not imported.

Complete date-range reads follow all pages and check for source changes. They stop without replacing the previous records if a page fails, the source changes during the read, or the configured limit of 500 records, 8 MB or the work deadline is reached. Successful reads replace the prior selected snapshot, so items removed from that source or outside the new window leave active account records. Failed or stale records remain visible to the owner but are excluded from model context. Exact coverage and read time are shown in the private workspace. Automatic polling is off.

TARS masks detected credential-like text before importing email records. Affected fields are visibly marked and are not verbatim copies; the original remains unchanged in Gmail for owner review. The detector is conservative and may mask harmless text, and it does not guarantee detection of every secret. Missing pages and failed reads are still failures, not masked successes.

Storage and access

After the owner approves AWS storage, imported records are stored in the owner's restricted TARS workspace on AWS. Google authorization credentials are kept separately from the assistant's model runtime. Google network requests use HTTPS. Encrypted backups of the workspace are copied to the owner's Mac Mini and checked through a locked restore process.

Hermes holds the assistant's confirmed memory. Imported account text is evidence, not an instruction or permission. A proposed memory is not confirmed until the owner reviews it.

AI processing and sharing

Google records are excluded from OpenAI by default. The owner can explicitly allow a source for cloud processing, select its records and approve a turn. Only permitted context is made available for that OpenAI request. Prior conversation context may include information already approved in earlier turns; the owner can exclude that history. OpenAI processing is subject to the connected account's applicable terms and data settings.

TARS does not sell Google data, use it for advertising, or train a general-purpose AI model with it. TARS handles Google data according to the Google API Services User Data Policy, including its Limited Use requirements. External sharing is limited to providers needed for the owner-approved features described here, such as AWS storage and explicitly permitted OpenAI processing.

The public information pages use Vercel hosting. They contain only the app description, this policy and terms. They do not display personal email addresses, email content, calendar events, assistant conversations or memory. There are no analytics scripts, advertising, sign-in forms or tracking cookies added by TARS on these pages.

Vercel processes website request information, including IP addresses, device information and approximate location, to deliver and protect the site and operate its services. Its infrastructure may process information outside the visitor's country. See Vercel's privacy notice and data processing terms. This policy does not promise a fixed deletion period for Vercel's operational records. Website hosting is separate from the private assistant's account storage on AWS.

Retention, correction and deletion

Disconnecting an account removes its active imported records from TARS. It does not automatically revoke Google's authorization, erase previous conversation text or erase encrypted backup copies. The owner can also remove TARS's authorization in the Google Account's third-party access controls.

The owner can correct or forget confirmed Hermes memories. Forgetting removes a memory from active recall and its native memory files; it does not erase earlier conversations or old backups. Historical conversations remain stored until separately removed by the owner. Failed or stale account reads are excluded from model context even when prior records remain visible for owner inspection.

Scheduled backups retain 30 days relative to the newest snapshot and keep at least the last two snapshots. Retention advances when backups run successfully; an outage can leave older copies in place longer. The Mac Mini retains its last verified archive until a replacement succeeds. A request to erase historical copies therefore requires separate owner maintenance; disconnecting alone is not a claim of complete historical erasure.

Changes and contact

These disclosures must be updated before materially changing collection, processing or sharing. The owner can review source access in TARS. Questions about correction, disconnection or historical deletion can be directed to the support contact shown on TARS's Google consent screen.