Privacy
Absolutus privacy policy
Last updated: August 3, 2026.
Private deployment
Absolutus is a self-operated, invitation-only deployment for its Creator’s personal use and for household or room members the Creator explicitly enrolls. It is not offered as a public software-as-a-service product, has no public signup, and has no public application download.
What Absolutus stores
Absolutus stores the account, tasks, messages, appointments, explicit memories, room content, configuration, and provider observations needed to provide the service. Personal-context data remains scoped to its owning user. Room members see only information deliberately created in or promoted to that room.
Google account data
Connecting Google is optional and initiated by the user. Each permission enables only its named capability. Gmail access imports selected mail and permits only explicitly approved, reversible label changes. Calendar read access imports selected external calendars and events. calendar.app.created creates and maintains the user-owned Absolutus - Me calendar. Writable calendar.calendarlist adds or removes an app-owned room calendar from that user’s Calendar list.
A dedicated Absolutus service account owns shared room calendars so they survive the room creator leaving. It has no Gmail authority, Workspace administrator role, or domain-wide delegation. Room membership controls reader access. Absolutus-created calendars and projected events are excluded from inbound Calendar ingestion to prevent feedback loops.
Absolutus does not send Gmail, edit unrelated Google events, create public calendars, invite attendees, or create Google Meet links. Declining or revoking one scope disables only the dependent feature.
Google API Limited Use
Absolutus’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve user-facing features for the owning user. It is not sold, used for advertising, or used to train or improve a generalized artificial-intelligence model.
Model processing
Setup identifies whether configured language, vision, transcription, or embedding providers are local or remote. Source content is not sent to a remote model until the user consents for that source. Revoking consent stops new remote processing. Provider credentials are server-only and are never included in source prompts.
Personal WhatsApp
The optional personal WhatsApp source is a read-only linked-device connection, separate from Absoluta’s speaking account. It imports supported sent and received content but exposes no application route to send as the user, react, mark messages read, publish presence, or change groups, contacts, profiles, or statuses. Pairing requires separate risk acceptance.
Security and isolation
Credentials are encrypted or mounted as restricted server secrets and are not included in the Android application, logs, exports, or public configuration. Provider operations, search, organization, projections, and exports are scoped to the authenticated actor. Shared rooms never expose another member’s private source material.
Retention, export, and deletion
Setup lets the user pause, disconnect, or delete an imported source copy without deleting the provider’s original data. Source deletion removes stored credentials, cached content, derived organization data, pending provider work, and source-bearing activity. Account export and deletion controls are available in Setup. Encrypted operational backups expire within the declared backup-retention window.
Controls
Users can review connection status and missing permissions, re-consent to an individual capability, disconnect providers, export their account, and request deletion from within Absolutus Setup. Permission denial never disables unrelated Absolutus functionality.