FamiliarPrivacy

Last updated August 15, 2026

Your data is there to help you.

Familiar gives one person one private agent. We use your data to provide the features you ask for. We do not sell it, use it for advertising, or use Google Workspace data to develop, improve, or train generalized, non-personalized AI or machine-learning models.

What Familiar keeps

Your account identifies you as the owner of an agent. The agent keeps the conversations, preferences, and memory needed to work with you over time. Its memory lives on its private agent volume; operational records and encrypted connection records live in the control plane. Deleting an agent leaves a scrubbed operational tombstone for lifecycle and admission accounting; it contains no conversation, memory, or Google credential.

Familiar uses Composio to operate its narrow Calendar feature and each external integration that you separately choose. Composio stores and refreshes the provider credentials. Familiar sends Composio a pseudonymous agent identifier and keeps opaque connected-account and auth-configuration identifiers plus requested-scope and bounded display-identity snapshots; those display values are not treated as verified identity. No connection path places a provider credential in your agent's machine.

The Understanding is a correctable mirror

As you work and talk together, your agent can add useful facts to the Understanding. Some are things you stated directly, kept with your own words as the supporting excerpt. Others are things your agent worked out from your conversations; those are labeled as its own conclusions, never as your words. Know Thyself lets you inspect, correct, or remove any of them.

Guesses about health, protected identity, or finances are held to a stricter rule: they are shown only inside Know Thyself, only as a possible pattern rather than a statement about you, and they are never sent to your phone or counted in anything that draws your attention. A guess that reads as a crisis is not shown in that room at all. Nothing in the Understanding carries a score or a confidence figure, because there is no honest one to give.

Removing a fact deletes it and its supporting Understanding evidence from Familiar and prevents that old source from recreating it. Something you say later can teach it again. It does not rewrite past conversations, the agent's private Memory, retained backups, or copies you already downloaded. Familiar does not use the Understanding as consent to train a generalized model or transfer a personal training corpus; any future training use would require a separate, explicit choice.

Deeper Memory and the memory partner

Every agent forms an Understanding of you from your conversations with it. Where that thinking happens is your choice. With Standard memory it happens inside Familiar and nothing leaves for this purpose. With Deeper Memory, which you turn on yourself and are never opted into, your conversation content is processed by our memory partner, Plastic Labs, in the United States, under our agreement with them — as it is by the model providers they use to do it. We have asked that none of it be used to train models. What they work out is stored in a space reachable only by your agent.

If you save voice notes, whether their contents reach the memory partner is a second, separate choice. Answer yes and the words of each saved note are sent as their own record, so your agent understands what you recorded. Deleting a note removes what it learned directly from that note within a few minutes. Anything already folded into its wider sense of you, or said back to you in a conversation, may remain. Answer no, or say nothing, and your notes stay between you and this app.

Nothing is deleted on a schedule. Switching Deeper Memory off disconnects your agent — its key is removed from its machine — and keeps what it understood, so switching back on loses nothing. When you want that understanding gone, Care has a control that deletes it: we drain the stored sessions, delete the space, and confirm it is absent before we tell you it is done. Saying goodbye to your agent does the same thing without being asked. In both cases the partner's own backups and logs age out within 90 days.

What Calendar access does

Google's permission covers events on calendars you own. Familiar's connector is deliberately narrower in this release: it addresses only your primary calendar. It can read event times, titles, descriptions, locations, and attendee email addresses. Your agent can use that information to answer a request and can prepare a proposal for a new event. It cannot edit or delete existing events, work in shared calendars, or create an event by itself.

A proposed event can include its title, time, description, location, and attendee addresses. Nothing is written to Google until you approve the exact proposal on an owner-authenticated screen. If you approve an event with attendees, Google sends real invitations to them. With a Composio connection, the approved event details and attendee addresses travel from Familiar through Composio to Google.

Where data is processed

Calendar data travels from Google through Composio, which holds the OAuth credential and executes Familiar's constrained Calendar requests, and then to Familiar's control plane. The control plane sends only the task context your agent needs to its private runtime and, when a model response is needed, through OpenRouter to the selected model provider. Composio and model processors may keep operational or abuse-prevention records under their own policies; Familiar does not promise that every request has zero retention. See Composio's current privacy policy.

For another integration you select, requested provider data travels from that provider through Composio to Familiar. This can include Gmail messages and contacts, Google Drive files, Google Docs content, Slack workspace content, GitHub repository and collaboration data, or Granola meeting notes and transcripts, depending on the exact capability you request. Familiar sends only the task context needed by your private agent through the approved model route. Connecting an account does not authorize a tool action: the owner must select the exact account and approve a capability before its first use.

Familiar reviews and records the approved model route and its data controls so Google data is not used for generalized-model training. See OpenRouter's current data collection documentation. We allow human access only when you ask for it, or when it is necessary for security, abuse prevention, or a legal obligation.

Retention and backups

A Calendar proposal contains the event details you approved, dismissed, or let expire. Terminal proposal payloads enter deletion after seven days; cleanup runs in bounded batches, so a backlog can require additional sweep ticks. A separate content-free outcome receipt (proposal identifier and terminal status only) remains until your agent receives it on a later owner turn, then enters deletion after 90 days. Composio operation audit rows keep event names and outcomes plus an opaque connected-account identifier, toolkit, and tool slug. The audit ledger stores no Calendar content and is deleted after 90 days.

While your agent exists, Familiar keeps content-free Composio account, binding, and revocation metadata so it can enforce one exact connection and finish cleanup truthfully. A completed Goodbye purges that metadata. If revocation or provider deletion is still unresolved, Goodbye remains incomplete and the content-free cleanup evidence stays on the scrubbed agent tombstone until the result converges.

Encrypted database backups and agent-volume snapshots can outlive a live-row deletion until their configured retention windows expire. Familiar records those production retention windows; we do not claim immediate physical erasure from every backup.

For a Calendar connection, Familiar first freezes the exact account binding and its unapproved proposals, then asks Composio to revoke the upstream Google tokens. Familiar requires Composio to report, in the synchronous revoke response for that exact account, that both the access-token and refresh-token credential subjects were revoked. A later REVOKED status alone is not enough. Familiar then deletes Composio's connected-account record and requires both an exact not-found response and absence from the owner's inventory. That credential-subject report is Composio's evidence of upstream revocation, not an independent confirmation from Google. Provider absence without that earlier evidence remains visible cleanup debt, not proof that the Google grant died. The OAuth credential in this path is held by Composio rather than in Familiar's encrypted database backups.

Disconnecting is not forgetting

During an ordinary Calendar disconnect, Familiar freezes access and keeps the connection visibly in the process of disconnecting until Composio supplies upstream-revocation evidence. Familiar snapshots only the names of the access and refresh credential subjects present for that exact account, then requires the synchronous response to name every one as revoked before deleting the connected account and reading back exact and inventory absence. Google grants require both access and refresh subjects; a provider that issued only an access token must still name that subject. A later revoked status is insufficient and is not an independent provider confirmation. If the provider is temporarily unavailable, Familiar keeps cleanup visible so you can retry; it does not pretend the revoke succeeded.

Disconnecting does not erase facts your agent already learned from your calendar. Like any long-running collaborator, it may have written useful facts into its own memory. Familiar does not yet offer selective “forget only Google information.” Deleting the whole agent removes its live agent memory, live connection, and login. The operational tombstone contains no conversation or Calendar content. Content-free account and revocation identifiers can remain while Familiar obtains Composio's credential-subject evidence and provider deletion proof. Provider backups and snapshots age out under their configured retention windows.

Optional Composio integrations are activated separately

Familiar offers Gmail, Google Drive, Slack, Google Docs, GitHub, and Granola through separately configured Composio connections. An owner must separately choose each provider and complete Composio's consent flow. The connection is bound to the exact selected account; it does not authorize a different account or a silent outward action.

Provider content travels through Composio to Familiar and may be sent through the approved model route only to perform the owner's requested task. Familiar does not use Gmail, Drive, Docs, Slack, GitHub, or Granola data for advertising, sale, or generalized-model training. Familiar can pause a provider when its configured policy or cleanup proof no longer matches.

Google API Limited Use

Familiar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide the user-facing feature you asked Familiar to perform for you; it is not transferred for advertising, sold, or used to train generalized AI models.