Legal

Privacy Policy

Last updated 18 September 2026

This policy explains what Colette AI collects, why, who it is shared with, and how you can get it back or have it deleted. It covers the Colette AI web app and the Colette AI Android app.

The short version

  • We store your account details, your conversations, and the files you upload — so your history is there when you come back.
  • Your messages are processed by Google's Gemini API to generate replies. That is how the assistant works.
  • If you connect another account such as Google or Slack, we hold an encrypted token and use it only for the actions you ask for.
  • We do not sell your data, and we do not use your conversations to train our own AI models.
  • You can disconnect any linked account, delete any conversation, or delete your whole account at any time.
Who we are. Colette AI is an independent project operated by Ozegbe Mike Isioma. In this policy, "we" and "us" mean the operator of Colette AI. You can reach us at masteralexleoreevesd1@gmail.com.

1. What we collect

Account details

When you create an account we store your email address and a display name. If you sign in with Google, we also receive your Google profile name, email address and profile photo URL. If you sign in with a password, that password is handled entirely by Firebase Authentication — we never see it.

Your conversations and creations

Your chats and messages are stored so that your history, memory and context persist between visits. This includes content you generate inside Colette AI, such as images, documents, podcast scripts, game sessions and canvas work.

Files you upload

Files and images you attach to a message are stored so Colette can read them and so you can find them again.

Connected accounts

If you link a third-party account — Google, Slack, GitHub, Notion, Dropbox and others — we store an encrypted access token and, where the provider issues one, an encrypted refresh token, together with a label identifying which account is linked. We never store your password for those services.

Technical and diagnostic data

Basic operational information such as timestamps, error logs and app version. This is used to keep the service running and to diagnose faults.

We do not collect your precise location, your contacts list, or any data from your device beyond what is needed to run the app.

2. How we use what we collect

  • To provide the service — generating replies, remembering your context, and keeping your history available.
  • To carry out what you ask for — for example reading, summarising or sending something through an account you have connected.
  • To keep the service secure and working — detecting abuse, preventing unauthorised access, and fixing faults.
  • To communicate with you — password resets, security notices, and important changes to the service.
  • To comply with the law — where we are legally required to do so.

We do not sell your personal data. We do not use your conversations to train, fine-tune or improve our own AI models.

3. Google user data and Limited Use

If you connect a Google account, Colette AI requests access only to the services you approve on Google's consent screen: Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets, Google Tasks and Google Contacts. You choose what to grant, and you can revoke it at any time from your Google Account permissions or by disconnecting the account inside Colette AI's Settings.

Colette AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • Google user data is used only to provide and improve the features you explicitly ask for — reading, searching, summarising, sending or editing the items you point Colette at. It is never used for advertising, and never sold.
  • We do not transfer Google user data to third parties except where it is necessary to provide the feature you requested, to comply with the law, or as part of a merger or acquisition with notice to you.
  • We do not use Google user data to train, fine-tune or improve generalised AI or machine-learning models.
  • No human reads your Google user data, except where you ask us to, where it is necessary to investigate security or abuse, or where the law requires it.

When you disconnect a Google account, the stored access and refresh tokens for it are deleted.

4. Who we share data with

We use a small number of service providers to run Colette AI. They process data on our instructions and are not permitted to use it for their own purposes.

ProviderWhat it doesWhat it receives
Google (Gemini API) Generates the assistant's replies and powers AI features The text of the messages and documents it needs to process to answer you
Supabase Database and file storage Your account record, conversations, and uploaded files
Google Firebase Sign-in and account authentication Your email address and authentication credentials
Render Hosts the backend service Traffic to and from the API
Netlify Hosts the web application Traffic to the web app

Your messages are processed by Google's Gemini API. To generate a reply or produce an image, the relevant content is sent to Google as part of a Gemini API request. This is how the assistant functions, and it means conversation content leaves our own infrastructure to be processed.

Separately, services you connect — such as Google, Slack or GitHub — receive data only when you ask Colette to use them on your behalf. We may also disclose information where we are legally required to, or where it is necessary to protect the rights and safety of our users.

5. Where your data is stored, and for how long

Data is transmitted over encrypted connections (TLS). Connected-account tokens are additionally encrypted at rest with AES-256-GCM, so a database copy alone does not expose them.

  • Conversations and uploads are kept until you delete them. Deleting a chat removes it from the active database; residual copies may persist briefly in encrypted backups before being rotated out.
  • Connected-account tokens are deleted immediately when you disconnect that account.
  • Your account — deleting your account removes your profile, conversations, uploads and connections.
  • Diagnostic logs are kept for a short period for security and troubleshooting, then discarded.

6. Your rights and choices

You can, at any time:

  • See and correct your account details in Settings.
  • Delete individual conversations, or delete your entire account.
  • Disconnect any linked account from Settings, which deletes its stored tokens.
  • Revoke Google access directly from your Google Account permissions.
  • Ask us for a copy of your data, or for it to be erased, by emailing masteralexleoreevesd1@gmail.com. We aim to respond within 30 days.

Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA. We honour those requests regardless of where you are.

7. Children

Colette AI is not intended for children under 13, or under the minimum age required in your country. We do not knowingly collect data from children. If we learn that a child below that age has created an account, we will delete it and the associated data.

8. International transfers

Our service providers may store and process data in countries other than your own, including the United States and the European Union. Where data is transferred internationally, we rely on our providers' contractual safeguards and standard data-protection measures.

9. Changes to this policy

If this policy changes, we will update the date above. For material changes we will give notice in the app or by email before they take effect.

10. Contact us

Questions about privacy, or a request about your data, can be sent to masteralexleoreevesd1@gmail.com. See also our Terms of Service.