Anyone can write a privacy policy. A policy is a statement of intent that can be rewritten on a Tuesday. What matters is whether the thing was built so that breaking the promise would take an engineering project — and whether you can check. This page is for the person who wants to check.
What we hold
An account — which can be an email address, or just a 20-digit number with no email at all.
Whether your subscription is paid up, and when it renews.
Counts: enough to run the service and stop abuse. How many, never what.
What we never hold
The things you ask, and the answers you get back.
Your chats. There is no history sitting on our servers, so there is no history to hand anyone.
What you remember, what you keep in your files, or the prompts you have saved.
A profile of you. No cookies, no ad pixels, no analytics identity that follows you.
Constraints, not settings
Four things we gave up the ability to do.
There is no history endpoint. There cannot be one.Your chats, your memory and your saved prompts exist on your device, encrypted at rest. This is not a retention setting we could quietly change our minds about later — the servers were never built to hold it.
Nothing third-party is watching, because nothing third-party is loaded.No cookies, no ad pixels, no analytics kits — not on this site, not in the apps. The only measurement on the public website is a cookie-free counter we host ourselves that never touches the signed-in app and is shared with no one. That is why the App Store label reads Data Not Collected and stays honest.
Between your own devices, we are a blind relay.When your chats move from one of your devices to another, the content is sealed with a key we never hold, passed through a window measured in minutes, and unsealed on the far side. We move a locked box.
The parts that must agree are written once.The encryption, the message format, the codes you verify each other with — one shared core, compiled into every app. Two of our own clients cannot drift apart and quietly weaken something, because there is only one copy of the hard part.
Shared chatsOnly in the apps
How Collaborate is encrypted.
Shared chats are end-to-end encrypted with MLS — the group messaging standard published as RFC 9420 — using the OpenMLS implementation. In practice that means three things worth caring about.
Yesterday stays shutKeys move forward constantly. Someone who takes your phone apart today cannot use what they find to open last month.
A break does not stay brokenIf a device in the group is ever compromised, the group heals itself as it keeps going, rather than staying quietly open forever.
Ready for the computers that do not exist yetKey exchange is hybrid post-quantum — X25519 alongside ML-KEM-768 — so a conversation recorded today by someone patient does not become readable when the hardware catches up.
The assistant is not in the groupThis is worth being precise about, because it is the question people ask. In a shared chat the assistant is never a member of the encrypted group. It does nothing until someone mentions it, answers what it was asked, and has no view of anything else. Attachments carry their own key, sealed inside the message, so what our relay and our storage see is bytes with no way in.
In your handsOnly in the apps
For the moment someone else is holding your phone.
Most privacy thinking is about distant servers. Some of it needs to be about the person standing next to you.
A lock on the app itselfFace ID or a passcode in front of everything, with the key material genuinely cleared when it locks rather than just a screen laid over the top.
A veil over old messagesLeave, background the app or lock the phone and the older parts of the chat cover themselves back up. There are also gentle reminders when you screenshot or copy.
A panic wipeOne control that shreds every chat, every memory and every key on the device, immediately.
Files that expireAnything you keep in the app can be set to destroy itself after a day, a week or a month.
And the small things nobody would noticeThe home screen widget reads none of your data — not by policy, but because it was built without the permission that would let it. Live Activities say a job is running, never what it is about. If you let the assistant know your clock, it gets the time offset and not the name of your region, because an offset is a stripe across many countries and a region name is a place. Nobody is auditing us on that level of detail. It is the level we work at anyway.
Do not take our word for it.
Read the warrant canary. Open the site in a private window and watch the network tab stay empty. Ask the assistant something and see that nothing about it comes back to you as an advert a week later.