Is it safe to let an AI into your email and calendar?

The seven rules, the honest limit of what a rule can do, where your files live, what should never go in, and what happens if the person who built it disappears.

A laptop on a warm desk at dusk showing a week-view calendar full of blocks, a phone beside it showing a list of messages, and a hand resting on the desk near the trackpad without touching it

On this page

In short

  • The first rule is that it drafts and never sends. You test that yourself on install day.
  • Seven rules, in plain English, at the top of your own file. You can change any of them.
  • A rule in a file is a strong instruction, not a padlock. Safety is three layers, and only the third is absolute.
  • Your files are plain text on your machine, read through your own AI account. There is no server of ours.
  • Secrets never go in. It holds the map of where they live, never the things themselves.

Two of the last people who asked about a second brain raised the same objection, independently, before they raised anything else. Not "will it work." Not "what does it cost." They asked whether they were about to hand an AI the keys to their inbox.

It is the right question, and most of the category answers it badly, either by waving it away or by promising a kind of safety that software cannot actually deliver. Here is the honest version: what the rules are, what a rule can and cannot do, where your files live, and what you should never put in one.

Will an AI assistant send emails on its own?

No. The first rule written into a second brain is that it drafts and never sends. It writes the reply, puts it in your drafts folder, and stops. A person presses send, every time, without exception.

This is not a setting buried three menus deep. It is the first line of the file the assistant reads before it does anything, and it is the first thing tested on install day. You ask it to send something. You watch it hand you back a draft instead. Then you believe it, because you saw it, which is worth considerably more than reading it in a brochure.

What are the rules, exactly?

Seven, and they fit on one screen. They are written in plain English at the top of your own file, in your words, and you can change any of them.

  1. Never send anything on my behalf.
  2. Never change my settings.
  3. Never delete anything without asking.
  4. Read-only on anything newly connected.
  5. Ask when unsure.
  6. Never invent facts about my life.
  7. When something is uncertain, say so. The doubt travels with the fact.

The last one is the least obvious and the one that saves you most often. An assistant that hedges when it is unsure is useful. An assistant that states everything with equal confidence is a liability, because you cannot tell the difference between what it knows and what it assembled.

Is a rule in a file actually enforcement?

No, and anyone who tells you otherwise is selling something. A rule in a file is a strong instruction, not a padlock. It shapes behaviour reliably, but it is not a permission system and it should not be described as one.

Safety here is three layers, and only the third is absolute.

  • The rule sits at the top of the file and is read before every conversation. This is the layer that does the day-to-day work.
  • Read-only first. Anything newly connected goes in able to read and not to write. You widen that deliberately, one tool at a time, after you have watched it behave.
  • You press the buttons. The write actions that matter are yours. This is the layer that does not depend on the assistant behaving well, which is exactly why it is the one the whole design leans on.

Being straight about this is not a weakness in the pitch. It is the reason to trust the rest of it. A system described honestly is one you can reason about.

Where does your data live, and who can see it?

On your machine, in plain text files you can open without any special software and without us. The assistant reads them through your own AI account, on your own subscription. Nothing is uploaded to a server of ours, because there is no server of ours.

That has a consequence worth stating plainly: your second brain is subject to the privacy terms of the AI provider you already chose, and nobody else's. If you are comfortable with your current assistant reading a document you paste into it, you are in the same position, with better organisation.

Whoever builds it for you keeps nothing once the work is done, and everything built is yours. An NDA is available on request and is a normal thing to ask for, not an awkward one.

What should never go into a second brain?

Secrets. Specifically: seed phrases, safe combinations, backup codes and passwords. A second brain holds the map of where those things live. It never holds the things themselves.

This sounds obvious and it is routinely got wrong, usually by being helpful. Someone adds a password to a client note because it is convenient once, and now the most sensitive string in the business is sitting in a folder that syncs to a cloud drive and gets read aloud by an assistant several times a week.

The rule is easier to keep than to repair. Password managers exist and are good. Your second brain should know that one exists, and know nothing that is in it.

What happens if the person who built it disappears?

It keeps working, because there is nothing to disappear. The files are plain text on your machine. The assistant is your own subscription. Removing anyone else's access is a short written procedure you run yourself, and you test it on install day rather than taking anyone's word for it.

Every build ships with a handover kit for exactly this: a recovery guide, a list of what anyone else can reach, a map of where everything lives, and the setup written down. It lives outside the system as well as in it, printed and in your email, because a recovery guide stored only inside the thing you are recovering is not a recovery guide.

How do you know it works before you commit?

You use it yourself, from your own phone, away from your desk, before the work is signed off. That is a deliberate gate rather than a courtesy. A system that works when the person who built it is driving is not yet a system that works.

There is a check-in ten days later too, and it exists because of a failure rather than a theory. One install worked beautifully on the day and had quietly degraded three weeks later. Nobody was told, because nothing broke loudly. It simply stopped being used. The ten-day call is the thing that catches that while it is still cheap to fix.

A note from Alex. I would rather lose a sale to this section than win one and have somebody discover in month two that I oversold what a rules file does. The people who ask this question first are usually the ones who end up getting the most out of a second brain, because they are the ones who actually think about what they are connecting.

If that is you, the second brain build page covers what gets built and how, the four layers post covers the architecture, and you can get in touch and ask harder versions of all of this.

Take this with you

Downloads from this post

No downloads on this post.

Alex Chaput

Written by

Creative director in Portland, Oregon. Twenty years in broadcast, motion and brand work, now running In Fair Light: brand films, design systems, and the AI systems that keep the studio running.

More about Alex

More field notes

All posts
A laptop on a warm desk at dusk showing a week-view calendar full of blocks, a phone beside it showing a list of messages, and a hand resting on the desk near the trackpad without touching it

AI systems

Is it safe to let an AI into your email and calendar?

The seven rules, the honest limit of what a rule can do, where your files live, what should never go in, and what happens if the person who built it disappears.

September 16, 2026

A warm modern home office at first light, a walnut desk with an open laptop and a brass lamp, a linen armchair and a low shelf of books, the room lived in and just left

AI systems

What is actually inside an AI second brain?

The four layers, why plain text, what every build comes with as standard, what it runs on, and why you do not need a vector database.

September 16, 2026

Cover graphic: I run my agency out of a folder of text files

AI systems

I Run My Agency Out of a Second Brain. Here Is Exactly What Is In It.

What a second brain is, how In Fair Light runs on one, and what it changes. The four layers, a working day on it, what it costs, and a two-page PDF to keep.

August 31, 2026

Bring the project.

20 minutes, no deck. Tell us what you are making and who it is for, and you will leave with a straight answer on whether this studio is the right fit. Including when the answer is no.

Or email alex@infairlight.com