Privacy Policy
Effective October 10, 2026
This policy explains how NanoLabs AI (“we”, “us”), the operator of Nano, collects, uses and shares information when you use Nano, our personal assistant over iMessage, and its website at app.nanobot.sh. Nano is currently an invite-only beta.
Information we collect
- Phone number and first name. To sign in, you enter your mobile number and, optionally, your first name on our website, and then text Nano a one-time code from that phone. Nano does not message you first. We store your phone number and first name. Sign-in codes are stored only in hashed form and expire after a few minutes. We also store the time zone your browser reports, so Nano can understand times like “tomorrow at 3”.
- Messages. The messages you send Nano and Nano’s replies, in iMessage and on the website.
- Task history and approvals. The tasks Nano works on, the steps and tool results for each task, and your approvals or rejections of actions such as sending an email or creating an event.
- Preferences you ask Nano to save.
- Google account information. If you connect Google, the email address and account ID of the Google account you connect, the permissions you granted, and the OAuth access and refresh tokens that let Nano act for you.
- Gmail and Google Calendar data that Nano accesses to complete a request you make, such as search results, the message you asked about, calendar names, events and free/busy times. See “Google user data” below.
- Operational logs. Minimal technical logs, such as service health and error codes. They do not include the content of your messages or email, or your phone number.
- Payment information. Nano is free during the beta, and we do not collect payment information today.
How we use information
- To sign you in and link your phone number to your Nano account.
- To understand your requests, carry them out, and reply to you.
- To show you the exact action Nano proposes (such as an email or event) and to carry it out only after you approve.
- To show your conversation and task history to you.
- To keep Nano secure, prevent abuse, enforce usage limits, and fix problems.
- To respond to you when you contact us, and to comply with the law.
We do not sell your information, and we do not use it for advertising.
Google user data
Nano's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide the features you request in Nano: answering questions about your email and calendar, drafting and sending email you approve, and creating calendar events you approve.
- We do not use Google user data for advertising, including targeted, personalized or retargeted ads.
- We do not sell Google user data.
- We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models. To process your request, Nano sends the relevant parts of it to our AI provider, Anthropic, under terms that prohibit Anthropic from training its models on that data.
- No person at NanoLabs AI reads your Google user data unless you give us permission (for example, when you ask for support), it is needed for security purposes such as investigating abuse, or it is required to comply with the law.
- Nano does not copy Gmail content into its long-term memory. Nano’s saved preferences contain only what you explicitly ask it to remember. Email excerpts that Nano read to complete a task stay in that task’s history, which you can see and delete (see “Data retention”).
- We transfer Google user data to others only as needed to provide your request (our AI provider, and our messaging provider when Nano’s reply to you includes an excerpt), for security, or to comply with the law.
Nano requests these Google permissions: read your Gmail (to find and read messages you ask about), compose Gmail (to save drafts and send email you approve), and view your calendar list, events and free/busy times and create events on calendars you own. Nano does not delete, label, archive or change your existing email, and it does not edit or delete existing calendar events.
AI processing
Nano uses an AI model from Anthropic to understand your messages and decide how to help. When you make a request, we send Anthropic the information needed to handle it: your message, relevant recent conversation, preferences you saved, and the results of any tools Nano used for that request, such as a short email excerpt or calendar entries. Anthropic processes this data to return a response to us. Under its commercial terms, Anthropic does not train its models on this data, and it may keep it for a limited period (currently up to 30 days) for safety and abuse monitoring.
AI output can be wrong. That is why Nano shows you the exact email or event and waits for your approval before it acts.
Service providers
We share information with these providers only so they can run Nano for us:
- Anthropic: AI model that processes your requests.
- Linq: delivers iMessages between you and Nano. Messages also travel through Apple’s iMessage service.
- Railway: hosts our servers and database.
- Google: Gmail and Google Calendar APIs, used at your direction when you connect your Google account.
- Cloudflare: DNS for our domain.
We may also disclose information if required by law, to protect the rights, safety and security of our users or others, or as part of a merger or acquisition, in which case this policy will continue to apply to your information.
Data retention
- We keep your account information, messages, task history and approvals for as long as your account is active, so you can see your history. We do not automatically delete older history yet.
- Sign-in codes expire after a few minutes, and Connect Gmail links expire after 30 minutes or after one use.
- If you disconnect Google in Nano, we stop accessing your Google account and delete the stored Google tokens right away.
- If you delete your account, we disable it and delete your Google tokens immediately. We then remove your messages, task history, approvals, preferences, phone number and files from our active systems. We keep a minimal record that the account was deleted (an internal ID and timestamps, with no content) so it cannot be accidentally restored.
- Copies held by our providers follow their own retention (for example, Anthropic’s limited retention described above). Messages already delivered to your phone and emails or events Nano already sent or created at your request are not affected by deleting your Nano account.
- Backups we make for disaster recovery are kept only as long as needed for that purpose and are not used to restore deleted accounts.
Your choices and deletion
- Disconnect Google. You can disconnect Google in the Nano web app, or remove Nano’s access at any time from your Google Account at myaccount.google.com/permissions.
- Delete your account. Sign in at app.nanobot.sh and open the full Nano app at app.nanobot.sh/app, then go to Settings and delete your app data. Or email support@nanobot.sh from any address and tell us the phone number on your account; we will verify the request and delete your account.
- Get a copy of your data. You can export your data from Settings in the Nano web app, or ask us at support@nanobot.sh.
- Approvals. You can reply NO to, or simply ignore, any action Nano proposes. Nothing is sent or created without your approval.
Security
Connections to Nano’s website and between Nano and its providers are encrypted in transit with TLS (HTTPS). Google OAuth tokens are encrypted at rest with AES-256-GCM before they are stored, and are never shown to the AI model, your browser or our logs. Access to our systems is limited to the people who operate Nano. No system is perfectly secure, so please contact us if you believe your account has been compromised.
Children
Nano is not intended for children under 13, and we do not knowingly collect information from children under 13. If you believe a child under 13 has given us information, contact us and we will delete it.
Changes to this policy
We may update this policy. If we make material changes, we will update the effective date above and let you know through Nano or our website before the changes take effect.
Contact
NanoLabs AI, support@nanobot.sh