Sub Umbra Privacy Policy
Sub Umbra is a private household assistant used by a single family. It is not offered to the public. This policy explains what it does with data from the family's Google account.
Google data accessed
- Gmail, read-only (
gmail.readonly). Sub Umbra cannot send, delete, label, or change email. - Google Calendar, read-only (
calendar.readonly). Sub Umbra cannot create or change events.
How it is used
- Sub Umbra looks only for two kinds of email: messages from the family's church community (OCDS) and transactional messages from services the household uses (order, pickup, delivery, prescription, billing, and account-security notices from retailers and the family's bank).
- Before acting on an email, it checks the sender's authentication (DKIM, SPF, and DMARC results).
- For matching emails it stores the sender, subject, date, category, and a short summary. Email bodies are read only to extract details such as a pickup window, and are not stored.
- Other email is not stored at all.
- Calendar events for the next two weeks (title, time, location) are stored to show the day's schedule.
- Results appear as notifications, suggested to-dos the family can accept or dismiss, and spoken answers through the family's private Alexa skill.
Where data lives
- All Google data is stored in a local database on the family's home computer. Sub Umbra has no cloud servers and no database elsewhere.
- Google sign-in credentials are kept in the computer's operating-system credential store (Windows Credential Manager).
Sharing
- Google data is not sold, rented, or used for advertising, and is not shared with anyone outside the household.
- One processor is used: summaries of OCDS community emails are generated by Anthropic's Claude model on the family's own Claude subscription. Questions the family chooses to ask “Claude” by voice may include household information. Anthropic processes this content under its own terms; Sub Umbra does not send Google data anywhere else.
- Sub Umbra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
- Data stays in the local database until the family deletes it. Local backups are kept for 30 days.
- Access can be revoked at any time at myaccount.google.com/permissions. After that, Sub Umbra can no longer read Gmail or Calendar.