Legal

Privacy Policy

Last updated August 11, 2026

Who we are

Aurex: Voice Command Ops (“Aurex”, “we”) is an iOS application operated by Kiloforge. Aurex is a voice-native assistant: you speak a command, and Aurex carries it out across the tools you have connected — Gmail, Google Calendar, Slack, GitHub, and Notion.

This policy explains what data Aurex accesses, why, where it is stored, and how to delete it. Questions go to hello@kiloforge.com.

What Aurex accesses in your Google Account

Connecting Google is optional, and it is a single consent covering both Gmail and Calendar. You can see exactly what was granted, and withdraw it, at any time. Aurex requests these permissions and no others:

openid · userinfo.email

Your identity

Identifies which Google account is connected, so the right mailbox and calendar are used. The account ID is our record key — it survives an address change.

gmail.modify

Gmail: read, organize, draft, and send

Aurex triages your inbox out loud, reads messages you ask about, labels and archives them, and drafts and sends replies you dictate. This permission deliberately cannot permanently delete mail — that requires a broader permission we do not request.

calendar.readonly

Calendar: read events

Reads your calendar list and events so Aurex can answer questions about your schedule and find free time.

calendar.events

Calendar: create and update events

Creates and edits events when you ask for one out loud.

Aurex acts only on your instruction. It does not browse your mailbox in the background for purposes unrelated to a request you made.

Google API Services Limited Use

Aurex’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, and without exception:

  • We do not sell your Google data, and we never will.
  • We do not use it for advertising, retargeting, or building advertising profiles.
  • We do not use it to train, develop, or improve generalized artificial intelligence or machine learning models.
  • We do not allow humans to read it, except with your explicit consent for a specific issue you have reported, where it is necessary for security purposes, or where required by law.

How your data is processed

Aurex is built on a large language model. To answer a spoken request, the relevant content — for example the emails you asked about, or the events in the day you named — is sent to OpenAI, which processes it and returns the response you hear.

This processing happens under OpenAI’s API terms, which prohibit using data submitted through the API to train their models. Your Google data is used to serve your request and for nothing else.

Only the content needed for the request is sent. Aurex does not upload your mailbox or calendar in bulk.

What we store, and where

Aurex stores as little as it can while still being usable between sessions. Specifically:

  • Account credentials. The access and refresh tokens issued by Google when you connect, alongside your Google account ID, email address, and the exact permissions you granted. These are what let Aurex act on your behalf without asking you to sign in every time.
  • Recent results. A short-lived cache of what Aurex has already looked up in a conversation — senders, subjects, message IDs, event details — so that asking a follow-up question does not re-query your mailbox.
  • Inbox triage state. The queue of messages Aurex is working through with you, and its notes on each, so a triage session can be resumed.
  • Resolved contacts. A mapping of names you say out loud to the email addresses they refer to, so “reply to Sam” means the same person twice.
  • Your Aurex account. Your sign-in identity and session records.

This data lives in a PostgreSQL database hosted by Neon, and the application runs on Vercel. Both are in the United States. Traffic is encrypted in transit with TLS, and the database is encrypted at rest.

Other connected services

Slack, GitHub, and Notion work the same way: connecting is optional, each stores its own credential, each is disconnected independently, and the data returned is used only to answer the request that asked for it. What Aurex is permitted to do in those services is bounded by an explicit allowlist of operations, not by the breadth of the token.

Keeping control, and deleting your data

There are three levers, and you can pull any of them at any time:

  • Disconnect in the app. Open Connections and disconnect Google. The stored tokens are deleted immediately and Aurex loses all access to your mail and calendar.
  • Revoke at Google. Visit myaccount.google.com/permissions and remove Aurex. This works independently of us and takes effect at Google.
  • Delete everything. Email hello@kiloforge.com and we will erase your account and every record derived from your connected services within 30 days, and confirm when it is done.

Credentials are erased the moment you disconnect. Cached results and triage state are retained until you ask us to delete them — they are not automatically expired, so that a conversation can be picked up where you left it.

Security

Access to production systems is restricted to Kiloforge personnel who need it. Credentials are never written to logs. Aurex requests the narrowest permission that does the job — the Gmail permission it asks for cannot permanently delete mail, and the broader one that can is not requested.

No system is perfect. If you believe you have found a vulnerability, please write to hello@kiloforge.com and we will respond quickly.

Children

Aurex is a tool for working professionals and is not directed at children under 13. We do not knowingly collect their data.

Changes to this policy

If this policy changes materially — particularly if Aurex begins requesting a new permission — we will update the date at the top of this page and notify connected users in the app before the change takes effect.

Contact

Kiloforge — hello@kiloforge.com