Alfred Chief of Staff

Privacy Policy

Last updated July 19, 2026.

1. Who we are

Alfred Chief of Staff (“Alfred,” “we,” “us”) is an AI Chief-of-Staff product operated by Albaro Xiloj. We provide a personal assistant that delivers briefings, surfaces calendar context, triages your inbox, and remembers what you have asked it to remember.

Contact for any privacy question or request: albaroxiloj@icloud.com.

2. What we collect

When you create an account, we collect your email address, the name and persona configuration you choose for your assistant, and any conversations you have with it. We do not ask for payment information directly — subscriptions are handled by Stripe.

If you choose to connect Google Calendar, we additionally request the calendar.readonly OAuth scope. With your explicit consent, we receive: the email address of the connected Google account; event titles, descriptions, times, locations, attendees, organisers, and your own response status for events on your calendar; and a refresh token that lets us read your calendar on a recurring basis while you remain connected.

We do not have, request, or use any write access to your Google Calendar. We cannot create, modify, or delete events on your behalf.

If you choose to connect Gmail, we request the gmail.readonly and gmail.compose OAuth scopes. With your explicit consent, we receive, for messages in your inbox: the sender's name and email address, the subject line, the short preview snippet Gmail itself generates, the message's labels (such as whether it is unread), and the date — together with a refresh token that lets us read your inbox on a recurring basis while you remain connected. We never receive, request, store, or process the full body of any email.

The gmail.compose scope lets Alfred prepare drafts and, with your explicit approval, send email on your behalf. When you ask Alfred to draft a message, it creates a draft in your Gmail for your review and does not send it. When you ask Alfred to send a message, it does not send right away: it prepares the email and shows you a confirmation prompt, and the message is sent only after you explicitly approve that specific email. Alfred cannot send email on its own — every send requires a per-message human approval, is authorized by a single-use, server-issued confirmation token, and is recorded in an internal audit log. Google does not offer a draft-only Gmail scope; gmail.compose is the narrowest scope that permits both preparing drafts and sending.

3. How we use it

We use the data you provide to deliver the product: composing your briefings, surfacing your day in the dashboard, classifying events by the venture or context they belong to so your briefing reads naturally, and powering semantic recall of past conversations and calendar context.

For your inbox, we use the message details described above to triage new mail — deciding which messages likely need your personal attention — and to summarise what is waiting for you in your briefings and when you ask about your inbox in conversation. When you ask Alfred to reply to someone, we use the compose scope to prepare a draft in your Gmail for your review, or — if you ask Alfred to send — to send the message after you approve a confirmation prompt for that specific email.

We do not use your data for advertising. We do not sell your data. We do not use your calendar contents to train any third-party model. We do not aggregate or profile across users.

4. Google API Services — Limited Use Disclosure

Alfred Chief of Staff's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: data received from Google APIs is used only to provide user-facing features of Alfred Chief of Staff. We do not transfer this data to third parties except as necessary to provide and improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to affected users. We do not use the data for serving advertisements. We do not allow humans to read the data unless we have your affirmative agreement for specific messages, we need to for security purposes (e.g. investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in line with applicable privacy laws.

5. Storage and encryption

OAuth tokens (the credentials that let us read your calendar) are encrypted at rest using AES-256-GCM with a key held only by our servers. Each token is additionally bound to your user identifier so that a token blob taken from one user's record cannot be re-used against another's.

Calendar events and inbox message details (sender, subject, preview snippet, labels, and date — never message bodies) are cached in our database, isolated by row-level security so that each row is readable only to the user it belongs to. The database is hosted on Supabase, which provides encryption in transit (TLS 1.3) and at rest. All communication with our services is over HTTPS.

6. Retention

We retain your account data, conversations, and the calendar event and inbox message caches for as long as you maintain an active account. The calendar cache holds a rolling window of events — roughly the previous week and the next four weeks — and the inbox cache holds recent message details; both are refreshed continuously while you remain connected.

On disconnect or account deletion (see section 7), all calendar events and tokens are removed within 24 hours.

7. Deletion and your control

You can disconnect Google Calendar or Gmail at any time from Settings → Integrations. Disconnecting a service deletes its encrypted tokens from our database and removes the data cached from it — for Calendar, every cached event and every memory derived from it; for Gmail, every cached message detail. Because all Google services share a single authorisation grant, disconnecting your last connected Google service also revokes that grant at Google, so we can no longer access any of your Google data even if we wanted to.

You can delete your entire account from Settings → Account. Account deletion is irreversible and removes all personas, conversations, memories, integrations, and cached data tied to your account.

You can also revoke our access from your Google account directly at myaccount.google.com/permissions. When you do this, our next sync attempt will fail, we will mark the integration as revoked, and the cached calendar will be cleared.

8. Third-party processors

We use the following processors to deliver the product. Each receives only the data necessary to perform its specific function.

  • Supabase — database and authentication. Stores all account data, conversations, memories, and the encrypted token / cached calendar tables described above.
  • Vercel — hosts the web dashboard. Sees request URLs and standard server logs; does not persist application data.
  • Anthropic and OpenAI — language model providers used to generate briefings, triage your inbox, draft replies in conversation, and produce embeddings for semantic memory. Your prompts, recalled context, and — when triaging mail — the sender, subject, and preview snippet of messages (never full bodies) are sent to these providers for the duration of a request. Per their terms, neither provider trains models on API requests by default.
  • ElevenLabs — text-to-speech for spoken briefings and replies. Receives the text being spoken but not your account or calendar data.
  • Stripe — payment processing for paid subscriptions. Receives your billing email and payment information directly; we do not see or store card numbers.
  • Google — the source of your calendar and inbox data, on the OAuth scopes you explicitly grant.

9. Changes to this policy

We will update this policy as the product changes. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated in-app and by email before they take effect.

10. Contact

For any privacy question, deletion request, or to report a concern, email albaroxiloj@icloud.com.