Privacy policy
Last updated 23 September 2026
Nora is a personal assistant operated by Umla (contact: umlahelp@gmail.com). This policy covers the Nora web app and the Google account data it uses. It is written for the preview build at nora-assistant-staging.umlahelp.workers.dev.
What we access in your Google account
Nora only asks for a scope when a feature behind it exists. Consent is granular — you can decline any line and the rest still works.
- Email address and OpenID — to sign you in and identify your account.
- Gmail read, compose, modify, send — to summarise mail you ask about, prepare drafts for your approval, and send or label a message once you approve it.
- Calendar events and read-only calendar — to show your schedule and create an event after you confirm it.
- Contacts and other contacts, read-only — to resolve a name you mention to the right email address.
- Tasks — to read and write your Google Tasks list.
- Drive file — limited to files you open with, or create through, Nora. Nora never requests access to the rest of your Drive.
Nora deliberately does not request https://mail.google.com/ or full Drive access, so it cannot permanently delete your mail or reach Drive files it did not create.
Limited Use
Nora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow humans to read it except with your explicit consent, for security or to comply with law.
How your data is handled
- Mail and calendar content is not stored. It is fetched when a request needs it, used to answer that request, and discarded. Our audit log records that a read happened and how many messages were involved, never their contents.
- Your refresh token is encrypted at rest with AES-GCM under a key held outside the database, and is never returned by any API response or export.
- AI processing. To answer a request, the relevant text may be sent to Microsoft Azure OpenAI and, as a fallback, Google Gemini. Sensitive values are redacted before this happens. These providers process the text to return a reply; they act as processors for us.
- Hosting. The app runs on Cloudflare Workers with Cloudflare D1 and R2 storage.
- We do not sell your data or share it with advertisers.
Removing access
Disconnect Google inside Nora. That deletes the stored token and calls Google's revocation endpoint in the same step, so the grant ends on both sides. You can also revoke it yourself at myaccount.google.com/permissions. To have the rest of your account data deleted, email umlahelp@gmail.com.
Changes
If this policy changes materially, the date above changes and we notify connected users by email.