A personal assistant becomes more useful when it can work with your email, calendar and documents. Those are also the places where you keep some of your most private information.
Connecting an account shouldn’t mean passing everything through to a model provider unchanged. We’ve added a privacy layer to Micro that filters and redacts text before it leaves your server.
The approach is straightforward: send less, replace identifying details where we can, and keep the information needed to restore them locally.
Email addresses and known names are replaced with consistent placeholders. The model can follow a conversation and refer to the same person without receiving those original values. Micro restores them locally in the answer you see, or when passing arguments to a tool. Existing permissions still apply.
These mappings exist only in memory for a single run. They aren’t shared between accounts or reused across runs.
Recognized credentials receive different treatment. Password fields, access tokens, API keys and other detected secrets are redacted without a reversible mapping. The model doesn’t need your Google refresh token to help you read an email.
For connected Google accounts, we’ve added some specific protections:
- Gmail: mask addresses, known sender and recipient names, message identifiers and private links. Remove standard quoted replies, signature tails and duplicate previews from the model’s copy.
- Calendar: mask exact locations and private links. For availability questions, direct the assistant to the existing free-time tool, which works with busy intervals rather than event details.
- Drive: mask persistent file identifiers and private document links, alongside the general text filtering.
This happens on the copy prepared for the model. Your stored messages and documents retain their original content.
The protection also covers conversation history and tool results. That matters because an assistant may fetch an email halfway through answering a question. Filtering only the initial prompt would leave that later exchange exposed. Streamed answers are restored locally too.
There are limits. This is redaction and pseudonymization, not encryption or complete anonymity. The model still receives meaningful content. A description can identify someone even without their name, and deterministic filters won’t recognize every sensitive detail or every email format. Image and media generation are outside this text-model layer.
But it’s a useful first step: Micro can do more of the work locally to reduce what a model provider receives, while keeping the assistant useful.