Privacy Policy
R3 ยท last updated 20 September 2026
R3 is a personal assistant run by one person on their own server, for their own use. It is not offered to the public and has no other users. This policy describes how it handles data, and in particular how it handles Google user data.
Who operates R3
R3 is operated by its sole user, who is also its developer and the owner of the hardware it runs on. Questions about this policy can be sent to the contact address listed on the application's Google OAuth consent screen.
Where data lives
Conversations, notes and files are stored on a private server owned by the user, on their own premises. The language model that answers questions also runs on that server. There is no hosted R3 service, no shared database, and no operator other than the user.
Google user data
What R3 requests. One scope only:
-
https://www.googleapis.com/auth/drive.fileโ access limited, by Google, to files that R3 itself created.
R3 does not request access to the rest of the user's Drive, to Gmail, to Contacts, to Calendar, or to any other Google service. Files the user did not create through R3 are not visible to it.
How R3 uses it. Only to carry out what the user asks:
- Upload a file the user asked R3 to store.
- Search and retrieve files R3 previously created, so it can refer to them.
How it is stored.
- The OAuth refresh token is held in a secrets store on the user's own server, readable only by the application. It is never logged and never included in backups that leave the machine.
- File contents fetched from Drive are used to answer the request at hand. R3 keeps a copy only where the user explicitly asked it to save one.
How it is shared.
- Google user data is not sold, rented, or shared with any third party.
- It is not used to train any machine-learning model, and it is not sent to any hosted model provider.
- It is not used for advertising, profiling, or any purpose beyond the feature the user invoked.
R3's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Data is kept until the user deletes it. Because the user is the only operator, deletion is immediate and under their sole control: access can be revoked at any time from Google Account โ Third-party access, which invalidates R3's token, and the stored token can be removed from the server. Files already in Drive remain the user's own and can be deleted from Drive directly.
Other services R3 connects to
At the user's configuration, R3 may also connect to their own calendar, task and mail accounts. Each connection is off unless credentials are supplied, and each sends only what the requested action requires. None of these services receives Google user data.
Children
R3 is not directed at children and has no users other than its operator.
Changes
Any change to this policy will be published on this page with a new date above.