Privacy Policy

Last updated: March 2026

1. Introduction & Data Controller

Winston the Pug ("we", "us", "our"). We are the data controller responsible for your personal data. We are registered with the Information Commissioner's Office (ICO) under registration number 31337.

This Privacy Policy explains how we collect, use, store, and protect your information when you use our AI assistant service ("the Service"), in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR, Regulation 2016/679).

2. Data Protection Officer

We have appointed a Data Protection Officer (DPO) who can be contacted at dpo@pug.bot for any questions regarding the processing of your personal data or the exercise of your rights.

3. Data We Collect

We collect the following categories of data:

  • Messages: Text messages you send to the Winston the Pug bot through supported messaging platforms.
  • User profile information: Your name, contact identifiers, and account preferences.
  • Intel profiles: Preferences, routines, and stated interests derived from your interactions, which you can view, edit, or delete at any time.
  • Connected service tokens: OAuth credentials for third-party services you choose to connect.
  • Usage metrics: Token consumption counts, request timestamps, and session metadata.

We do NOT store message content long-term. Conversations are session-based with a 30-minute inactivity timeout. Once a session expires, message content is discarded.

4. Legal Basis for Processing

We process your personal data on the following legal bases under Article 6 of the GDPR:

Processing ActivityLegal BasisArticle
Providing AI responses and executing tasksContract performanceArt. 6(1)(b)
Session and conversation managementContract performanceArt. 6(1)(b)
Building and maintaining intel profilesConsentArt. 6(1)(a)
Connecting third-party services (OAuth)ConsentArt. 6(1)(a)
Service quality and reliability improvementsLegitimate interestsArt. 6(1)(f)
Security measures and fraud preventionLegitimate interestsArt. 6(1)(f)
Processing children's data (Family plan)Parental consentArt. 6(1)(a), Art. 8

Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms.

5. How We Use Data

We use the data we collect for the following purposes:

  • To provide AI assistant responses and execute tasks on your behalf.
  • To maintain conversation context within active sessions.
  • To build and maintain user intel profiles, including your preferences, routines, and stated interests. You can view, edit, or delete these profiles at any time.
  • To improve overall service quality, reliability, and performance.

6. Profiling & Automated Decision-Making

We build and maintain intel profiles based on your interactions with the Service. These profiles include your stated preferences, routines, and interests, and are used to personalise AI responses and proactively assist you. This constitutes profiling under Article 4(4) of the GDPR.

This profiling is based on your consent. No decisions with legal or similarly significant effects are made solely through automated processing. You can view, edit, or delete your intel profile at any time via the dashboard, and you may object to profiling under Article 21 (see Your Rights below).

7. Connected Services

When you connect third-party services such as Gmail, Google Calendar, Google Drive, or GitHub, we access data through those services using OAuth tokens that you explicitly authorise. We request the minimum necessary permissions required to perform the actions you request. Your OAuth refresh tokens are encrypted at rest using authenticated envelope encryption (AES-256-GCM with a unique per-record data key, itself wrapped by a master key held in a separate secrets manager). Short-lived access tokens are held only in memory and never written to disk. You may revoke access to any connected service at any time through the Winston the Pug dashboard or directly in the third-party service's settings; doing so deletes the stored token and revokes it at the provider.

7.1 Google Workspace APIs — Limited Use

Winston the Pug's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We request only the scopes needed for the features you use:

  • See & download your email (gmail.readonly): to search and read messages when you ask (e.g. “any important emails this week?”).
  • Send email on your behalf (gmail.send): only after you explicitly confirm each message — we never send without a confirmation.
  • Calendar (calendar.readonly, calendar.events): to read your events and create events you ask for (with confirmation).
  • Drive (drive.readonly, drive.file): to find and read the files you authorise.

We do not use data obtained through Google Workspace APIs to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models. When fulfilling a request, the relevant Google data is sent to our AI processing provider only transiently and solely to answer that specific request; we do not retain it beyond the request and do not use it for advertising or any unrelated purpose. No human reads your Google data except (a) with your explicit consent (for example, to resolve a support issue), (b) where necessary for security or to comply with applicable law, or (c) where required to fix or prevent a technical problem. You can delete all connected-service data at any time by disconnecting the account or deleting your Winston the Pug account.

8. Data Storage & Retention

Your data is stored on secured infrastructure with appropriate technical and organisational safeguards. Long-term memory and knowledge entries are stored in our encrypted memory store — powered by GraphANN™, operated by us — the ICO-registered data operator — with per-user encryption and isolation, so your data is never co-mingled with other users' data.

We retain your data for the following periods:

  • Conversation messages: Deleted automatically after 30 minutes of session inactivity.
  • Intel profiles and knowledge entries: Retained for the duration of your active account; deleted within 30 days of account closure.
  • OAuth tokens: Deleted immediately upon disconnection or account closure.
  • Usage metrics: Retained for 12 months, then anonymised.
  • Account data: Deleted within 30 days of an account deletion request.
  • Backups containing personal data: Purged within 90 days of a deletion request.

9. Data Sharing & Sub-Processors

We do NOT sell your personal data. We do not engage in advertising, behavioural profiling for third parties, or data brokerage of any kind. Your data may be shared with the following categories of recipients solely to provide the Service:

  • AI processing providers: For generating AI responses to your requests.
  • Messaging platforms: WhatsApp (Meta Platforms) and Telegram, for message delivery.
  • Connected services: Google (Gmail, Calendar, Drive) and GitHub, only when you have explicitly connected these services.

We maintain Data Processing Agreements (DPAs) with all processors in accordance with Article 28 of the GDPR.

10. International Data Transfers

To provide the Service, your data may be processed by AI providers and messaging platforms located outside the United Kingdom and European Economic Area. Where we transfer personal data internationally, we ensure appropriate safeguards are in place in accordance with Articles 44 to 49 of the GDPR, including:

  • The UK International Data Transfer Agreement (UK IDTA) or EU Standard Contractual Clauses (SCCs).
  • Adequacy decisions where applicable.
  • Supplementary security measures including encryption in transit and at rest.

You may request details of the specific safeguards applied by contacting our DPO.

11. Your Rights

Under the UK GDPR and EU GDPR, you have the following rights:

  • Access (Art. 15): Request a copy of your personal data and intel profiles at any time via the dashboard.
  • Rectification (Art. 16): Correct inaccurate or incomplete data in your profile.
  • Erasure (Art. 17): Delete any or all of your stored data, including intel profiles and knowledge entries.
  • Restrict processing (Art. 18): Request that we restrict processing of your data while any disputes about accuracy or lawfulness are resolved.
  • Data portability (Art. 20): Export your data in a portable, machine-readable format.
  • Object (Art. 21): Object to processing based on our legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Withdraw consent (Art. 7(3)): Where we rely on your consent (e.g., for intel profiles or connected services), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Account deletion: Request permanent removal of all associated data.

To exercise any of these rights, contact our DPO at dpo@pug.bot. We will respond within one month as required by law.

Right to complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) or with your local EU data protection supervisory authority if you believe your data has been processed unlawfully.

12. Children's Privacy

The Service is designed for family use, including children. We are committed to complying with the UK Age Appropriate Design Code (Children's Code) and take the following measures:

  • Age requirements: Children under 13 (UK) or under 16 (EU, unless the applicable member state has set a lower threshold) cannot use the Service without verified parental consent. Child accounts may only be created by a parent or legal guardian through the Family plan.
  • Parental consent: The primary account holder on a Family plan must confirm they are the parent or legal guardian of any child added, and must explicitly consent to the processing of their child's personal data.
  • Intel profiling: Intel profiling is disabled by default for child accounts. A parent or guardian may enable it via the dashboard.
  • Data minimisation: Data collection for child accounts is limited to what is strictly necessary to provide the Service.
  • Content filtering: Age-appropriate content filtering is applied to accounts identified as belonging to minors.
  • No detrimental use: Children's data will not be used in ways that are detrimental to their wellbeing or that conflict with their best interests.
  • Parental controls: Parents may review, download, modify, or delete all data associated with their children's accounts at any time.

13. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals' rights and freedoms, in accordance with Article 35 of the GDPR. This includes our use of AI for message processing, intel profiling, and the processing of children's data.

14. Security

We implement robust security measures to protect your data, including encrypted credentials using NaCl secretbox encryption, secured infrastructure with access controls, and regular security audits. While no system is perfectly secure, we are committed to maintaining industry-standard protections and promptly addressing any identified vulnerabilities.

15. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to you, we will notify you without undue delay in accordance with Article 34.

16. Cookies

We use minimal cookies strictly for authentication and session management purposes. We do not use tracking cookies, third-party analytics cookies, or advertising cookies.

CookiePurposeTypeExpiry
sc_sessionSession identificationSessionBrowser close
sc_authAuthentication tokenPersistent30 days

17. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide at least 30 days' notice of any material changes via email or in-app notification. Where changes affect processing activities based on your consent, we will request your renewed consent before applying those changes. If you do not agree with any changes, you may delete your account and we will cease processing your data.

18. Contact

If you have any questions or concerns about this Privacy Policy or our data practices, please contact: