What Reason keeps, and what it does not
Privacy
Reason is a personal assistant you text. This explains what it stores, what leaves the machine it runs on, and how to get rid of all of it. It is written against the code, which is public: github.com/omarionnn/pa
What Reason stores
One database file on the machine Reason runs on. There is no other copy, no analytics service and no third-party storage. Everything in it is keyed to your conversation, and no query in the code can read one person's rows from another person's conversation.
Your messages to Reason and its replies to you, as a running transcript. The transcript keeps the most recent 60 messages of your thread and older ones fall off it.
What the transcript holds is worth being plain about: it includes the results of things Reason looked up for you. So if Reason read an email or an event for you, the text of that email or event is in the transcript on the disk until it falls out of those 60 messages. It is not stored anywhere else, it is not indexed, and nothing goes looking through it.
Plans, reminders, timers and the jobs Reason is working on between messages. Facts you have asked it to remember about people. Pages it made for you, and any answers you tapped on one.
A receipt for every action that touched the outside world — what it did, when, whether it worked — so that "what did you do today" is answered from a record rather than from memory. Every time it asked you for permission, and what you said.
Which accounts you have connected, and the tokens that make them work. Phone calls it placed for you, with their recordings as files on the same machine. A count of how many turns and calls you used each day, and what has been committed in spending.
Your Google data in particular
Reason asks for five Google permissions in total and no others. Asking for your email and calendar asks for three of them: Gmail (read, search, draft, send, label, archive, and move to the bin), Calendar events (see, add, change and remove events), and reading a calendar's settings (its name and time zone, so times are written in your zone). It deliberately cannot delete your mail permanently, because the permission that would allow that is not one it asks for; and it cannot create, share or delete a calendar, for the same reason.
Your Drive is the other two, and it is a separate tap: connecting your email does not connect your files, and Reason will send you a second link the first time you ask it for something in your Drive. One permission lets it find and read your files; the other lets it make a new Google Doc when you ask for one, and covers nothing but the documents it made itself. It cannot delete, share, rename, move or edit anything in your Drive — those permissions are not ones it asks for, so ask it to change a document and it will tell you it cannot and offer to make you a new one. Adding a permission never takes away one you already gave.
Reason uses your Gmail, Calendar and Drive data only to do the thing you asked for in the conversation you asked in. Nothing else reads it. It is never sold, never shared with a data broker, never used for advertising of any kind, and never used to train or improve any model.
It does not copy your mailbox or your Drive. It asks Google for what it needs when you ask a question, and what comes back lives in your transcript as described above until it falls off it. There is no index, no second copy and no background scanning: a file is read when you ask about it and not before.
A PDF — in your Drive, or attached to an email — can be read, and this is the part worth being exact about. Reading an email does not download what is attached to it; the bytes are only fetched when you ask about that particular file. The text is then pulled out on the machine Reason runs on, by the PDF reader macOS already has. The document is not sent to any model, any service or anybody else to be read, and it is not kept: the bytes are written to a temporary file for as long as the reading takes and deleted straight afterwards. What stays is the text that came out, in your transcript, exactly like the text of an email or a Google Doc, until it falls off those 60 messages — and a disconnect clears it along with everything else Reason read out of your account. A PDF that is a scan has no text in it to pull out, and Reason tells you that rather than sending it somewhere that could guess.
No access token or refresh token ever leaves the machine. They are not in an export, not in a receipt, and not written to a log. Nor are the contents of a document it made for you: the receipt says which document and where it is, and the document itself is in your Drive.
Anything inside an email, a calendar invite or a document is treated as information and never as an instruction. A file or an email that tells Reason to forward itself, or to reply with a code, gets reported to you, naming it. It cannot make Reason act: the permission gate reads your own replies in your own conversation, and a document is not one of those.
Limited Use
Reason's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain words, what that commits to here: the data is used only to provide the features you can see in your own conversation; it is not transferred to anyone except as needed to provide those features to you, for security, or where the law requires it; it is not sold or used for advertising; and no human reads it except where you have asked for something specific, or where it is necessary to investigate a bug or abuse, or where the law requires it.
What leaves the machine, and why
To answer you at all, Reason sends your conversation to Anthropic's API, because that is the model that reads it and writes the reply. There is no model on the machine. That means the part of your conversation still in the transcript — including text from an email or an event Reason read for you — is sent to Anthropic as part of producing your answer. Anthropic's own terms govern what they do with it.
When you ask Reason to do something with a service, it talks to that service: Google for your mail, calendar and Drive, and whichever of a search provider, a telephony provider or a payments provider is set up on this install. It sends what the request needs and nothing more.
That is the whole list. Nothing is sent anywhere for analytics, advertising, or model training.
Disconnecting
Text Reason and ask it to disconnect your Google, or to stop reading your email. It revokes the connection at Google and deletes the stored tokens from the machine — one grant covers your mail, your calendar and your Drive, so disconnecting takes all of it. If Google will not confirm the revoke, Reason tells you so rather than claiming it is done.
You can also take it away from your own side at any time, whatever Reason does: myaccount.google.com/permissions lists every app with access to your Google account, Reason included, and removing it there cuts it off immediately.
Disconnecting stops Reason reaching your account. It does not by itself clear what is already in your transcript — ask for a delete for that.
Getting it all, or getting rid of it
Ask Reason and it will tell you. If you run this install yourself, two commands do it: `npm run data:export` writes out everything held about you, including the call recordings, with the tokens replaced by a marker because those are live credentials rather than your records. `npm run data:delete` removes it.
A delete is real and immediate. It removes the rows, the call recordings as files from the disk, and the saved browser logins, and it asks Google to let go of your connection on the way through — and reports honestly if Google would not.
Reason has no backups. There is nothing to recover from and nothing to ask anybody else to delete.
Children
Reason is not for anybody under 13 and is not directed at children.
Changes, and who to ask
If what Reason does with your data changes, this page changes with it, and the date at the top moves.
This is one person's assistant, run by the person who gave you the number. Ask them, or read the code: github.com/omarionnn/pa
Reason