Privacy Policy

Last updated: April 24, 2026

This policy explains what information Aan ("Aan", "we", "us") collects from you when you use the WhatsApp-based assistant at aan.live, how we use it, and what choices you have. Aan is operated as a personal service; we do not sell or monetize user data.

1. What we collect

Information you send in WhatsApp

When you message Aan on WhatsApp, we receive: your WhatsApp chat ID (a phone number formatted as {number}@c.us), the text or voice note you send, and — for voice notes and images — the media file so the assistant can transcribe or analyze it. We store a rolling history of messages to keep the conversation coherent across turns.

Information you give Aan during setup

During onboarding you tell Aan your display name, timezone, preferred language, your routines (tasks with times), optional goals, and optional "not-to-do" rules. This information is stored so Aan can remind you at the right time and give context-aware replies.

Information Aan derives from your use

A log of which routine you completed or skipped each day, streak counters, and internal timing metadata for reminders.

Information from Google (only if you explicitly connect your Google Calendar)

If you tap the "connect calendar" link and grant consent, Google returns an OAuth refresh token and access token to Aan. Aan uses these tokens solely to fetch a read-only view of your upcoming calendar events (the https://www.googleapis.com/auth/calendar.readonly scope). For each enabled calendar, Aan stores a cached copy of events within a sliding 7-day window — event title, location, start/end time, whether it is an all-day event, whether it is private, and your RSVP status. Aan never writes to your calendar.

2. How we use your information

We do not use your messages, routines, logs, or calendar data to train machine-learning models, show advertising, or build a profile of you.

3. Google API Services User Data Policy — Limited Use disclosure

Aan's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Aan:

4. Where your data is stored

All data is stored in Cloudflare D1 (SQLite), encrypted at rest by Cloudflare. The Worker processing your messages runs on Cloudflare's edge network. No data is stored on our personal machines. We do not operate traditional servers.

5. Third-party sub-processors

To run the service, Aan passes specific information to the following providers:

6. How long we keep your data

7. Your choices

8. Security

We follow industry-standard practices: HTTPS for all transport, encrypted storage at rest, signed OAuth state tokens with short TTL (10 minutes), and the minimum OAuth scope needed (calendar.readonly — read-only, no write permissions). We do not have a SOC 2 report; this is a solo-operator service.

9. Children

Aan is not intended for children under 13. Do not connect a child's Google account.

10. Changes to this policy

If we change this policy materially, we will send a notification via WhatsApp to each user and update the "Last updated" date at the top. Continued use after notification constitutes acceptance.

11. Contact

Questions, requests, complaints: company@aan.live.