We process, never store.
DAIA's Quick Scan reads a short window of your work activity to build your AI assistant — then deletes everything raw and disconnects itself. This page is the complete, plain-English account of how that works.
What happens during a scan
- 1
You connect
You approve read-only access through each app's own official sign-in screen. We never see your password.
- 2
We read a recent window
Our system reads about 90 days of work activity — prioritizing things you wrote, because they show how you actually work.
- 3
We distill
AI turns that activity into a short work profile: your recurring workflows, the tools you use, and how you talk about your work. A human reviews everything built from it.
- 4
We delete
Everything raw — every email, file, and message — is permanently deleted the moment the profile is done. The scan is one-time, not ongoing.
- 5
We disconnect
We revoke our own access automatically. You can verify this yourself (see below).
Exactly what we can see
Google (Gmail, Drive, Calendar)
Can see: Read-only: recent emails (about the last 3 months, focused on ones you sent and threads that repeat), files you recently edited, and your calendar.
Can't do: We can't send email, edit or delete anything, or see your password.
Microsoft 365 (Outlook, OneDrive, Teams)
Can see: Read-only: recent sent and received email, recently used files, and recent Teams chats.
Can't do: We can't send messages, change files, or administer your account.
Slack
Can see: Read-only: your messages in public channels you're already in.
Can't do: We cannot see direct messages or private channels — we never ask for that permission.
What we keep — and what we never keep
The only thing that survives a scan is your work profile: your role, your recurring workflows (like "Friday invoice reconciliation — QuickBooks and a tracking sheet, about 2 hours"), the tools you use, who you work with, and a handful of short phrases from your own messages so your assistant talks the way you do. You can ask to see it, correct it, or have it deleted at any time.
We never keep — and our database is physically incapable of storing — raw emails, files, messages, attachments, or contact lists. Sign-in tokens are held by our OAuth provider (Nango) for the minutes the scan runs, then destroyed. Nothing about the scan is recurring; there is no ongoing sync.
Verify the disconnect yourself
- Google: visit myaccount.google.com/connections — after your scan completes, DAIA no longer appears.
- Microsoft: visit myaccount.microsoft.com → App permissions, where you can confirm or remove DAIA's access.
- Slack: your workspace's Appspage — DAIA's access is revoked after the scan.
Who touches the data (subprocessors)
- Anthropic — the AI that reads and distills, via API. API inputs are not used to train models; processed transiently under Anthropic's standard retention (up to 30 days), then gone.
- Nango — holds the OAuth tokens during the scan so our own servers never do; connection deleted at the end.
- Supabase — our database. Stores the profile and an access audit log (counts and dates only — no content).
- Vercel — runs the application.
For IT departments
Every scan writes an access log— which APIs were called, how many items, over what date window (never contents) — and we'll share it on request. All access is read-only and least-scope; the exact OAuth scopes are listed above and never expand silently. Tokens are revoked programmatically at scan completion, with an automated sweep retrying any failure within the hour. Questions or a security review: email coby.gayer@gmail.com.
Prefer we see nothing at all?
DAIA also offers a 15-minute interview instead: an AI interviewer asks about your work and we build your assistant from the conversation alone — no account connections of any kind. Ask the person who sent your link to switch you to the interview.