Privacy policy
Last updated: 2 October 2026
Rund is a private, self-hosted assistant with a single user: its operator. This policy describes how Rund handles data from the operator's Google accounts. No data from any other person's Google account is accessed, because no one else signs in to Rund.
Data accessed
- Basic profile information (email address and name), used only to identify which of the operator's accounts is connected.
- Google Calendar data: the list of calendars and their events (titles, times, locations, descriptions, attendees and invitation status).
How the data is used
- To answer the operator's own questions about their schedule.
- To create, change or delete events and to answer invitations, only when the operator asks for it and approves each change.
Data is not used for advertising, profiling, sale, or training machine-learning models, and it is not shared with anyone except as described below.
Processing and storage
- Rund runs on a server controlled by the operator. OAuth tokens are stored on that server with access restricted to the account running Rund.
- To generate a response, the relevant calendar data is sent to the operator's language-model provider (Mistral AI, via its API) and the response is shown to the operator in a private Matrix room.
- Conversation history, including calendar details mentioned in it, is kept on the operator's server so the assistant can refer back to earlier messages.
Google API Services User Data Policy
Rund's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access and deleting data
Access can be revoked at any time on the Google Account permissions page. The operator can delete the stored tokens and conversation history from the server at any time.