actual.me

Privacy Policy

Effective date: August 17, 2026 Last updated: August 19, 2026

My Actual Me, Inc. ("Actual Me," "we," "us") operates myactual.me. This policy explains what we collect, why, who can see it, and how to remove it.

Questions or requests: nlawrence@myactual.me


The short version

Actual Me lets you connect accounts you already use — your calendar, your code repositories, your fitness ring — and builds an agent called Candor that answers questions about you using only that verified data.

Six things worth knowing up front:

  1. You choose every source. Nothing connects unless you connect it.
  2. Candor speaks only from data you connected. If it has no evidence, it says so.
  3. Some data can never be shown to anyone but you, regardless of your settings. Your email metadata is in this category, permanently, by design.
  4. Some data we hold, we will not send to an AI model at all — because the platform it came from prohibits it. We name them below.
  5. We use no advertising, no analytics, and no tracking. Not one third-party analytics, error-tracking, or session-recording tool runs in this product.
  6. You can delete your account and everything in it, permanently.

1. Information we collect

1.1 Account information

At signup we collect your email address, and nothing else.

During setup we ask for a display name, a handle (your public URL), and your primary goal for using Actual Me. Your browser's timezone is detected automatically. You may add a profile photo, stored with Cloudinary.

We use magic-link sign-in (a one-time link emailed via Resend) and Sign in with Google. Signing in with Google gives us your name, email address, and profile picture — for authentication only. Signing in never grants us access to your Google data; that is a separate, explicit step you take later.

We never ask for a password, so we never store one.

1.2 Sources you can connect

Each connection is a separate, explicit act. We request the narrowest access that supports the feature, and we never request write access to any account.

Connected accounts:

Source What we retrieve
Google Calendar Event titles, start and end times, duration, all-day flag, and attendee counts. You may block entire calendars — blocked calendars are never queried — and filter events by keyword. See section 3.
Google Gmail Metadata only, never message bodies. Not yet available; see section 3.2.
GitHub Only the repositories you select at install time. Metadata, contribution counts, and file contents for those repositories.
Slack Activity patterns — channel counts, unread counts, timezone, status, display name. No message content.
Notion Workspace activity metadata only — page counts and dates. Never page titles, content, or collaborator information.
Oura Sleep, readiness, and heart-rate-variability metrics.
Banking Via Plaid. Transaction summaries and spending categories.

Files you upload:

Source What we read
Instagram From an export you download from Instagram and upload to us: likes, posts, saves, follows, and interests. Your DMs, comments, and personal information stay on your device and are never uploaded.
Facebook From an export you download from Facebook: posts, reactions, friends, pages, groups, and interests. Your DMs, comments, and personal information stay on your device and are never uploaded.
Documents Résumés, writing samples, or other files you choose to upload.

We are not connected to Meta and never have been. Instagram and Facebook data reaches us only because you exported it yourself and chose to upload it.

Currently paused: we previously synced Strava and Spotify and have stopped, because those platforms' terms conflict with how this product works (section 5.1). Data already synced is retained for you until you disconnect it or delete your account.

We do not sell your data. We do not use it for advertising. We do not use it to train AI models.

1.3 What we deliberately do not collect

1.4 Analytics, tracking, and logs

We use no third-party analytics, product telemetry, error tracking, session recording, or advertising SDK. No Google Analytics, no Segment, no Sentry, no ad network, no data broker.

Our servers keep operational logs, and those logs can contain your email address (when a sign-in link is sent), your account identifier, and the names of sources you connect or request. Logs never contain message content, event titles, or file contents. They exist for debugging and are held by our hosting provider, Render.


2. Who can see what

The boundaries below are enforced in code by filtering data before it reaches the agent — not by instructing the agent to be discreet.

2.1 Visible to any signed-in visitor

GitHub activity and repository descriptions, Calendar patterns, Slack activity patterns, and documents you have explicitly marked public.

2.2 Visible to people you approve (your Circle)

Everything above, plus health and location signals where you have connected them. You are shown exactly what Circle membership grants before you grant it, and you can revoke it at any time.

2.3 Visible only to you — permanently

Gmail metadata can never be shown to any other person, in any audience, under any setting. There is no toggle that changes this. Your mailbox is correspondence with people who never agreed to anything.

Notion and banking data are also owner-only.

2.4 Uploaded documents

Private by default. A document becomes visible to others only if you explicitly mark it public. A résumé you publish for a recruiter is public; a performance review you upload for your own use is not.


3. Google user data

3.1 Limited Use disclosure

Actual Me's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3.2 What we access and why

Google Calendar is the only Google data source currently available. Gmail metadata is described here because the capability is built, but it is not yet offered — it requires an additional Google security review we have not completed. No Actual Me user can connect Gmail today.

Scope Permits Why we request it
email, profile, openid Your name, email address, profile picture Sign-in only
calendar.readonly Read your calendars and events Time-allocation patterns — how you actually spend working time
gmail.metadata Read message metadata only — no bodies, no search Response-time and sending-rhythm patterns

These are requested at different moments. Signing in requests identity only. Google Calendar and Google Gmail are separate connections, each requested at the moment you connect that source and never at sign-in. They are independent: connecting one never grants access to the other.

3.3 Specifically regarding Gmail

As stated in section 3.2, Gmail is not yet offered and no Actual Me user can connect it today. This section describes the capability as built, for when it becomes available.

The gmail.metadata scope does not permit reading message content and does not permit search. We request message timestamps, thread identifiers, and one header (In-Reply-To).

We do not retain per-message records. Individual message identifiers and timestamps exist only in memory during analysis and are discarded when it completes. What we store is statistics: total messages sent, average per day, busiest day of week, top sending hours as percentages, percentage sent outside business hours, a consistency score, and average and median reply times.

These are facts about you, not about the people who write to you.

Gmail-derived data is never shown to any other person on the platform.

3.4 Revoking Google access

Google Calendar and Google Gmail are separate connections, and each can be disconnected from inside Actual Me. Disconnecting one is handled like any other source — see section 7.1.

Signing in with Google grants identity only. Sign-in does not connect either data source, and it does not restore one you have disconnected.

To revoke our access at Google itself, use myaccount.google.com/connections. That takes effect immediately. Deleting your Actual Me account (section 7.2) also revokes it.


4. How we use your data

To compute patterns about you; to let Candor answer questions from you or from people you have authorized; and to answer verification requests you have accepted.

We do not use your data for advertising, sell or rent it, or use it to train any AI model.


5. AI processing and our AI provider

Candor is built on models from Anthropic. When Candor answers a question, relevant summaries of your data are sent to Anthropic's API.

Anthropic's commercial terms state that inputs and outputs from the Anthropic API are not used to train their models. Anthropic's published commercial retention policy deletes API inputs and outputs within 30 days.

We send computed summaries, not raw data — statistics about your calendar and email rhythms, not your events or your messages.

5.1 Sources we will not send to any AI model

Some platforms prohibit their data being used with AI models. We honor those terms by excluding those sources from AI processing entirely — even for your own private use.

We still display this data to you. Candor cannot see it, and will tell you so rather than pretend otherwise.

5.2 Human access to your data

No feature of Actual Me lets one user see another user's private data. Every data route derives identity from your authenticated session. There is no administrative interface, no support impersonation, and no route that reads one account while authenticated as another.

Separately: we operate the database, and our engineers can access it directly for debugging, maintenance, and incident response. This is true of essentially every online service, and we would rather state it than imply otherwise. Access is limited to personnel who need it, and our internal practice is to work from counts and structure rather than reading individual records.


6. Data sharing

We share your data with:

These are the only third parties that receive your data. When you connect a source, we of course communicate with that provider — Google, GitHub, Slack, Notion, Oura — to retrieve the data you authorized.

We do not sell your personal information.


7. Retention and deletion

7.1 Disconnecting a source

Disconnecting a source deletes the data we synced from it, deletes our stored access tokens, removes the facts that source contributed to your profile, and attempts to revoke our access with the provider. Where a provider offers no revocation endpoint, we tell you so and direct you to revoke it in that service's own settings.

Three things to know:

  1. Your weekly insight history is deleted entirely — not only the parts from that source. Insights blend several sources into prose that cannot be separated afterward, so we delete rather than leave behind something we cannot honestly attribute. This is not restored.
  2. Your conversations with Candor are not deleted, nor are documents you uploaded. Those are separate, and you can clear or delete them separately.
  3. Google Calendar and Google Gmail are disconnected separately — each is its own connection, and each can be disconnected here. See section 3.4.

7.2 Deleting your account

Deleting your account permanently deletes everything: your profile, every connected source's data, all synced data, uploads, chat history, insights, and access tokens. We also delete your profile photo and attempt to revoke every provider token — and if any provider could not be revoked automatically, we tell you which ones, both on screen and in the confirmation email, so you can finish the job yourself.

This cannot be undone.

You can delete your account from the Account tab in your dashboard.

7.3 How long we keep data

We keep your data until you delete it. There is no automatic expiry: no retention timer, no scheduled purge. Synced data is refreshed on a schedule, replacing the previous copy.

Two exceptions: sign-in links expire after 60 minutes, and invitations expire after 7 days.

If you want your data gone, you have to tell us — by disconnecting a source or deleting your account. We would rather say that plainly than imply a cleanup that does not happen.


8. Your rights and controls

Within Actual Me you can: see every connected source and when it last synced; disconnect any source (see section 7.1); see and revoke every person you have granted access to; mark uploaded documents public or private; delete uploaded documents; clear your Candor conversation history; block calendars or filter events by keyword; control whether your profile is discoverable; and delete your account.

Depending on where you live, you may also have rights to access, correct, delete, or export your data. To exercise these, contact nlawrence@myactual.me.


9. Security

Data is encrypted in transit. Sessions are signed tokens that can be invalidated centrally, and signing in never exposes a password because we do not use passwords. Our database is hosted by Render with encryption at rest at the storage layer.

Access tokens for your connected accounts are stored in our database without an additional layer of application-level encryption. We state this because it is true.

No system is perfectly secure, and we do not claim otherwise.


10. Children

Actual Me is intended for adults and we do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact nlawrence@myactual.me and we will delete it.


11. Where Actual Me is offered

Actual Me is intended for users in the United States. Our servers are located in the United States, and if you use the service from elsewhere your data is processed here.


12. Changes to this policy

We will post changes here and update the date above. For material changes — particularly any change to what we collect or who can see it — we will notify you directly and, where required, ask for your consent again.


13. Contact

nlawrence@myactual.me

My Actual Me, Inc. 980 N Michigan Ave, Ste 1090 Chicago, IL 60611 United States