Privacy policy
Effective 7 October 2026
Haruspex is a desktop application that runs on your own computer. The Haruspex project runs no servers, has no user accounts and collects no telemetry. We never receive your data. This policy explains what the app does with your information on your device, and what it sends to other services when you use features that need them.
What stays on your device
Your conversations, the model's answers, your settings, files you work with, and anything you ask Haruspex to remember are stored only on your computer. Passwords, API keys and sign-in tokens are kept in your operating system's keychain or, where none is available, in an encrypted file in the app's data folder.
What leaves your device
Haruspex contacts other services only to do things you use it for:
- Models. Model files are downloaded from Hugging Face. By default the model runs on your computer. If you choose a remote model server or a cloud provider such as OpenRouter, your prompts and the content the assistant reads, including any email, calendar or contact details, are sent to that server or provider and handled under its privacy policy.
- Web research. Search queries go to the search provider you choose, and the pages it finds are fetched from their websites. You can route this through a proxy.
- Accounts you connect. Email, calendar and contact accounts are reached directly from your computer, using credentials stored on your computer. Integrations you add (MCP servers) run on your computer with the access you give them.
- Update check. At startup the app asks GitHub for the latest release number.
Google user data
If you choose Sign in with Google, Haruspex asks Google for permission to:
- see your calendars and their events (
calendar.readonly); - see your contacts (
contacts.readonly); - see your email address, to show which account is connected.
How it is used. Haruspex reads your calendar events and contacts only when the assistant needs them to answer your question, for example "what's on my calendar this week?" It never creates, changes or deletes anything in your Google account.
Where it goes. Google data travels directly between Google and your computer. It is never sent to the Haruspex project. The events or contacts the assistant reads become part of that conversation, which is stored on your device. The only case in which Google data leaves your device is the one you configure: if you use a remote model server or cloud AI provider, the content the assistant reads is sent to it so it can answer you.
Storage. Haruspex keeps a sign-in token in your system keychain so it can reach your calendar later. It does not keep its own copy of your calendar or contacts; it fetches them when asked.
No other use. Google data is not sold, not used for advertising, not used to train AI models, and not shared with anyone except as described above.
Haruspex's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access. Remove the account in Settings → Integrations → Calendar & Contacts. That deletes the token from your device and revokes it at Google. You can also revoke access at any time at myaccount.google.com/permissions.
Deleting your data
Because everything is stored on your computer, you control it: delete conversations, memories and accounts in the app, or uninstall Haruspex and remove its data folder.
Children
Haruspex is not directed at children under 13.
Changes
Changes to this policy are published on this page with a new effective date. The history is in the project's source repository.
Contact
Questions about privacy: open an issue on GitHub.