Last updated: August 22, 2026
BananaBrain Privacy Policy
BananaBrain is a private personal-use AI assistant operated by Gleb Malenkov. This policy explains how it accesses, uses, stores, and shares Google user data.
Google data the assistant may access
- Gmail messages, headers, labels, threads, drafts, and sending functions.
- Google Calendar events and calendar metadata.
- Google Drive files and metadata, including Docs and Sheets content.
- Google Contacts names and contact details on a read-only basis.
How Google data is used
Google data is used only to provide features requested by the account owner, including:
- prioritizing mail and producing daily email summaries;
- preparing reply drafts and sending approved replies;
- reviewing schedules and managing requested calendar events;
- finding, reading, creating, or updating requested files, documents, and spreadsheets;
- locating contact information needed for a requested task.
Email content is treated as untrusted data. BananaBrain does not follow instructions found inside messages, attachments, or linked pages.
Storage and retention
OAuth credentials are stored on a privately controlled server with restricted filesystem access and are retained until the Google connection is removed or access is revoked. This public website does not store Google account data. The private assistant may retain short summaries and operational logs needed for continuity and diagnostics. These records are removed when no longer needed or upon the account owner's request.
Data sharing and AI processing
Personal information is not sold, rented, or used for advertising. Data may be processed only by services needed to complete a requested task: Google APIs, the configured AI inference provider, private hosting infrastructure, and Telegram when the owner requests delivery there. Data is not used by BananaBrain to train a generalized AI model.
Human approval and user control
BananaBrain prepares email replies as drafts by default. Sending email, unsubscribing, deleting data, and other consequential actions require explicit approval. The account owner can revoke Google access at any time and request deletion of locally stored credentials and records.
Security
Access is limited to the owner's authorized account. Credentials are not intentionally exposed in public pages or client-side code. Reasonable administrative and technical safeguards limit unauthorized access.
Google API Services User Data Policy
BananaBrain's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Changes
This policy may be updated if functionality or data practices change. The current version will remain available at this URL.
Contact
Questions or deletion requests: malenkov.gleb.official@gmail.com