Privacy Policy
What we collect
Account data: Email address, username, and a hashed (non-reversible) version of your password.
Device metadata: Device name, operating system type, registration date, last-seen timestamp, and a public key used to establish your device's encrypted connection. The corresponding private key is generated on your device and never transmitted to us.
Usage data: Connection events, session durations, model token counts, and stored-data volume per device, used for service operation, metering, and your account overview.
Agent content: The messages, instructions, and files you send to the agent, and the responses and results it produces — including screenshots and media captured from your devices at your direction. We process this content to deliver and secure the Service. We use it to analyze and improve the Service only if you have turned that on, which is off by default (see below). To generate responses, this content is sent to our artificial-intelligence model provider for processing.
Attachments: Files you attach to a chat are stored temporarily to deliver them to the agent or a device, and are deleted after use or on a short expiry. File types the agent cannot read are stored without being opened.
Voice: If you use voice features, your audio is converted to text, and replies are synthesized to speech, by our processing providers. Audio is processed transiently and is not retained after processing.
Compute workloads: If you provision cloud machines or accelerated computing, the workloads and data you place there run on third-party infrastructure providers at your direction, under your account.
Server access logs: IP addresses, request paths, HTTP status codes, and timestamps of requests to our servers. Retained for 90 days, then deleted.
Payment data: Payment processing is handled entirely by Stripe. We do not receive, store, or have access to your full card number or payment credentials. We store only what Stripe provides: subscription status, plan type, and a Stripe customer ID.
What we do not collect
We do not access, inspect, store, or retain the content of network traffic tunneled directly between your own devices — that traffic passes through our infrastructure without logging or inspection. (This is distinct from agent content you send to the assistant, described above.) We do not sell or rent your personal data, and we do not share it with third parties for advertising or marketing purposes.
How we use your data
To authenticate you, operate device connectivity, display your account overview, process payments, send service-related notifications you have opted into, detect abuse, and maintain the security and reliability of the Service. Separately, and only with your permission, we use usage and content data to debug, evaluate the quality of agent runs, and improve the Service through automated analysis. That use is off unless you turn it on in Settings → privacy, and you can turn it off again at any time. Processing needed to operate, secure, or bill the Service is not covered by that setting and continues either way.
We may create aggregated or de-identified data from your use of the Service and retain and use it to evaluate quality and develop and improve our products. Such data does not identify you or your content.
Third-party processors
We use a small number of vendors to deliver the Service. They act as processors on our instructions, are bound by contract, and are not permitted to use the data for their own purposes. By category:
- Artificial-intelligence model providers — agent content is sent to generate responses.
- Payment processing — card details are handled entirely by the processor and never reach us.
- Infrastructure, hosting, and network protection — servers, content delivery, and denial-of-service mitigation.
- On-demand compute — cloud devices, accelerated hardware, and voice processing, provisioned at your direction.
- Web search — search queries the agent makes on your behalf.
- Notification delivery — optional messaging channels, only if you enable them.
The current list of named sub-processors is available on request to the address below, and is provided as part of a security review. The set may change as the Service evolves; material changes are reflected here.
Anonymous use of public pages
Our public pages, including the front-page build tool, can be used without an account. For anonymous use we record de-identified interaction signals — the requests made to the tool, coarse usage counts, and a salted hash of the network address for abuse prevention — without linkage to any account or identity. These signals are pruned on a rolling window and are used to operate, protect, and improve the product.
Cookies and local storage
We use a small set of first-party cookies, all set by us and none shared with advertisers: a session cookie that keeps you signed in, a security token that protects forms against forgery, a short-lived state cookie during Google sign-in, a device-fingerprint value used to distinguish humans from bots and to recognize your trusted browsers, and — when you arrive through a campaign link — a referral code so we can tell which outreach worked (expires after 90 days). Interface preferences such as theme are kept in your browser's local storage and never leave your device. We do not use third-party advertising or cross-site tracking cookies, which is why you don't see a consent banner: everything above is either strictly necessary to operate the Service or first-party measurement of our own links.
Data retention
Account and device data is retained while your account is active and for 30 days following account deletion, after which it is purged. Access logs are retained for 90 days. Payment records are retained as required by applicable law.
Your rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. We will respond within 30 days. You can also delete your account yourself in settings → privacy — deletion removes your devices, conversations, memories, media, and tokens, and cancels any active subscription.
Security
We implement reasonable technical and organizational measures to protect your data. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
Children
The Service is not directed to individuals under the age of 18. We do not knowingly collect data from minors.
Changes
We may update this policy at any time. Continued use of the Service after changes constitutes acceptance. Material changes to data practices are reflected on this page.