Private pilot · Updated 8 October 2026

How EFA handles data

EFA (Executive Function Assistant) is a self-hosted personal assistant. Its instance operator controls the application, connected accounts and stored records. This notice describes the current private pilot, which has no public registration.

Information used

EFA stores intentions and context supplied by its user, source references, reminder times, replies, and history. Provider message identifiers support duplicate prevention and recovery.

With Google authorisation, EFA checks calendar availability and can read linked event information and create separately confirmed events. Its current Google permissions cover availability on accessible calendars and events on owned calendars. Application configuration restricts reads and bookings to selected sources and a selected booking destination. The Google permission is broader than those application restrictions.

Why and where information is used

Records support capture, resuming work, scheduling, reminders and recovery. They are stored in the operator’s private application storage and backups. Calendar requests go to Google; private bot messages go through Discord; email notifications go through Resend and the recipient’s email provider. Notification content can include saved intention context. Each provider handles the information it receives under its own policies.

The current pilot does not send planning records to an AI model provider, sell user data, or use Google user data for advertising. EFA’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Storage and retention

Application files and credentials are restricted to the operator or dedicated service account. Credentials are separate from portable planning backups. The application does not encrypt planning files or backups itself. The operator controls retention; deleting a record from the current store does not erase earlier backups or copies retained by message and email providers.

Control and contact

The user can pause reminders, disable reception, export planning records and delete intentions and their retained application history. Google access can be revoked through Google Account connections. The operator must separately remove private credential files and any backups or provider copies they no longer want to retain.

For questions about this private instance, use the support email shown on its Google authorisation screen. Future changes that add users, providers or new data uses require a review of this notice and the relevant permissions.