Altar Ego

Privacy Policy

Altar Ego (also referred to as “Secretariat”) · Last updated 26 August 2026

Altar Ego is a personal assistant operated by and for one individual, Miles Van de Wetering. It is not a commercial product, has no other users, and is not offered to the public. This policy describes what it does with data from connected accounts.

Who runs it

Miles Van de Wetering — milesvdw@gmail.com. There is no company, no team, and no third-party operator.

What data is accessed

With the account owner’s explicit consent through Google’s OAuth flow, the application may access:

Only the authenticated account owner’s own data is accessed. The application does not access data belonging to anyone else, and no other person can sign in to it.

Where the data goes

Data is stored locally, in a database on a personal computer owned and physically controlled by the account owner. It is not uploaded to any hosted service operated by the developer, because no such service exists.

Encrypted backups are written to private cloud storage. They are encrypted on the local machine, before leaving it, with keys the account owner alone holds; the storage provider cannot read them.

What the data is not used for

Google API Services Limited Use disclosure

Altar Ego’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Language models

The application uses a large language model to summarise and organise the account owner’s own material. Content sent for processing is handled under the model provider’s terms and is not used to train their models. The account owner decides what is sent; the application does not transmit connected-account data for any other purpose.

Retention and deletion

Data is retained for as long as the account owner wants it, because the entire purpose of the system is to keep a durable personal record. The account owner can revoke the application’s access at any time at myaccount.google.com/permissions, and can delete the local database outright. Doing either stops all further access immediately.

Security

Credentials are held in an operating-system-sealed store on the local machine rather than in configuration files. Anything that leaves the machine is encrypted first. Remote access to the system is gated behind an identity proxy.

Changes

If this policy changes, the date at the top of this page changes with it.