Privacy

Conrad has one user, and this describes what happens to that user's data.

What it accesses

Conrad requests exactly one Google permission, gmail.metadata, against a single Gmail account belonging to its operator. That permission grants the sender, subject, date and labels of messages in that mailbox.

It does not grant access to message bodies, attachments, or any other Google service. Google enforces this: a request for a message body using this credential is refused with an error. No Calendar, Drive, Contacts or other data is accessed.

What it does with it

Nothing is sent, replied to, deleted, labelled or modified. Conrad only reads and only notifies.

What is stored

Message identifiers, timestamps and the urgency decision are kept so that the same message is not processed twice and so the operator can review whether the judgements were right. Subject lines are not retained after a decision is made. Message bodies are never available to store.

Who else sees it

Deciding whether a message is urgent uses a language model provided by Anthropic. The sender address, subject line and Gmail labels of a message are sent to Anthropic's API for that judgement. Nothing else is transmitted, and message bodies cannot be, because Conrad never has them.

Alerts are delivered through Pushover and by email to the operator. No data is sold, shared with advertisers, used for training, or disclosed to anyone else.

Google Workspace API data is not used to develop, improve or train generalised models.

Control

Access can be withdrawn at any time at myaccount.google.com/permissions, which immediately and permanently ends Conrad's ability to read anything. Since the operator and the only user are the same person, there are no other parties with data to request or erase.