Privacy policy

Aveline. Last updated 16 September 2026.

Aveline is self-hosted software. There is no hosted service and no company server. When you run it, you run it on your own machine against your own database. This policy describes what the software does with your data. Whoever operates a particular installation is responsible for that installation.

What Google data it accesses

With your permission, Aveline uses the Google Calendar API to access:

It requests calendar.events.readonly to read events. If the operator turns on event creation, it also requests calendar.events so it can create events on its own calendar and invite people to them.

It does not access Gmail, Drive, Contacts, or any other Google service.

Why it accesses it

Where the data goes

Stored on your own infrastructure. Calendar data is written to a PostgreSQL database controlled by whoever runs the installation. It is not sent to the authors of this software and there is no central server that receives it.

Sent to a large language model provider. This is the part you should read carefully. To write its daily brief and to decide what to say, Aveline sends a summary of relevant data to an external language model API. That summary can include event titles, dates, times and locations, and the names of people it knows about. Which provider receives it is configured by the operator. The current default is DeepInfra. The provider's own terms and privacy policy apply to that data.

Nothing else leaves the installation. There is no analytics, no tracking, no advertising, and data is not sold or shared with anyone else.

How long it is kept

Indefinitely, until the operator deletes the database. The software is deliberately append-only: when an event changes, the older version is marked superseded rather than deleted, so that the history stays answerable. If you want your data removed from an installation, ask whoever runs it.

Limited Use

Aveline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Withdrawing access

You can revoke access at any time at myaccount.google.com/permissions. If you shared a calendar with a worker, you can stop sharing it from your own Google Calendar settings. Either one takes effect immediately and the software cannot undo it.

Contact

cheaway@gmail.com