AgentIO

Privacy Policy

DRAFT. This text has been written but has not yet been reviewed by a lawyer. The same banner is shown inside the app. It will be removed once legal review is complete.

1. THE CORE PRINCIPLE: DEVICE-FIRST

Your work stays on your device. Your chats, deliverables and the data read from the servers you connect are not stored on our servers as readable content. Two narrow exceptions, both ENCRYPTED: server-side execution (at most 24 hours) and, if you enable device sync, an end-to-end encrypted copy of your team that we cannot read.

2. WHAT WE PROCESS

Legal bases: performance of the contract and legitimate interest (GDPR art. 6(1)(b) and (f); Turkish KVKK art. 5/2-c and f).

3. WHAT WE DO NOT PROCESS

We do not collect, store, sell or use for advertising your conversation content, your files, the data coming from the systems you connect, or your credentials. We DO NOT SELL and DO NOT SHARE personal information within the meaning of CCPA/CPRA.

4. MODEL PROVIDERS

To produce an answer your prompt is passed to the model provider — Anthropic, Google, OpenAI, or via OpenRouter to xAI, Meta or Moonshot. This transfer is required for the service to work. We request zero-data-retention terms where available. If server-side execution is on, records are stored ENCRYPTED for at most 24 hours, then deleted. If you want to work fully offline you can choose the on-device model (Apple Foundation Model); in that mode content never leaves your device.

5. WHAT IS KEPT ON YOUR DEVICE

Your team, minutes, deliverables, memory records, tool credentials (Keychain), consent signatures and tool permissions. Deleting the app deletes all of it.

6. RETENTION PERIODS

7. COOKIES AND TRACKING

No advertising identifier is used, there are no third-party trackers, and no cross-app tracking takes place (there is no processing that would require permission under Apple App Tracking Transparency).

8. YOUR RIGHTS

You have rights of access, rectification, erasure, restriction, objection and portability (GDPR art. 15-22, UK GDPR, KVKK art. 11, CCPA/CPRA, LGPD art. 18, PIPEDA, POPIA art. 23-25, APPI, PIPA, PDPA). You can use the in-app data export and account deletion features, or write to us. In the EU your right to complain to a supervisory authority is reserved.

9. CHILDREN

The app is not designed for anyone under 18. We do not knowingly collect children's data (COPPA, GDPR art. 8).

10. SECURITY

TLS in transit, Keychain for credentials, and access control on the server side. Because no content is stored, the breach surface is minimal.

11. CHANGES

If this policy changes you are notified in the app and, where needed, your consent is asked again.