Altar Ego (also referred to as “Secretariat”) · Last updated 26 August 2026
Altar Ego is a personal assistant operated by and for one individual, Miles Van de Wetering. It is not a commercial product, has no other users, and is not offered to the public. This policy describes what it does with data from connected accounts.
Miles Van de Wetering — milesvdw@gmail.com. There is no company, no team, and no third-party operator.
With the account owner’s explicit consent through Google’s OAuth flow, the application may access:
Only the authenticated account owner’s own data is accessed. The application does not access data belonging to anyone else, and no other person can sign in to it.
Data is stored locally, in a database on a personal computer owned and physically controlled by the account owner. It is not uploaded to any hosted service operated by the developer, because no such service exists.
Encrypted backups are written to private cloud storage. They are encrypted on the local machine, before leaving it, with keys the account owner alone holds; the storage provider cannot read them.
Altar Ego’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The application uses a large language model to summarise and organise the account owner’s own material. Content sent for processing is handled under the model provider’s terms and is not used to train their models. The account owner decides what is sent; the application does not transmit connected-account data for any other purpose.
Data is retained for as long as the account owner wants it, because the entire purpose of the system is to keep a durable personal record. The account owner can revoke the application’s access at any time at myaccount.google.com/permissions, and can delete the local database outright. Doing either stops all further access immediately.
Credentials are held in an operating-system-sealed store on the local machine rather than in configuration files. Anything that leaves the machine is encrypted first. Remote access to the system is gated behind an identity proxy.
If this policy changes, the date at the top of this page changes with it.