privacy · offload
privacy policy.
last updated · july 13, 2026
your privacy at a glance
- Offload only accesses the accounts and sources you connect on purpose.
- To do the work, the context donna needs is processed on our servers and sent to our AI providers. Those providers are configured for zero data retention and are restricted from using your data to train their models.
- We never sell your data, never use it for advertising, and never use it to train generalized AI models.
- Any action that sends, posts, buys, or changes something waits for your explicit approval.
- You can disconnect any source at any time, which revokes our access, and you can ask us to delete everything.
Questions? Reach us any time at support@offload.so.
who we are
The service is operated by Offload Studio, Inc. For anything about this policy or your data, contact support@offload.so.
the data we collect
We collect data in three categories: data from sources you connect, data you create with donna, and the account and billing data needed to run a paid service.
Sources you connect
- Google (Gmail, Google Calendar, Google Drive) · connected via Google sign-in. The scopes we request are listed in the table below. This access lets donna brief you, find things, prepare drafts, and, with your approval, send mail, schedule events, and create or edit files.
- Apple iMessage and Apple Notes · read from your Mac’s local databases on your machine. The context donna needs to work is processed on our servers as described below.
- Other integrations you enable · for example Canvas or X lookups. Each integration collects only what it requires.
Data you create with donna
- Your conversations with donna, the tasks and notes she keeps for you, and the drafts she prepares for your approval.
- If you use voice, the audio and transcript of the conversation while it is active.
Account and billing
- Your phone number, used to send a one-time sign-in code, and your device passkey if you register one.
- Your email address, captured when you start a subscription.
- Billing details, handled by our payment processor, Stripe. We do not store your full card number.
how we use your data
- To provide Offload · briefing you, finding things, drafting, and taking the actions you approve.
- To operate the service · sign-in, billing, support, and keeping the service reliable and secure.
- To communicate with you · receipts, service notices, and replies to your requests.
We do not use your data for advertising, and we do not use it to develop or train generalized AI or machine-learning models.
google data and the scopes we request
Connecting Google grants Offload the following OAuth scopes. Two of these (Gmail and Drive) are restricted scopes under Google’s policy and one (Calendar) is sensitive.
| scope | access | why we need it |
|---|---|---|
gmail.modifyrestricted · read & write | Read, organize, and compose Gmail, and, only with your approval, send mail. | Morning briefings, finding mail, drafting and sending replies you approve. |
driverestricted · read & write | Read your Drive files, and, only with your approval, create or update files. | Finding documents, and creating or editing docs when you ask donna to. |
calendarsensitive · full | Read and write your calendar. | Knowing your day, telling you when to leave, and scheduling with your approval. |
openid, userinfo.email, userinfo.profile | Your basic Google identity. | To sign you in and label the connected account. |
You can review and revoke Offload’s access to your Google account at any time at myaccount.google.com/permissions, or by disconnecting Google inside the app.
google api services · limited use
Offload’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:
- We use Google user data only to provide or improve user-facing features that are prominent in Offload’s interface.
- We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use Google user data for serving advertising of any kind.
- We do not allow humans to read your Google data, except with your affirmative agreement for specific data, where necessary for security, to comply with applicable law, or where the data is aggregated and anonymized for internal operations.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
how your data is processed
donna’s reasoning runs on large language models operated by third-party AI providers, and specific features rely on a few additional service providers for search, embeddings, voice, message delivery, and billing. We use each provider only to operate the feature it powers.
We configure our AI providers for zero data retention, with the training opt-out enforced at the routing layer. Your content is sent to a model only to generate a response, held in memory for the request, and not retained afterward, and it is never used to train models. The providers that power search and recall are configured the same way.
how your data is stored
The context donna keeps for you is stored in our database and object storage, hosted in the United States. Data is encrypted in transit, and our infrastructure providers encrypt the underlying storage at the platform level. Access is isolated per account: every database query is scoped to your user with row-level security, and access by our team is limited to what operating the service requires, consistent with the Limited Use commitments above. Our security page describes this in more detail.
retention
We keep your data for as long as your account is active so donna can do her job. When you disconnect a source, we revoke the access token and delete our stored copy of it. When you ask us to delete your account, we remove your data from our production systems, and residual copies in routine backups cycle out within our backup window.
your rights and choices
- Disconnect a source. You can disconnect Google or any other integration at any time inside the app. This revokes our access and deletes the stored tokens for that source.
- Delete your account and data. Email support@offload.so and we will delete your account and associated data.
- Export your data. Email the same address to request a copy of the data we hold about you.
- Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including access, correction, deletion, and restriction of processing. Contact us to exercise them.
children
Offload is not directed to children under 13, or the minimum age in your jurisdiction, and we do not knowingly collect their data.
changes to this policy
If we change this policy, we will update the date at the top and, for material changes, notify you in the app or by email.
contact
Offload Studio, Inc. · support@offload.so. See also our terms of service and security pages.