Arc Marabot

A private personal assistant, run by one person, for one person.

Privacy policy

Last updated 15 September 2026

The short version

Arc Marabot is used by exactly one person: its owner and operator, Mark Shidran. The only Google Account it connects to is his own. It reads his own mail, calendar, contacts, files and tasks in order to answer his own questions. Nothing is sold, and nothing is shared with anyone except the language-model providers that generate the assistant's replies, described below.

Who operates this application

Mark Shidran, an individual. Contact: mark.shidran@gmail.com. The application runs on a private server rented and administered by him. There is no company behind it, no staff, and no other operator.

Whose data this covers

Only the operator's own. Arc Marabot is not offered to other users and has no way to accept them: the Telegram bot it runs on ignores messages from every account except the operator's, and no second Google Account has ever been connected. If you are reading this policy because you saw this application's name on a Google consent screen, and you are not Mark Shidran, do not grant it access.

What Google data it accesses, and why

The application requests only the access it actually uses. Each item below corresponds to a permission shown on the Google consent screen.

Access requestedWhat it is used for
Gmail — read and manage messages Reading recent and unread mail to answer questions about it and to build the morning digest. Marking messages read, archiving and labelling, and sending mail — each send happens only after the operator confirms that specific message.
Gmail — basic settings Used only when the operator asks for a vacation auto-reply to be turned on or off. Not read or changed otherwise.
Google Calendar Reading events to answer scheduling questions and to build the morning digest. Creating, changing or deleting an event only on explicit, per-event confirmation.
Google Contacts and directory Resolving a name the operator mentions to the right email address, so mail and invitations go to the intended person.
Google Drive, Docs and Sheets Finding, opening and exporting the operator's own documents and spreadsheets when he asks about their contents; writing to a spreadsheet only on confirmation.
Google Tasks Reading the operator's task list for the morning digest and overdue reminders, and mirroring it into his own private notes. Adding or completing a task on his instruction.
Account identity (name, email address) Confirming which Google Account the stored authorisation belongs to.

How the data is handled

Reading is on demand

Google data is fetched when a request needs it — when the operator asks a question, or when a scheduled job assembles the morning digest, checks for unread mail, or mirrors the task list. There is no bulk export and no continuous copying of a mailbox or drive.

What is stored, and where

The authorisation token itself is stored on the private server in an encrypted credential store readable only by the server's administrative account. Answers and digests produced by the assistant, which may quote parts of the data they were built from, are kept in the operator's own private notes and conversation history on that same server, and in his own encrypted off-site backups. None of this is public.

Language-model providers

The assistant's replies are generated by large language models that the operator does not host himself. To answer a question about a message or an event, the relevant content is sent to the model provider — currently OpenRouter, which routes the request to the model vendor serving it — and to an embedding service used to search the operator's own notes. This is the one category of third party that sees any of this data, it sees only what a given request requires, and it is disclosed here so that it is not a surprise. No data is sent to advertisers, data brokers, or analytics services, and none of it is sold.

Retention and deletion

Stored notes, conversation history and backups are kept while they are useful to the operator and deleted by him at will. Revoking the application's access, as described below, stops all further reading immediately.

Security

The server is administered by the operator alone. Credentials are held in an encrypted store, outside the application's source code and outside version control. Any action that would change data on Google's side is refused by default and runs only after the operator approves that individual action.

Withdrawing access

Access can be withdrawn at any time from Google Account → Data & privacy → Third-party apps & services, by removing Arc Marabot. The stored token stops working the moment it is revoked.

Limited use

Arc Marabot's use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Changes to this policy

If what the application does with the data changes, this page is updated and the date at the top changes with it.

Contact

Questions about this policy: mark.shidran@gmail.com