Privacy outline
Working notes for a later brochure privacy page. Verify against the shipped beta and actual data flows before publication.
Source: PRIVACY-OUTLINE.md.
This page is not a final privacy policy, Terms of Service, or legal advice.
Do not treat it as GDPR/CCPA guarantees, certifications, or “we never sell data” claims.
Local-first design (verify in implementation)
- Core help/search, installed-app catalog, local knowledge packs, and local indexing are designed to work on-device; offline results should remain useful.
- Local timer/reminder state is designed to remain local.
- Query history is optional; if enabled, it is designed to be local with clear/delete controls.
- Active-app identity/name is used only when the user enables that context. Core help/search does not require Accessibility.
- Core design excludes screenshots, screen recording, OCR, document/window text, keystroke capture, and browsing-history collection.
- Menu guidance is a separate, explicit Accessibility action: read only exposed menu titles for the chosen current app and request; no continuous scan or automatic clicks.
- Local search has no default online query or active-app-context send — design-only until verified in a running build.
May leave the device / use a network
Documented design, not a live claim:
- Optional online catalog and versioned knowledge-pack delivery are proposed.
- Proposed service metadata may include pack revisions, manifests, moderation, and entitlements; the service and endpoint are not established.
- Direct-build Pro is locked to an external checkout; provider, payload, account data, retention, and disclosures are TODO.
- Beta signup data, email provider, analytics, logs, cookies, IP handling, retention, and deletion route are TODO; no signup endpoint or legal treatment is established.
- AI, voice, dictionary, connectors, and organization resources may have separate data routes — TODO per capability. Any external handoff should show provider, payload, destination, and user action first.
Not claimed yet
- Final privacy policy, Terms, or legal advice
- Jurisdiction-specific rights guarantees
- Compliance or security certifications
- Subprocessor lists, retention windows, deletion timelines, export guarantees
- Encryption, incident-response, cookie, analytics, or IP-handling claims as published fact