Last updated August 19, 2026
Norman reads your email and calendar so it can do your busywork. That only works if you can see exactly what it reads, what it keeps, and who else touches it. This page is that accounting, in plain language.
Norman (“Norm”) is an assistant that reads your inbox and calendar, drafts replies and briefings, and waits for your approval before anything goes out. This policy covers the Norman web console at meetnorm.app, the Norm for Mac companion app, and the background jobs that run on your behalf.
Norman is operated by Dunnewold Labs LLC. Questions, requests, and deletion demands go to ryan@dunnewold.studio.
Your account. When you sign in with Google we store your name, email address, profile picture, and the OAuth tokens that let Norm act for you. We never see or store your Google password.
Your mail and calendar. Message senders, recipients, subjects, dates, bodies, and unsubscribe headers; calendar events, times, and attendees. Norm reads these to do its work and keeps what it needs to show you why it proposed something — the card, the draft, and the message it was replying to.
What Norm writes down. Drafts and proposals awaiting your approval, tasks, meeting notes, saved reference material, and a short profile of how you write — distilled from a sample of your own sent mail so drafts sound like you. You can see all of it in the console, and delete any of it.
From Norm for Mac, if you install it. Which apps and windows held focus and for how long, and — when you turn day capture on — short notes about what was on screen. Those notes are written by a model running on your Mac. Screenshots and the raw text read off your screen never leave the machine; only the notes are uploaded.
Meeting audio, if you record one. Audio is uploaded for transcription and stored with the transcript and recap. Dictation audio is never written to disk. With cloud upload off, nothing is sent at all.
Norman requests the narrowest set of scopes that lets it do the job, and the console shows which ones you have granted at any time. If a capability needs a permission you have not granted, Norm does without it rather than asking for blanket access.
| Permission | Why Norman needs it |
|---|---|
| gmail.modify | Read your mail so Norm can triage the inbox and write briefings, create drafts, send a reply once you approve it, and archive mail on an approved cleanup. This is the single Gmail permission Norman uses — it replaces the four narrower ones we used to request. |
| calendar.events | Read your events for briefings and meeting prep, and create or update the ones you approve. Norman does not ask for access to your calendar list or settings. |
Norman’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, and without exception:
Your mail and calendar are sent to Anthropic’s Claude models so Norm can understand them and write the drafts. Anthropic processes that content to return a response and does not use it to train its models. No other model provider receives your Google data.
Norman runs on infrastructure operated by other companies. These are all of them. We do not sell your data, rent it, or hand it to advertisers — there is no advertising in Norman and no plan for any.
| Company | What they do | Where |
|---|---|---|
| Vercel | Hosts the app and runs its background jobs; stores meeting audio. | United States |
| Neon | The Postgres database holding your account, cards, tasks, and notes. | United States |
| Anthropic | The Claude models that read your mail and calendar to draft the work, reached through Vercel's AI Gateway. | United States |
| Deepgram | Transcribes meeting and dictation audio, when you record one. | United States |
| The source of your mail and calendar, and the sign-in provider. | United States |
We may also disclose data if the law requires it, or to protect someone’s safety. If Norman is ever acquired, your data moves with it, and you will be told before that happens.
Your account data, cards, tasks, and notes are kept until you delete them or close your account. Meeting audio and transcripts are kept until you delete the meeting. Day-capture notes are kept as the daily record they exist to produce.
When you delete your account, everything we hold about you is removed from the live database within 30 days, and from backups as those age out.
Data is encrypted in transit and at rest. OAuth tokens are held in an access-controlled database and never exposed to the browser. Norm for Mac authenticates with a device token you can revoke. No system is perfect, and we will tell you promptly if a breach affects your data.
Norman is not for anyone under 18, and we do not knowingly collect their data.
If this policy changes in a way that affects what we do with your data, we will tell you before it takes effect — by email, or in the console. The date at the top always reflects the current version.
Questions: ryan@dunnewold.studio. See also the Terms of Service.