FilsOnly ("we," "our," or "the app") is a personal AI executive assistant application. This policy explains what data the app accesses, how it's used, and — just as importantly — what we deliberately do not collect or store.
Microsoft Outlook / Microsoft 365 (via Microsoft Graph API)
With your explicit consent through Microsoft's OAuth sign-in flow, the app accesses:
This access is governed by Microsoft's own authentication system. We never see or store your Microsoft account password. You can revoke this access at any time through your Microsoft account security settings, or by disconnecting within the app.
Google Gmail (via Gmail API)
With your explicit consent through Google's OAuth sign-in flow, the app accesses:
This access is governed by Google's own authentication system. We never see or store your Google account password. The app does not access your Gmail calendar, contacts, or any other Google service beyond the two Gmail scopes described above. You can revoke this access at any time through your Google Account's third-party access settings, or by disconnecting within the app.
You connect either Outlook or Gmail (not both simultaneously in the current version), depending on which email provider you choose during sign-in.
Your AI provider (Anthropic or OpenAI)
You provide your own API key for an AI provider of your choice. When the app triages emails or drafts replies, it sends relevant email content directly from your device to your chosen AI provider's servers, using your own API key and billed to your own account. We do not proxy, log, or have visibility into these requests.
Memory and search features (embeddings)
To power features that let you ask about past emails or receive proactive reminders about conversations that need follow-up, the app converts email text into numerical representations called "embeddings." This is the one part of FilsOnly that is not entirely peer-to-peer: generating an embedding requires a small server-side function that we operate, which calls OpenAI's embedding API on your behalf using our own API key, not yours.
Specifics of how this works:
If you'd prefer not to use this feature, you can decline to use memory/search features within the app; core triage and reply functionality does not depend on it.
All data used by FilsOnly is stored locally on your device using on-device storage (SQLite) and secure encrypted storage (for your API key). This includes:
None of this data is transmitted to or stored on any server operated by FilsOnly, because FilsOnly does not operate a backend server for personal use of the app.
If you enable background sync, the app periodically checks your inbox in the background (even when closed) using the same direct device-to-Microsoft and device-to-AI-provider connections described above, and may show you a local notification for urgent items. This processing happens entirely on your device; no data is sent to us as part of this feature.
We do not sell, rent, or share your data with third parties. We have no access to your email content, calendar data, or AI usage to share in the first place.
Because your data is stored locally on your device, uninstalling the app removes all locally stored data. Disconnecting your Microsoft or Google account within the app (or from that account's own security settings) revokes the app's access to your email and calendar.
FilsOnly is not directed at children under 13, and we do not knowingly collect data from children.
If this policy changes, we'll update the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.
Questions about this policy or the app's data practices can be sent to hello@filsonly.com.