Privacy Policy
Last updated: August 10, 2026
1. Who we are
PA Forever (“we”, “us”) provides a personal-assistant service that you can talk to by phone or from a browser. This policy explains what information we collect, why we collect it, and what we do with it.
2. Information we collect
- Account data — your name, email address, and the encrypted password you set at sign-up.
- Assistant data — the conversations, tasks, calendar events, and knowledge-base items you create with your PA.
- Voice data — short-lived audio sent to our speech-to-text provider (SOC 2 / HIPAA / GDPR compliant) for transcription. We do not store raw audio.
- Telemetry — minimal log data (IP, user agent, error traces) used to keep the service running and secure.
- Connected email & calendar accounts — if you choose to connect Gmail, Outlook or another mailbox over IMAP, or Google Calendar, Outlook Calendar or iCloud Calendar, the email and calendar data described in section 3.
3. Connected email & calendar accounts
Connecting an account is always optional. Gmail, Outlook, Google Calendar and Outlook Calendar use each provider's official OAuth consent flow — for those we never see or store your password. When you connect a mailbox, the assistant can:
- Read incoming mail to triage it, answer your questions about your inbox, and notify you of what needs a reply.
- Draft replies into your own Drafts folder for your review.
- Send email you explicitly ask it to send (or that a rule you enabled allows), and tidy your mailbox (mark read, label, archive, move to trash) when you ask. It never permanently deletes mail.
What we store on our servers:
- Message metadata (sender, recipients, subject, date) and a snippet of up to 300 characters. Full email bodies are never persisted — when you ask to read a message in full, we fetch it live from your provider, show it to you, and do not keep a copy.
- Attachments you explicitly ask to open are cached temporarily so we can hand you a download link; cached copies are deleted automatically after 30 days.
- OAuth tokens, stored encrypted in Google Cloud Secret Manager — never in the browser and never in plain text.
Connected calendars. If you connect Google Calendar, Outlook Calendar or iCloud Calendar, the assistant reads your events to answer questions like “what's on today?” or “am I free at 3?”, and creates, updates and deletes events only when you ask it to. We also read the list of calendars on the account — their names, ids and whether they're writable — for one reason: so you can choose which calendar the assistant writes to, and so we can label the connected account. We never read event content through that list. Event details are fetched live from your provider each time and we do not keep a copy of your calendar; what remains afterwards is the receipt in your activity log of what the assistant did (for example “Created calendar event ‘Lunch’”) and, until your next calendar question, a short list of the events from your most recent answer so a follow-up like “move that one to 2pm” lands on the right event.
Accounts that sign in with an app password. Mailboxes you connect over IMAP/SMTP, and iCloud Calendar, do not offer OAuth — they sign in with your address plus a password, and for providers with two-factor authentication (iCloud always) an app-specific password you generate for PA Forever alone. That password is stored encrypted in Google Cloud Secret Manager — never in our database, never in the browser, never in plain text — is used only to talk to that provider's own server over an encrypted (TLS) connection, and is destroyed when you disconnect the account.
Google user data. PA Forever's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data (Gmail and Google Calendar) only to provide the assistant features you see; we never sell it, never use it for advertising, and never allow humans to read it except with your consent, for security purposes, or to comply with law. Google user data (Gmail and Google Calendar) is not used to develop, improve, or train generalized AI or machine-learning models.
Microsoft user data. The same rules apply to Outlook / Microsoft 365 mail and calendar accessed through Microsoft Graph: assistant features only, no advertising use, no sale, no model training.
You can disconnect an account at any time from the Connections page, which stops all processing and deletes our stored tokens and passwords. For Google accounts we also revoke the grant at Google; Microsoft offers no app-side revocation, so for Outlook we destroy our copies and you can additionally remove the app from your Microsoft account. iCloud has no grant to revoke — disconnecting deletes the stored app-specific password, and you can also revoke that password yourself at appleid.apple.com (Sign-In and Security → App-Specific Passwords). Google and Microsoft access can also be revoked directly, at any time, from myaccount.google.com/permissions or account.live.com/consent/Manage.
4. How we use your data
We use your data to:
- Provide and operate the assistant.
- Authenticate you and protect your account.
- Improve reliability, diagnose problems, and prevent abuse.
- Communicate important service notices.
We never sell your data. We do not use the contents of your assistant conversations to train third-party models.
5. Sub-processors
We use a small set of trusted infrastructure providers:
- Firebase / Google Cloud — authentication, database, file storage.
- Cloudflare — application delivery and edge compute.
- Speech AI providers — SOC 2 / HIPAA / GDPR-compliant speech-to-text and text-to-speech.
- Telephony providers — optional phone connectivity.
- Large-language-model providers — inference on only the messages needed to answer the current turn.
A current list of named sub-processors is available on request from privacy@paforever.com.
6. Your rights
You can export or delete your data at any time from the Settings page or by emailing privacy@paforever.com. EU/UK/CA residents have additional rights under GDPR / PIPEDA — reach out and we'll honour them within 30 days.
7. Retention
Account and assistant data is kept for as long as your account is active. Stored email metadata and calendar metadata follow the same rule and are removed when you disconnect the account or delete your data; cached attachment copies expire after 30 days. When you delete your account, we permanently remove your data within 30 days, except where we're legally required to keep it (e.g. billing records).
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Production access is restricted to a small number of engineers and audited. If we detect a breach that affects you, we'll notify you within 72 hours.
9. Contact
Questions? Email privacy@paforever.com.
This is a plain-English summary — nothing on this page is legal advice. Please consult your own counsel for questions about how this policy applies to you.