Privacy Policy
Last updated: October 10, 2026
Umika (“Umika”, “we”, “us”) is a personal AI agent you talk to through messaging apps such as Telegram. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to our website, dashboard and messaging bots (together, the “Service”).
1. Information we collect
Account information. Your phone number (used to sign in with a one-time code), your name if you provide it, your time zone, and your invite and waitlist status.
Messaging information. When you message Umika, we receive your messaging account identifier, display name and username, and the content of the messages you send and receive, including any phone number you choose to share with the bot.
Location (only when you share it). If you tap “Send location” or share a place, we store your most recent location — coordinates and an approximate address — to answer requests like “find a pharmacy near me”. We keep only the latest location, not a history, and it is replaced each time you share a new one.
Agent memory and tasks. Facts and preferences the agent saves to help you later (for example, your city or a family member’s birthday), reminders you set, and confirmations you give for actions.
Google account data (only if you connect Google). If you connect a Google account, we receive your Google account email address and an access token that lets the agent, at your request:
- read, search and organize your Gmail messages — archive, labels, read state, trash — and create drafts (gmail.modify);
- send email on your behalf after you tap “Yes” on a confirmation (gmail.modify);
- view and create Gmail filters, filters only after you confirm (gmail.settings.basic);
- view your calendars; create, change and cancel events after you confirm (calendar);
- view and manage your Google Tasks (tasks);
- look up your contacts and people you have emailed (contacts.readonly, contacts.other.readonly);
- find and read files in Google Drive, and create or edit Docs, Sheets and Slides; share a file with someone only after you confirm (drive, documents, spreadsheets, presentations).
We do not copy your mailbox, calendar or files into our database. The agent fetches only the messages or events needed to answer your request, and may keep short summaries in your conversation history.
Technical information. Basic logs such as IP address, timestamps and error reports, used to operate and secure the Service.
2. How we use information
- to provide the Service: understand your requests, reply, remember context, run reminders and tasks;
- to verify your identity and manage invite-only access;
- to keep the Service secure and prevent abuse (for example, rate limits on sign-in codes);
- to communicate with you about the Service.
We use your conversations to improve Umika only if you turn on “Use my data to improve the agent” in Preferences, and only in de-identified form. Google user data is never used for this purpose.
3. Google user data and Limited Use
Umika’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- we use Google user data only to provide and improve user-facing features that you request;
- we do not sell Google user data or use or transfer it for advertising;
- we do not use Google user data to train or improve generalized AI or machine-learning models;
- we transfer Google user data to third parties only as needed to provide the features you request (for example, to our AI model provider to summarize an email you asked about), to comply with law, or as part of a merger or acquisition with notice to you;
- our staff do not read Google user data unless you give explicit consent for specific messages, it is necessary for security purposes, or it is required by law.
4. Service providers
We share information with providers that process it on our behalf, under contracts that limit their use:
- Supabase — database and authentication;
- Vercel — website hosting;
- Trigger.dev — background task processing;
- Anthropic — AI model processing of your messages and requested data (not used to train their models);
- Twilio — sending sign-in codes by SMS or WhatsApp;
- Telegram — delivering messages between you and the agent;
- Photon by komoot (OpenStreetMap data) — turning shared coordinates into an approximate address;
- Google — if you connect your Google account.
We do not sell your personal information.
5. Retention and deletion
- We keep your information while your account is active.
- Disconnecting a Google account in Workspace → Connectors revokes our access token with Google and deletes the stored tokens.
- Deleting your account in Preferences permanently deletes your profile, messages, agent memory, reminders, invites and connected-account tokens, except where we must keep limited records by law.
- You can also ask us to delete your data by emailing support@example.com.
6. Security
Data is encrypted in transit (TLS). Access tokens for connected accounts are encrypted at rest with AES-256-GCM. Actions on your behalf, such as sending email or creating events, require your explicit confirmation. No system is perfectly secure, but we work to protect your information and limit access to it.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, and to withdraw consent. You can manage most of this in the dashboard; for anything else, contact us at support@example.com. You may also have the right to complain to your local data protection authority.
8. International transfers
Our providers may process information in Canada, the United States and other countries. Where required, we use appropriate safeguards for these transfers.
9. Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from children.
10. Changes
We may update this policy. If changes are significant, we will notify you through the Service before they take effect.
11. Contact
Umika · support@example.com