Security and trust
What we design for, and what we do not claim
This page states the design goals. It will be rewritten against what is deployed and tested when the service launches.
Our approach
- Least privilege. Tools get the access a task needs and no more.
- Approval first. Higher-risk actions, such as sending or buying, stop for your yes.
- Logs without content. Operational logs describe what happened without storing what you wrote.
- Thin apps. Apps hold no secrets. Protected logic runs on our servers.
What we do not claim
No third-party audit or certification has been completed, and none is claimed. We do not claim compliance with any specific law or standard on this page. Counsel will decide what to state and when.
Your data
- Where your data lives. Your account data is stored on our servers, kept apart per person and per persona. Apps on your device hold no secrets.
- Daily Google Drive export. Optional and Off by default. When you turn it on, a daily export goes to your own Drive. You can also export or delete everything.
- Consent defaults. Every optional switch starts Off: Drive export, analytics, crash reports, notifications, personalization, and Google sync. You choose at first run and can change it in Settings. A change in wording asks again.
- Children. People under 18 cannot create their own account. A parent can add a managed child profile with stricter rules: no screen-watching memory, no analytics, no personalization, no connectors, and no free chat.
- Screen-watching memory. Opt-in, for adults only, Off by default, and never on a child profile. It starts as text only; a separate choice is needed for anything involving images. Screens can show other people, so a plain-language screen explains this first.
- Password Manager. Encrypted on your device, so we never hold the readable contents.
- Deletion. Each store of your data has a defined deletion path, run as one account deletion workflow.
- Keys. Access tokens are short lived and refresh tokens rotate on every use.