Privacy Policy
Miller Family Bots · Effective 15 September 2026 · Last updated 15 September 2026
Miller Family Bots ("the Application") is a private, self-hosted set of personal assistants used by the Miller family. This policy explains what Google user data the Application accesses, why, how it is stored, and the limits on its use.
Scope. The Application is for the Miller family's own use. It is not offered to the public, has no public sign-up, and does not serve third-party users. Only Google Accounts explicitly added by the family administrator can connect.
1. What Google user data we access
Each assistant connects only to the Google Account of the family member it was set up for, after that person grants consent through Google's standard OAuth screen. Depending on the account, the Application may request the following Google API scopes:
| Scope | What it allows | Why it is used |
|---|---|---|
gmail.modify |
Read, search, label, archive and send mail | Find and summarise the user's own messages; draft and send mail on request; build a searchable archive of the family's own email |
gmail.settings.basic |
Read and manage basic Gmail settings | Read signature, label and filter configuration so the assistant behaves consistently with the account |
calendar |
Read and manage calendars and events | Answer "what's on today", add and move events at the user's request |
drive |
See, edit, create and delete files in Google Drive | Locate and open the user's own documents; save files the user asks to be saved |
documents |
Read, edit, create Google Docs | Read and revise the user's own documents on request |
spreadsheets |
Read, edit, create Google Sheets | Read and update the user's own sheets on request |
tasks |
Read and manage Google Tasks | Keep the user's own to-do list: add, complete and list items |
contacts.readonly |
Read the user's contacts | Resolve names to addresses when the user asks to email or invite someone |
userinfo.email, openid |
Basic profile: email address and account identifier | Identify which connected account a request belongs to |
No data from any other Google service is requested. The Application does not request offline access beyond the refresh token needed to operate between sessions, and it does not request access to any Google Account other than the one granting consent.
2. How the Google user data is used
Google user data is used only to carry out requests made by the account holder themselves. Specifically:
- Answering the user's own questions about their own email, calendar, files, tasks and contacts.
- Carrying out actions the user explicitly asks for — sending a message, adding an event, creating or editing a document, updating a task list.
- Building and searching a local archive of the family's own email, so the family can search its own correspondence offline. This archive contains only the mailboxes of family members who have connected their accounts.
There is no automated bulk harvesting, no behavioural profiling, no advertising use, and no automated decision-making about any individual.
3. Where it is stored
All data is stored on privately owned hardware on the Miller family's own home network. The Application is self-hosted: there is no cloud vendor, no third-party hosting provider, and no external database service in the path.
Authentication tokens issued by Google are stored on that same family-owned hardware, encrypted at rest, and are readable only by the service that needs them. Each family member's credentials are kept in an isolated store, so one family member's assistant does not hold another's tokens.
Data is retained only as long as the family member remains connected. Disconnecting the account stops all further access; on request, the stored copy is deleted.
4. How it is shared
It is not shared. Google user data obtained through the Application is not sold, rented, traded or otherwise transferred to any third party. It is not transferred to advertisers, data brokers, or analytics providers. It is not used for advertising or ad personalisation.
The single exception is where disclosure is required by law — for example, a valid subpoena or court order — in which case only the data actually compelled would be disclosed, and the affected family member would be told unless legally prohibited from being told.
No employee, contractor or agent of any kind outside the Miller family has access to this data.
5. Use in AI models
Google user data accessed by the Application is not used to develop, improve or train any machine learning or artificial intelligence model, whether ours or a third party's. It is not used to train generalised models, and it is not fed into any public model.
Requests to the assistants are processed by language models. Routine processing runs on the family's own hardware. Where a request requires a hosted model, only the specific content needed to answer that one request is transmitted, and that content is not retained by us for model training.
6. Google API Services User Data Policy
The Application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, and consistent with Limited Use:
- Google user data is used only to provide and improve the user-facing features described in this policy.
- It is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to users.
- It is not used for serving advertisements, including retargeting, personalised or interest-based advertising.
- It is not used for any purpose that requires the sale of the data.
- No humans read the data, except (a) with the user's explicit consent for a specific request, (b) where necessary for security purposes such as investigating abuse, or (c) where required by law.
7. Security
Access to the systems holding this data is limited to the family administrator. Credentials are held in an encrypted secret store rather than in application configuration files. Network access to connected services is restricted to the family's own network, and traffic to Google is carried over HTTPS.
8. Your controls — revoking access
Access can be revoked at any time by the account holder, without needing to ask anyone. Revoking access immediately invalidates the application's tokens and stops all further access to that Google Account.
- Go to myaccount.google.com/connections (Google Account → Security → Third-party apps & services).
- Find Miller Family Bots in the list of connected apps.
- Select it, choose Delete all connections you have with Miller Family Bots, and confirm.
You can also ask the family administrator to disconnect the account and delete the locally stored copy of the data.
9. Children
Assistants may be set up for family members under 18, always with the involvement and consent of a parent or guardian who holds and administers the account. The Application does not knowingly collect data from anyone outside the family.
10. Changes to this policy
If this policy changes in a way that affects how Google user data is handled, the updated version will be posted at this URL with a revised "Last updated" date. Because the Application is private and limited to a known set of family accounts, changes are also communicated to those family members directly.
11. Contact
Questions about this policy, or requests concerning data held by the Application, should go to the family administrator:
Jordan Miller — jordan.d.miller@gmail.com