Privacy policy
Last updated 24 September 2026
The part that matters most: tool calls pass through our servers, and we store what was sent and what came back for 7 days so a call can be retried and audited. If an assistant reads a file on your machine, the contents of that file are in that record for those 7 days. Do not point the agent at folders holding secrets you are not willing to have pass through us.
What we collect
| Account | Email address. Your password is kept only as a scrypt hash, so we cannot read it. Your API key is kept only as a SHA-256 hash and is shown to you once. |
| Machines | The device id and name you choose, the list of tools the agent offers, when it was last seen and whether it is online. The device credential is kept only as a hash. |
| Tool calls | Which tool was called, the arguments sent to it, the result returned, which machine ran it, and timestamps. Arguments and results can contain file paths and file contents. |
| Usage events | A timestamped count for billable calls, used to calculate the rolling quota windows configured for your plan or account. |
| Connected apps | The OAuth clients you approved, the scope granted, and hashes of the tokens issued to them. |
| Sessions | A hashed session token so you stay signed in on this website. |
| Server logs | When a request fails we log the method, path and a correlation id to diagnose it. |
We do not use cookies for advertising or analytics. The only cookie is the one that keeps you signed in.
What we do not collect
- We do not read your files except as needed to carry a call you asked for.
- We do not sell or rent your data, and we do not use it to train models.
- We do not ask for payment card details. Upgrades are arranged directly with you.
How long we keep it
| Tool calls, including arguments and results | 7 days |
| Usage events | At least 35 days, or the longest configured quota window plus 1 day, whichever is longer |
| Website session | 7 days, or until you sign out |
| OAuth access token | 1 hour |
| OAuth refresh token | 30 days, or until you revoke the app |
| Pairing code | 10 minutes, single use |
| Account, machines and connected apps | Until you delete them or close the account |
Who else sees it
The assistant you connect, ChatGPT for example, receives the results of the calls it makes, because that is the point of connecting it. Its own privacy policy governs what it does with them. We do not send your data to anyone else, other than the hosting provider that runs our servers on our behalf.
How it is protected
- Traffic to the service is encrypted in transit.
- Passwords use scrypt; API keys, device credentials, session tokens and OAuth tokens are stored only as hashes and compared in constant time.
- A connected app receives a token bound to your account and to this service; a token issued elsewhere will not work here.
- Your machines are reachable only by your own account. An account cannot see or command a machine paired to another account.
Your choices
- Limit what is collected. Set
AUTONOMOUS_ALLOWED_DIRSon each machine so the agent can only reach folders you choose. - Revoke an app. Connected apps on your dashboard, any time.
- Unpair a machine. Also on your dashboard; its credential stops working immediately.
- Access or delete your data. Ask us on WhatsApp and we will export or erase it.
Changes
We will update this page when what we collect or how long we keep it changes, and update the date at the top.
Contact
Questions about your data: WhatsApp.