Secretariat is an organization app built around one to-do list. It pulls your classes, deadlines and calendars into one place, helps you plan your week and shows how you’re keeping up. This page explains what it collects, what it does with it, and what it never does.
What we collect
- Your account: name, email address, password (stored only as a secure hash), and optionally a phone number. If you confirm a school (.edu) email for Student Pro, that address too. If you turn on two-step sign-in, the key for your authenticator app and your recovery codes. If early access is full when you sign up, we keep your name and email (never your password) so we can let you in later.
- Data from apps you choose to connect. Which data depends on the app, and is listed under “Connected apps” below.
- Things you create in Secretariat, like to-dos, notes, events, goals and routines, plus whether you’ve checked things off, so it can show your progress.
- Feedback you choose to send us.
- Basic security records, like sign-in times and IP addresses, used to protect your account.
- For each AI request, a usage record (which feature, which model, how many tokens, what it cost), so we can keep costs in check. It never includes what you asked or what the AI answered.
Secretariat doesn’t use ads, tracking pixels or analytics services. It sets a cookie to keep you signed in, one to protect forms, and, with two-factor on, one so a device that gave a code isn’t asked again for 30 days. It also saves a few preferences (like your theme and recent assistant chat) in your own browser.
Connected apps
Each app is only connected if you connect it, and you can disconnect it at any time.
- Canvas: your courses, assignments and due dates, whether you’ve submitted, announcements, course pages, modules and files (including the syllabus), and your grades and assignment weights.
- Google Calendar, Outlook and calendar links: your events, with their titles, times, places and notes.
- Google Tasks, Microsoft To Do, Todoist and Notion: tasks and pages with due dates.
- Outlook mail: the subject, sender and link of the last few days of your inbox, sorted with plain rules (not AI) so the ones that ask something of you show on Home. On the Pro plan, emails you’ve flagged become to-dos. Never the body, and the inbox isn’t saved; an email you add to your list keeps its subject there.
- Slack: messages in the channels you pick and messages that mention you, sorted with plain rules (not AI) into events and asks.
- Google Drive, if you connect it: only file names and dates, used to link the doc you’re writing to its assignment. Secretariat never opens what’s inside your Drive files.
- Gmail, only while it’s open to early testers: the subject, sender and Gmail’s own short preview of the last few days of your main inbox, sorted with plain rules (not AI) so the ones that ask something of you show on Home. Never the full body, and the inbox isn’t saved; an email you add to your list keeps its subject there.
Secretariat reads from these apps and never sends, changes or deletes anything in them, with one exception you choose: if you turn on adding to Google Calendar (a separate sign-in that asks for that one extra permission), an event you made in Secretariat is added to your Google Calendar when you tap to add it. Checking something off or moving it in Secretariat never changes it in Canvas or your other apps.
If you use your private forwarding address (Pro), emails you forward to it become to-dos. Only the subject and who first sent it are kept, never the body.
How we use it
Only to run Secretariat for you: building your to-do list and calendar, keeping them in sync, tracking your progress, sending the notifications you turn on, and answering your requests to the assistant. We don’t sell your data, show you ads, or use your data to train AI models.
AI
Some features use Anthropic’s API (Claude). To do that, Secretariat sends Anthropic only what each feature needs: your requests to the assistant and the to-dos and events that go with them, calendar event titles and notes to work out what an event is and what’s due, and your Canvas course material (syllabus, pages, announcements and class files) to find readings, late policies and what an assignment asks for. Anthropic doesn’t use API data to train its models. Your grades are never sent to AI and are only ever shown to you.
The assistant never creates or changes anything without you confirming it first. If spoken replies are on, the text of each reply (not your request) is sent to our voice provider, OpenAI or ElevenLabs, to turn it into speech. When you talk to the assistant, the recording is sent to OpenAI to turn it into words, along with your class names and Canvas assignment titles so they come out right. OpenAI doesn’t use API data to train its models, and Secretariat doesn’t keep the recording. If that’s unavailable, your browser’s own speech recognition (run by Google in Chrome, Apple in Safari) does it instead.
Google user data
If you connect Google Calendar, Google Tasks, Google Drive or (for early testers) Gmail, Secretariat reads only what’s needed to show those items to you inside Secretariat, as described above, and only adds to your Google Calendar if you turn that on. Secretariat’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is never used for advertising, never sold, never used to train or improve AI models (ours or anyone else’s), and never read by people except with your permission, for security, or where the law requires it.
Google data leaves Secretariat in only three ways. Calendar event titles, times and notes are read by Anthropic’s API after each sync so Secretariat can sort them into classes, deadlines and to-dos, and Google Tasks titles go there when you ask the assistant about them. Anthropic doesn’t keep or train on them. If spoken replies are on, a reply that mentions an event goes to our voice provider to be read aloud. And an AI app you connect yourself (below) can read your calendar. Disconnecting a Google app deletes its sign-in, and you can choose to remove the items it brought in at the same time.
Claude and other AI apps
You can connect Secretariat to Claude or another AI app that supports it (ChatGPT once it allows apps like this), from inside that app. Only once you log in here and allow it, that app can read your to-dos, deadlines and calendar, look things up in your class syllabus, and add to-dos, check them off, set time aside and add notes when you ask it to. It never gets your password or the sign-ins of the apps you connected to Secretariat, and it can’t delete anything.
What it reads goes into your conversation in that app, so from then on the app’s own privacy policy (OpenAI’s or Anthropic’s, for example) covers it. You can disconnect any of these apps in Settings at any time, and changing your password disconnects all of them.
Chrome extension
Secretariat for Chrome shows today’s to-dos in your toolbar and lets you check them off, add new ones and move them to another day. Once you sign in and allow it, it reads today’s to-dos (titles, times, whether they’re done and the course) and the next thing due, and saves the to-dos you add and check off. It only talks to Secretariat, never reads or changes the pages you visit, and sends nothing to anyone else. It keeps its sign-in on your computer, where only the extension can read it. Sign out from the extension, or from every browser at once in Settings. Changing your password signs it out too. If you use its mic, Chrome’s own speech service (run by Google) turns what you say into words, and only those words come to Secretariat, where they’re handled like anything you ask the assistant in the app.
Notifications and email
If you turn on notifications, reminders and your morning and evening notes are sent through your browser’s or phone’s own push service (like Apple’s or Google’s), which delivers them to your device. Account emails, like confirming your address, password resets and a heads-up when two-step sign-in is turned on or off, are sent through Resend.
How it's protected
Sign-in tokens for connected apps, calendar links, phone numbers and two-step sign-in keys are encrypted (AES-256) before they’re stored, and recovery codes are kept only as keyed hashes. Your password is stored only as a secure hash. Everything travels over HTTPS. Each account can only ever see its own data.
Who else handles it
Secretariat runs on a few service providers, which only process data to provide their service to us:
- Vercel, which hosts the website.
- Neon, which hosts the database.
- Anthropic, which powers the assistant and the AI features described above.
- OpenAI, which turns what you say to the assistant into words, and OpenAI or ElevenLabs, which read its replies aloud.
- Resend, which sends account emails and receives the emails you forward to Secretariat.
- Stripe, which handles payments if you subscribe to a paid plan. Your card details go to Stripe, never to us.
Your choices
You can disconnect any app from the Integrations page at any time. That deletes its stored sign-in and removes its items from your calendar. You can also revoke access from that app’s own account settings. Notifications, spoken replies and two-step sign-in can each be turned on or off in Settings.
To delete your account and everything in it, use Delete account in Settings, or email hello@getsecretariat.com. Deleting your account also cancels any subscription and disconnects your connected apps. To get a copy of your data, email us.
Students
Secretariat is made for students and you must be at least 13 to use it. If you think a child under 13 has made an account, email us and we’ll delete it.
Changes and contact
If this policy changes in a meaningful way, we’ll update the date above and let you know in the app. Questions: hello@getsecretariat.com.