Privacy & data

Private AI assistants: what an agent sees when you let it in

Agents stopped answering questions and started doing things, which means asking for your inbox, your calendar and your card. An honest look at what that access buys, what it costs, and the three questions worth asking before you grant it.

Aleem O'BalogunBy AleemUpdated 8 min read

The short answer

A private AI assistant is one where your files stay on your device and only what a specific request needs ever leaves it. Most of the agents launched in 2026 work the other way: they ask for standing access to your inbox, calendar, messages and payments. The question worth asking is not whether a tool calls itself private, but what it sees, what leaves, and what is kept.

What an AI agent is actually asking for

Something changed in the assistant category in 2026, and the privacy conversation has not caught up with it. A chatbot needed your question. An agent needs your accounts. The moment a tool stops answering and starts doing, booking the appointment rather than telling you how to book it, it needs standing permission to reach into the places where your life is stored.

The pattern is consistent across the agents that launched this year, whoever built them. You are asked to connect email, calendar, messages, sometimes a payment method, usually in the first few minutes, usually in a flow designed to make granting easy. The pitch is that the assistant can only be useful once it can see enough, which is true, and it is why the request is made early and made warmly.

None of that is a criticism, it is a description. You cannot have an agent book your dentist without giving it your calendar and a way to pay. The access is not a side effect of the product, it is the product. Which is exactly why it deserves a clearer question than the one most people ask.

The three questions that decide whether an assistant is private

Most privacy discussion stalls on encryption, which is close to the least useful place to start. Encryption tells you whether someone in the middle can read your data in transit. It tells you nothing about what the company at the other end sees, keeps, or does next. These three questions are more decisive.

First, what does it see? There is an enormous difference between a tool that receives one request and a tool holding a live connection to your inbox. The first sees a sentence. The second sees everything that arrives, forever, including the things you would never have thought to send it.

Second, what leaves your device, and when? Almost every AI tool worth using sends something to a server, because almost none of them run a capable model locally. Honest tools tell you precisely what goes and when. Be wary of any product claiming nothing ever leaves while offering cloud AI, because those two things cannot both be true.

Third, what is kept, and what else is it used for? This is where assistants built inside advertising businesses differ most sharply from ones that are not, and it is the question least often answered plainly. Retention is one thing. Whether your calendar becomes a signal in an ad profile is another.

Standing access is the thing that changed

The shift from per-request tools to agents is not a difference of degree, it is a different security model, and it is worth naming because product marketing tends to skate over it.

A per-request tool sends one thing, once, when you ask. You can see the boundary. Nothing happens while you sleep. An agent holds a connection you granted once and acts through it continuously, including at moments you are not present to judge whether the action was a good idea. The permission takes a second to grant and then persists indefinitely, which is a strange bargain to strike in a sign-up flow.

It is worth being precise about what that access covers, because consent is usually given at the level of the account rather than the item. Connecting an inbox does not mean the assistant reads the one email you had in mind. It means it can read what is in there and what arrives next, including correspondence that is not yours alone: what other people told you in confidence, and what they never agreed to share with a third party.

That makes revocation the real test, and almost nobody checks it before connecting. How hard is it to take the access back? What happens to what it already read? If a company cannot answer both questions plainly on its own site, that is information about the company.

It also reframes the convenience trade honestly. Standing access is what makes an agent genuinely useful, so anyone offering you agent-grade convenience with no standing access is either doing less than they imply or is not telling you where the data goes. The trade is real and it is sometimes worth making. It is just worth making deliberately.

Where asambl sits, honestly

Disclosure, since this page is on asambl's site and I built asambl: what follows includes the parts that do not flatter it.

Your plans, notes and files stay on your computer. When you use an AI feature, only the information needed for that specific request is sent to asambl's managed AI and is not retained long-term. While web search is on, the search text composed for a request goes to asambl's search providers, never your files. AI and web search can each be switched off entirely.

Now the concessions. asambl is not offline. Weekly planning makes a cloud call to a managed endpoint hosted on Azure OpenAI, and with AI switched off the drafting stops, though the rest of the app keeps working. If you want a planner that needs no network at all, asambl is the wrong choice and the fully-local picks in the private planner round-up are better, several of which beat asambl outright on local-ness.

What crosses, and what never does

Stays on your computer

  • Your plans, notes, journal and reviews, as plain files
  • The semantic search index, built and queried on your device
  • Everything else you have not put in a prompt or a search
  • An AI request

    Your computerone prompt, for that request onlyManaged AI (Azure OpenAI, via our proxy)

    Not retained by asambl. Microsoft may hold prompts up to 30 days for abuse monitoring, then they are gone. Never used to train models.

  • A web search

    Your computer, while web search is onthe search text composed for that request, with your home city addedTavily for the web; Azure Maps and Ticketmaster for places and events

    Never your files. Not stored by asambl. Switch web search off in Settings and nothing on this lane leaves.

  • A phone capture

    Your phoneend-to-end encrypted, unreadable in transitYour desktop, the only place that can read it

    The relay holds only unreadable payloads and delivery status, which auto-expire within days.

  • Calendar sync

    The one Google Calendar you choosetwo-way, opt-in, revocableYour week in asambl

    You grant it, you can disconnect it, and .ics export works without it.

The larger concession is about scope. asambl is not a general assistant and will not become one. It does not book your dentist, read your inbox, or hold your card. It has no standing connection to any account of yours. If what you want is an agent that acts across your services, asambl does not do that job and this page is not an argument that it secretly does.

What it does instead is draft a week across six life areas from context you have chosen to give it, and wait for your yes. The difference that matters here is structural rather than a promise: there is no standing access to revoke, and there is no advertising business behind the product that would benefit from knowing what is in your week. Semantic search and embeddings run on your device, and there is no bring-your-own-key or provider choice to misconfigure. How your data moves, in detail has the full data map.

What to check before you connect anything

  • Ask what the tool sees, not what it encrypts: one request, or a standing connection to an account
  • Find the retention answer on the company's own site, and treat its absence as the answer
  • Check whether the assistant sits inside an advertising business, and whether your data feeds it
  • Find the revocation path before you grant access, not after, and check what happens to what it already read
  • Be suspicious of any cloud-AI product claiming nothing ever leaves your device, because it cannot be both
  • Remember that an inbox is not only yours: granting access shares what other people sent you in confidence
  • Grant the narrowest scope that does the job, and re-check it after each major update
  • If a tool cannot survive you reading its privacy page, that is the test working

Sources

checked 26 September 2026

Deliberately structural: the assistant category is changing monthly, so this page names no product and pins no version, tier or feature state. The claims kept are the ones that survive releases, and they are about how permission models work rather than about any company's current behaviour. asambl's own data handling is stated from the product's privacy policy and the detailed data map, checked 26 September 2026.

  • For asambl's own boundary, the canonical references are the privacy policy and how your data moves, in detail, which lists every provider that receives anything and when.
  • For any other assistant, the only sources worth trusting are its own privacy policy and data-deletion pages, read before you connect rather than after. Third-party summaries of a product weeks old go stale quickly.

Plan the week before it starts

Notes on deciding what next week is actually for, plus the occasional essay. Sent when there is something worth reading, not on a schedule. No product pitch, unsubscribe any time.