The Alfred Project

Effective September 8, 2026

Privacy policy

The Alfred Project is a private personal assistant operated by Thomas Gardner. It accesses Google data only for the owner's requested email, scheduling, and recording workflows.

Information accessed and purpose

Alfred reads Gmail account and label information, message headers, snippets, and message text to search, read, and summarize email. It reads Calendar lists and event information, including event names, times, status, and links, for scheduling context. These integrations do not implement sending email or editing Calendar events.

The audio workflow lists and downloads recordings from the owner's designated Google Drive intake folder. It transcribes them locally and creates transcripts, notes, digests, and processed-audio copies in designated Drive output folders. Original Drive recordings remain until separately deleted.

Processing and sharing

Honcho / Plastic Labs is not part of Alfred's current processing architecture. Its former memory integration and runtime credential are disabled. The historical live workspace was permanently deleted on September 8, 2026 and is no longer available through Honcho's dashboard or API. Honcho's published policy states that encrypted backup snapshots may remain on a rolling basis for up to 90 days and API logs follow a 90-day/day-91 lifecycle.

The standalone audio processor uses local faster-whisper inference and does not itself send audio to a remote transcription service. Later assistant review of transcripts can involve OpenAI. Google-derived content must not be routed to an unapproved external processor.

Retention and deletion

Local conversations, memories, downloaded audio, transcripts, notes, digests, processing ledgers, and cron outputs do not currently have an enforced time-based deletion schedule. They are retained while required for the active workflow or until manually deleted. Some application logs rotate by size; that is not a day-based deletion guarantee. Source files and generated outputs in Google Drive persist until deleted separately.

Deleting live data does not immediately remove older backup copies. The preserved WP-00 recovery set contains selected Google-derived data and includes a root-only plaintext archive plus an encrypted copy. Hostinger full-server backups roll forward on the provider's backup lifecycle and cannot be selectively edited.

Incoming and outgoing Telegram content is retained in local conversation stores and in Telegram's cloud chat. No Telegram auto-delete timer is active. Local copies can be deleted manually. For remote deletion, the owner must delete messages or clear the private chat for both parties in Telegram.

Disconnecting Google stops future authorized access but does not delete existing local records, Drive outputs, model or provider records, Telegram messages, or backup copies. A deletion request must address each applicable store and derivative.

Security and limits

Active Alfred and Gmail profile data is restricted through dedicated Unix accounts, protected home and profile directories, and limited service identities. Data is encrypted in transit to external providers. The VPS guest disk was not shown to use a separate full-disk encryption layer, root and hosting administrators can access server data, and a preserved recovery archive is plaintext but root-only. No absolute end-to-end encryption or immediate-backup-deletion promise is made.

The reviewed workflows do not sell Google data or use it for advertising. Google-derived content must not be submitted through voluntary feedback. This policy describes observed handling; it is not a provider certification.

Contact and controls

Contact Thomas Gardner at gardnertom603@gmail.com for access, correction, or deletion requests. Google access can be revoked through Google Account connections. Revocation and deletion are separate actions.

Related policies: Terms of use.