Privacy Policy
Last updated: September 6, 2026
1. Who we are
Daily Summarizer ("the Service", "we", "us") is operated by Stéphane Molano, trading as Creasteph, based in France. The Service is hosted at summarizer.creasteph.net. For any privacy-related question, contact contact@creasteph.net.
2. What the Service does
Daily Summarizer is a personal productivity tool that aggregates the user's own daily activity from connected accounts (Google Calendar, Gmail, GitHub, Slack) and from local sources (git repositories, shell history) to generate a single AI-assisted daily report. It is designed for individual use: each account's data is isolated and is not shared with, joined to, or made visible to any other user.
3. Information we access and collect
3.1 Account information
When you create an account, we store your name, email address and a hashed password. When you connect a third-party provider via OAuth, we additionally store the provider's user identifier, an access token, an optional refresh token, the granted scopes and the token expiry. Tokens are stored encrypted at rest in our database and are used only to call the provider's API on your behalf.
3.2 Data accessed via Google APIs
With your consent, the Service accesses the following Google data through the official Google APIs:
- Profile (
openid,email,profile) - to identify your Google account inside the app. - Google Calendar (
calendar.readonly) - to list events on the requested day, their duration, and the email addresses of attendees. - Gmail (
gmail.readonly) - to list email threads on the requested day, detect threads you responded to, and extract the corresponding contact email addresses.
Google API Services User Data Policy - Limited Use disclosure. Daily Summarizer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy , including the Limited Use requirements. Specifically:
- We use Google user data only to provide the daily-summary feature you requested.
- We do not sell, trade, or transfer Google user data to any third party for advertising, resale, or any other purpose unrelated to the Service.
- We do not use Google user data to train, fine-tune, or improve any generalized or third-party AI/ML model.
- Humans do not read your Google user data, except (a) with your explicit consent, (b) for security purposes (e.g. investigating abuse), (c) to comply with applicable law, or (d) when the data has been aggregated and anonymised for internal operations.
3.3 Data accessed via Slack APIs
With your consent, the Service accesses your Slack data through user-token scopes only
(no bot installation): channels:read, channels:history,
groups:read, groups:history, im:read,
im:history, mpim:read, mpim:history,
users:read, search:read. These are used to find the messages
you authored on the requested day and to resolve user IDs to display names.
3.4 Data accessed via GitHub APIs
With your consent, the Service accesses your GitHub data through the scopes
read:user, user:email and repo, in order to list
the commits, pull requests, code reviews and issues you authored on the requested day,
including in private repositories you have access to.
3.5 Data sourced locally
The desktop application can read commits from local git repositories you explicitly
register, and the shell history file (~/.zsh_history or ~/.bash_history)
of the operating-system user running the app. This data is sent only to the Service's own
backend that you operate.
3.6 Generated data
The Service generates and stores: the daily activity items it ingests, the daily reports it produces, knowledge-base entries (project names, recurring contacts, clarifications), and configuration entries (tracked repositories, preferences). All generated data is scoped to the authenticated user.
4. Use of AI / large language models
To produce the daily report and to extract knowledge entries, excerpts of your activity are sent to a third-party large-language-model provider (Anthropic Claude). Only the minimum content required to produce the report is transmitted. We do not allow the provider to use this data to train its models, and the data is not shared with any other party. As stated above, Google user data is never used to train any AI/ML model.
5. Storage, retention, and security
- Data is stored on infrastructure operated by Creasteph, located in the European Union.
- OAuth access and refresh tokens are stored encrypted at rest.
- Passwords are stored using a one-way bcrypt hash; we never see your password in plain text.
- Activity data older than 90 days may be automatically pruned by the retention command. You can shorten this window or wipe data on demand at any time (see Section 7).
- Access to the database is restricted to the operator and is protected by infrastructure-level controls.
6. Sharing of data
We do not sell, rent, or share your personal data with third parties for marketing purposes. Data is transmitted only to: (a) the AI provider strictly for the purpose of generating your report, and (b) the third-party providers you have connected, when calling their APIs on your behalf.
7. Your rights and how to delete your data
Under the GDPR you have the right to access, correct, export and delete your personal data. To exercise these rights:
- Disconnect a provider - from the Connections page inside the app, which immediately revokes and deletes the corresponding OAuth tokens.
- Delete activity - from the Settings page, by selecting a date range and confirming the deletion.
- Delete your entire account - email contact@creasteph.net from the address registered to your account; we will permanently delete your user record, OAuth connections, activities, reports and knowledge entries within 30 days.
- Revoke access from your provider - you can also revoke our access at any time from Google, GitHub, or Slack.
See the dedicated Data Deletion page for step-by-step instructions.
8. International transfers
The AI provider used to generate reports may process data outside the European Economic Area (notably in the United States). Such transfers are covered by the provider's Standard Contractual Clauses and equivalent safeguards.
9. Children
The Service is not directed to children under 16 and we do not knowingly collect data from them.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the latest revision. Material changes will be communicated by email to active users.
11. Contact
Stéphane Molano (Creasteph) - contact@creasteph.net.