Version: v2
Date: 19 August 2026
In case of any discrepancy between the French and English versions of this document, the French version prevails.
The controller of your data is Aristide Hervé Mbassi Demoudourou, a natural person, reachable at aristide.mbassi28@gmail.com and residing at 91 D Rue Gabriel Péri, 42100 Saint-Étienne, France. This policy is published at https://milly-virtualassistant.fr/privacy.
Milly keeps, for each user, in a PostgreSQL database:
Two unusual points, in your favour:
place_id is kept; re-reading an old conversation re-fetches the cards from Google. Exception: the place you actually choose. Its name and address become the appointment's location, stored and projected to Google Calendar like any other appointment field.Milly does no advertising, no profiling for commercial purposes, and no selling of data.
Your data is shared with the following third parties, solely to operate the service:
https://www.googleapis.com/auth/calendar, to read your calendar and write the appointments Milly creates; and the Places API (New), which returns place suggestions. The Google Terms of Service (https://policies.google.com/terms) and the Google Privacy Policy (https://policies.google.com/privacy) apply to map and place data and are incorporated by reference into this policy. Some place summaries are authored by Google and displayed verbatim, with their attribution.claude-haiku-4-5) so Milly can understand your request. This content is processed to serve the request and is not used to train models.Milly receives data from your Google account through the Google Calendar API, on a scope Google classifies as sensitive. Milly complies with the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. Notwithstanding anything else in this policy:
The publisher has technical access to the production database and does not read the content of your conversations or calendars, outside the exceptions listed in the previous section.
No conversation, calendar or task content is used to train any model, neither by the publisher nor by Anthropic through the API. The transfer to Anthropic is precisely the case Google allows: a transfer necessary to provide a user-facing feature that is prominent in the app, the conversation itself.
The application server is in France and the database is hosted within the European Union: hosting your data involves no transfer outside the Union. Google, Anthropic and Apple may process data outside the European Union, each under its own safeguard:
The service is not intended for people under 15, the threshold set in France under article 8 of the GDPR. No account is knowingly created for a minor under 15.
If the business is transferred, personal data may be part of the transfer. Google user data, for its part, may only be part of it after your explicit prior consent.
Your data may be disclosed when the law or a legal process requires it.
You have the rights of access, rectification, erasure, restriction, objection and portability over your data. To exercise them, write to aristide.mbassi28@gmail.com. You may also lodge a complaint with the CNIL, the French data protection authority (https://www.cnil.fr).
The measures in place: encryption in transit with TLS, connections being made over HTTPS with Let's Encrypt certificates; conversation content and Google tokens encrypted at rest with AES-256-GCM; refresh tokens stored only as hashes; secrets held per environment, outside the source code.
In case of a personal data breach, the publisher notifies the CNIL within 72 hours and informs you when the risk to your rights is high, in accordance with articles 33 and 34 of the GDPR.
You can delete your account from the app, in the settings, after a confirmation. Deletion is immediate and final: there is no grace period and no deactivated account kept in the background. Everything this policy describes is erased, including your conversations, your tasks, your preferences, your day plans, your action journal, your device registrations for notifications and your session tokens.
Before erasing anything, Milly revokes its access to your Google account with Google. If that revocation fails, your data is deleted anyway and Google expires the authorisation on its side.
The appointments Milly wrote into your Google Calendar belong to you and stay in your calendar: they are not deleted with your Milly account.
You can also write to aristide.mbassi28@gmail.com to ask for deletion.
To revoke Milly's access to your Google account without deleting your Milly account, use your Google account settings (https://myaccount.google.com/permissions).
Milly is an iOS application and an API: it does not use cookies. Sessions rely on tokens sent by the application, described above.
This policy may change; every new version will carry its number and date, and you will be informed of substantial changes. For any question: aristide.mbassi28@gmail.com.