Privacy Policy

Effective 11 July 2026.

1. What Shimmer is

Shimmer is a personal AI agent that reads your inbox, calendar, contacts, and selected documents to help you keep up with your work and life. Your agent runs in its own isolated instance, operated by Shimmer, under your direction. Operator and data controller: Shimmer, contact hello@shimmer.fyi.

2. Data we receive from Google

A first-time Google connection requests read-only scopes:

  • gmail.readonly: message metadata and content from your Gmail account, used to summarize, classify, and surface relevant threads.
  • calendar.readonly: events and attendees from your calendars, used to brief you before meetings and plan your day.
  • contacts.readonly (optional): your Google contacts, used to seed your people map. Requested only if you enable contact import.
  • drive.readonly (optional): files and folders you explicitly authorize, used to read documents you want Shimmer to work with.
  • openid, email, profile: basic identity to bind the connection to your Shimmer account.

If you turn on sending, Shimmer requests two write scopes in addition to the read scopes above:

  • gmail.send: lets your agent send email from your address, only after you approve each message.
  • calendar.events: lets your agent create or update events on your calendar, only after you approve each change.

Write scopes never act on their own. When your agent wants to send an email or touch your calendar, it creates a proposal and stops. Nothing executes until you approve that specific action with an explicit tap, in the app or by replying on WhatsApp, and every approval or denial is logged to your knowledge base. If you skip the sending upgrade, Shimmer stays read-only.

3. Data we receive from Microsoft

Connecting a Microsoft account follows the same pattern via Microsoft Graph. A first-time connection requests read-only scopes: Mail.Read (Outlook message metadata and content) and Calendars.Read (events and attendees), plus openid, email, profile, and offline_access for identity and a persistent connection. Turning on sending adds Mail.Send and Calendars.ReadWrite, and every send or calendar change is gated behind the same per-action approval described in §2.

4. Other data Shimmer handles

  • WhatsApp (optional). You can pair your agent to WhatsApp as a linked device by scanning a QR code, the same way WhatsApp Web works. While linked, your WhatsApp messages relay through a bridge so your agent can chat with you, deliver briefs, and take approvals there. The pairing session is held server-side, scoped to your agent alone. Unlink at any time from WhatsApp's Linked devices screen.
  • Meeting audio (optional). When you record a meeting, the audio is transcribed by a Whisper service we operate and then deleted immediately; it never persists beyond transcription. The transcript is kept in your instance.
  • Passkeys. Sign-in uses WebAuthn passkeys. We store the public-key credential needed to verify you. There are no passwords, and the private key never leaves your device.
  • Waitlist. If you request an invite, we store the email address you give us and use it only to contact you about access.
  • Sessions. A session cookie keeps you signed in. We do not use advertising or third-party analytics cookies.

5. How we use your data

Data from your connected accounts is used solely to provide Shimmer's features to you: drafting summaries, surfacing follow-ups, building your personal knowledge graph, and answering your questions. It is not used to train general models, not sold, not used for advertising, and not shared with anyone but you and the language-model providers strictly required to fulfill your requests (see §7).

6. Limited Use disclosure (Google API Services User Data Policy)

Shimmer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Shimmer does not transfer Google user data to third parties except as necessary to provide or improve user-facing features that are prominent in the requesting app, does not use the data for serving advertisements, does not allow humans to read the data unless we have your affirmative agreement for specific messages, are required by law, are doing so for security purposes (such as investigating abuse), or are operating internal operations subject to equivalent or stricter restrictions on access, and does not sell the data.

7. Where your data lives, and who else sees it

Your connected-account data, your knowledge base, and your conversations live in your Shimmer instance. Credentials are kept apart from data: first-time Google and Microsoft connections are enrolled into a hosted, hardware-isolated credential broker, and Shimmer acts on those accounts through the broker rather than holding the token itself. Where a direct OAuth token is used instead (additional accounts, and connections made before the broker), the refresh token is held in the control plane's private registry on our server, never in your knowledge base and never visible to other tenants. To answer a question or draft text, Shimmer sends the relevant context to a large-language-model provider (today: Anthropic Claude models via OpenRouter). These providers process the data transiently to return a response, under terms that bar training on it. We do not send your data to any other third party.

8. Retention and deletion

Cached account data and derived artifacts (summaries, embeddings, conversation history) persist in your Shimmer instance until you delete them. You can revoke Shimmer's access at any time from your Google account permissions page or your Microsoft account permissions page, unlink WhatsApp from its Linked devices screen, and request deletion of your cached data by emailing hello@shimmer.fyi.

9. Security

OAuth tokens for first-time Google and Microsoft connections live in a hardware-isolated credential broker rather than on Shimmer's servers. Direct-connection tokens are held in a locked-down registry readable only by the control plane, are never written to your knowledge base, and are never shared between tenants. The Shimmer codebase is reviewed before release and runs in containers with the minimum necessary network access. Report security issues to hello@shimmer.fyi.

10. Changes

We may update this policy as Shimmer evolves. Material changes will be announced on get.shimmer.fyi and dated above.

11. Contact

Questions, requests, or concerns: hello@shimmer.fyi.