Privacy Policy

Last updated August 1, 2026.

What Nona collects

Your account email (via sign-in), and whatever you enter directly — tasks, notes, and calendar items. If you connect Gmail or Outlook, Nona requests read-only access to fetch and summarize your inbox.

Email data specifically

Email content is read live over the provider's API for each request and is not stored afterward — it's processed in memory to generate summaries and briefs, then discarded. Nona's access is read-only: it cannot send, delete, or modify anything in your inbox. OAuth tokens that grant this access are stored server-side, encrypted, never in the browser.

Google user data

Nona's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Concretely, if you connect a Google account Nona requests two read-only scopes: Gmail (gmail.readonly) to summarise and triage your inbox, and Calendar (calendar.readonly) to show your appointments in the week view. Nona cannot send, delete or change anything in either. That data is used only to provide those features to you: it is never sold, never used for advertising or profiling, never used to train generalised AI or machine-learning models, and no human at Nona reads it. Email and calendar text is sent to the Anthropic API (Claude) to produce your summaries — Anthropic processes it as a service provider under their API terms and does not use API inputs to train models. Nothing else receives it.

How data is used

Solely to run the features you use — generating your daily brief, parsing tasks, and triaging email. Task and email text is sent to the Anthropic API (Claude) to do that parsing and summarizing; Anthropic processes it under their own API terms and does not use API inputs to train models.

Mailing list

If you sign up for product updates, your email is stored separately for that purpose only. You can unsubscribe at any time from the unsubscribe page.

Third parties

Nona runs on Vercel (hosting) and Supabase (database, authentication). Sign-in and email triage integrate with Google and Microsoft. None of these providers receive more than what's required to operate the feature in question.

Your data, your control

You can request deletion of your account data at any time via the contact page. Disconnecting Gmail revokes Nona's access with Google immediately. Disconnecting Outlook deletes Nona's stored tokens straight away, which stops all access; Microsoft offers no way for an app to revoke its own consent, so to clear that record on their side too, remove Nona at account.live.com (personal accounts) or myapps.microsoft.com (work or school accounts).

Where things stand

Nona is an actively developed MVP built by a solo founder. This policy describes how the product works today and will be updated as it changes — check back periodically if that matters to you.