STAN Privacy Statement

Effective date: 14 September 2026

About STAN

STAN is a private personal-assistance application operated by Klaus Muerle. It connects local tools, authorized online services, and external AI assistants to support tasks requested by its owner.

Contact: kmuerle@gmail.com

Privacy principles

STAN's privacy policy requires information sharing to be limited to what is necessary for the current task. Unrelated information should be omitted, and personal information should be minimized or redacted where practical.

Protected information requires the owner's authorization before external disclosure. Approval to share information does not automatically authorize other actions, such as publishing, sending messages, or deleting files.

Credentials and secrets must not be included in AI handoffs or ordinary logs. Credentials needed to connect to a service are used for authentication with that service.

Information processed

Depending on the task and enabled connections, STAN may process instructions, preferences, documents, communications, service metadata, and task results.

For its Gmail integration, STAN uses Google-authorized read-only access. The current workflow retrieves selected LinkedIn job alerts using a configured label and sender filter. Although Google's permission allows broader mailbox reading, this workflow restricts which messages it retrieves. It does not send, delete, or modify email.

External services and AI processing

STAN may send task-relevant information to connected services and external AI providers, including OpenAI, to perform requested analysis or generate responses.

This can include selected content, extracted facts, relevant personal context, and earlier task results. The current job-review workflow sends extracted vacancy details and configured career preferences, while excluding raw email bodies and Gmail credentials from AI requests.

Information sent to external providers is also subject to their applicable terms and privacy practices.

Storage and security

STAN stores configuration, working files, processing records, and task results locally. Some workflows retain retrieved source content and copies of external requests and responses.

Google authorization tokens are protected using Windows credential encryption for the local user. Other local files depend on the security of the owner's computer and storage.

Retention and control

Information is retained according to the workflow and the owner's management of local files. There is currently no universal automatic deletion period across STAN.

The owner can stop workflows, delete stored local information, and revoke connected-service access through the relevant provider's account settings.

Revoking access prevents further authorized retrieval but does not automatically delete existing local files or information previously sent to external providers. Provider-side retention and deletion follow the applicable provider's controls and policies.

Purpose limitations

STAN processes information to support its owner's requested tasks. It does not sell personal information or use connected-account data for advertising.

Changes and contact

This statement will be updated when STAN's information handling materially changes.

For privacy questions, contact kmuerle@gmail.com.