Privacy policy
Woody by Wotobo · Effective September 15, 2026
Woody is a personal AI assistant running as a private pilot. This policy applies to the assistant and the public Wotobo website.
Operator and contact
The project is operated by Tomáš Wolf under the name Wotobo. Send questions about personal data, access requests or deletion requests to wolft.thomas@gmail.com.
Data Woody may access
Access to your Google account is established only after you grant consent on Google's authorization page. Its scope depends on the permissions granted and the tools enabled:
- Account identity: email address and basic profile information to distinguish connected accounts.
- Gmail: messages, their contents and attachments, senders, recipients, threads and labels needed for a task.
- Calendar: calendar lists, events, dates and times, descriptions, attendees and availability.
- Drive, Docs and Sheets: file names and metadata, document and spreadsheet contents, and related information needed for a task.
- Conversations and assistant operations: your instructions, responses, approvals, tool results and task history.
How and why we use data
Data is used for the features you request: finding and summarizing information, working with email, planning, analyzing documents and preparing outputs. It may also be used for explicitly configured recurring tasks and technical troubleshooting.
Permission to write is not itself an instruction to make a change. Sending, editing, deleting and sharing through connected Google tools require approval in the application.
We do not use Google data for sale, advertising targeting or building databases for unrelated purposes. We do not use it to develop or train our own general-purpose AI models.
Cloud models and other recipients
The application combines local and cloud models. When a cloud agent handles a task, the instructions and relevant tool results, including Google data, may be sent to the provider of that model: OpenAI, Anthropic or Google. A self-hosted server therefore does not mean all processing takes place locally.
When you use Telegram, Telegram processes the messages and attachments you send and the responses delivered to you. Ordinary bot conversations are not end-to-end encrypted. Content from connected accounts is not published on this public website.
Cloud service providers have their own terms, processing locations and retention periods. They may process data outside the user's country. The specific rules depend on the service, subscription and account settings used; this application does not promise zero retention by those providers.
Storage and protection of access credentials
The assistant's configuration and history are stored on the operator's server. The Google connection uses OAuth; the application does not store your Google password. Authorization tokens and client credentials are kept separate from the public website and ordinary agent instructions.
Access to the private application is restricted and protected by authentication. The server administrator technically has access to the data stored on it. No technical measure can provide an absolute guarantee of security.
How long we retain data
Connections and authorization credentials are retained while the connected account is in use, until they are removed. Task history and outputs may remain stored after a task is completed or an account is disconnected; the pilot does not yet have an automatic history deletion period. The operator removes history during cleanup or at a user's request.
Any copies held by cloud providers and Telegram are subject to their own deletion options and retention rules. Deletion from Woody does not automatically delete them from those services.
Revoking access and deleting data
- In your Google account connections, select Woody by Wotobo and remove its permissions. This prevents further access to the account through that connection.
- To remove the stored connection and history, email the contact address. Specify the account and the scope of your request; do not send a password or token.
- The operator will verify your identity in a proportionate way and confirm the outcome. Revoking access does not itself delete previously stored tasks.
You may also request information about processing and a copy or correction of data relating to you.
Visiting the public website
This website contains no analytics or advertising tools, uses no cookies and does not load fonts or images from third-party services. The web server keeps technical records for operation and security, such as IP address, timestamp, request path and result. The access log does not store form contents or URL query parameters.
Technical web logs are normally rotated daily, with at most 14 rotated files retained alongside the current log. These are separate from the assistant's task history. Following an external link takes you to another service with its own policies.
Google policies and changes
The use and transfer of information obtained from Google APIs must comply with the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only for the specific user-facing features described above.
Changes to features or data handling will be reflected in this policy, with an updated effective date. New account permissions require separate consent through Google.