Privacy Policy
Last updated: 6 September 2026
1. Who we are
Aaka ("we", "our", "the software") is an open-source personal assistant application published at github.com/prasadgupte/aaka-life (opens in a new tab). The software is self-hosted — you run it on your own computer or server. For questions, contact hello@aaka.life.
2. What Aaka is and is not
Aaka is software you install and operate yourself. It is not a cloud service. We do not have access to your data, and we do not operate the infrastructure on which you run Aaka. This privacy policy describes how the software handles data when you run it.
3. Data Aaka accesses via Google APIs
When you configure Aaka, you grant it access to certain Google services using OAuth 2.0. The scopes Aaka may request are:
- Google Calendar (
calendar.events,calendar.readonly) — to read your calendar events and write new events you request via chat. - Google Tasks (
tasks) — to read and create task items. - Gmail (
gmail.readonly) — to read emails when you explicitly request a summary or search.
4. How your data is used
Data retrieved from Google APIs is used solely to respond to your requests in the messaging app you have configured (WhatsApp or Telegram). Specifically:
- Calendar data is read to answer schedule queries and written only when you explicitly confirm an event addition.
- Task data is read to list tasks and written only when you create a new task.
- Email data is read only when you explicitly request it and is not stored persistently.
Aaka does not use your data to train machine learning models, build advertising profiles, or any other purpose beyond fulfilling your immediate request.
5. Data storage and retention
Aaka stores the following data locally on your hardware:
- OAuth tokens — in your configured token directory.
- Calendar snapshots — plain-text files used for zero-token schedule reads, updated by a background sync process you control.
- A SQLite queue database — containing pending actions, cleared after execution.
- Log files — operational logs, stored locally and rotated on a schedule you configure.
No personal data is sent to or stored on any server operated by Aaka's authors.
6. Third-party services
When you send a message that requires natural-language understanding (for example, "add dentist on Friday at 3pm"), Aaka may call a large language model API (currently Google Gemini or a compatible API you configure). Only the text of that specific message is sent — no calendar data, no personal identifiers beyond what is necessary to extract the intent.
The messaging platforms you use (WhatsApp, Telegram) are governed by their own privacy policies. Aaka receives messages via their respective APIs and does not store message content beyond the immediate processing cycle.
7. This website (aaka.life)
Sections 1–6 describe the Aaka software you run yourself. This section is about this website, which is a different thing: it is a website we operate, and it is the only place where we process any data about you.
Nothing is measured unless you agree. On your first visit we ask whether we may use analytics. Until you accept, no analytics script is downloaded, no cookie is set and nothing is sent. Declining, closing the banner, or simply ignoring it all leave analytics switched off. If your browser sends a Global Privacy Control signal we treat that as a refusal and do not even ask.
If you do accept, we use Google Analytics 4 and it records:
- Pages viewed, and how far down each page you scrolled.
- Which sections, buttons, demo tabs and links you interacted with.
- Approximate location from your IP address, which Google truncates and does not store.
- Device, browser and referring site.
We never send your name, your email address, or anything you type into the contact form. When someone submits that form we record only that a submission happened and which topic was chosen.
| Cookie | Purpose | Expires |
|---|---|---|
_ga | Distinguishes one browser from another | 2 years |
_ga_<id> | Keeps session state for the property | 2 years |
Legal basis is your consent, under Article 6(1)(a) GDPR and the ePrivacy Directive. Processor is Google Ireland Limited, with transfers to Google LLC in the United States covered by the EU–US Data Privacy Framework. Retention is 14 months, after which Google deletes the event data.
To change your mind, use the cookie settings link, also in the footer of every page. Withdrawing deletes the analytics cookies from your browser and stops any further collection. Withdrawal is as easy as consenting, and does not affect anything collected before you withdrew.
The contact form is protected by hCaptcha, which processes your IP address and browser signals to tell people from bots. That is strictly necessary to operate the form and runs only when you submit it.
8. Children's privacy
Aaka is not directed at children under 13. As a self-hosted tool operated by an adult administrator, any use involving children's data is entirely under the operator's control and responsibility.
9. Your rights
Because Aaka is self-hosted, you have complete control over your data at all times. You can revoke Google OAuth access at any time via your Google Account permissions page. You can delete all local data by removing the Aaka data directory.
10. Changes to this policy
We may update this policy as the software evolves. Material changes will be noted in the GitHub repository changelog. Continued use of the software constitutes acceptance of the updated policy.
11. Contact
Questions about this policy: hello@aaka.life