1Scope and responsibility
This policy describes how AspectGraph handles personal information through AspectGraph Studio, AspectGraph Remote, our websites, and related services covered by this policy.
The operator identified above is responsible for the personal information we process for our own purposes, such as account administration, security, support, and communications. If you use a workspace provided by an organization, that organization may separately determine how information in its workspace is used. Contact the organization about its instructions and access arrangements. Where we process information on an organization's behalf, applicable data-processing agreements also govern that processing.
Studio is a Mac application connected to cloud services. Using it does not mean that all your information stays on your Mac. Workspace content is stored by AspectGraph, and information used by connected AI providers is also subject to their terms and privacy practices.
2Information we collect
Account and workspace information
We process account identifiers, email addresses, profile information made available through your sign-in method, workspace names, memberships, roles, invitations, and connected-device information. We receive information from you, your authentication provider, and people who invite you to a workspace.
We use Clerk for account authentication. If you choose a sign-in provider such as Apple, that provider also processes the sign-in under its own privacy policy. We receive the information your chosen sign-in method makes available, rather than your password for that provider.
Content and activity
We process content you and your agents submit to the Service, including messages, prompts, responses, tasks, boards, decisions, stored knowledge, uploaded files, and work products. Associated records may include authorship, timestamps, revisions, relationships between items, agent identity and status, permissions, and usage information.
We also store application state used to restore your experience, such as saved team configurations, where the relevant synchronization feature applies. Information may come from you, workspace collaborators, connected agents, and services acting on your instructions.
Giving an agent access to a file or system can result in information from that source being included in a prompt, response, uploaded artifact, or workspace record. You should consider the access you grant and the information you ask agents to use.
Device and operational information
Studio automatically reports its application version, operating-system version, and the supported agent software detected on the device once per launch when the report can be delivered. These records are associated with your account and a device identifier, with a reporting timestamp. These source records are not anonymous, even when we use them to produce aggregate statistics about supported environments and version adoption.
We and our infrastructure providers also process information needed to deliver and secure the Service, such as network addresses, request timestamps, authentication and device records, errors, and operational logs. We use this information for troubleshooting, compatibility, abuse prevention, and service reliability.
Support and bug reports
When you contact us or submit a bug report, we receive your message and the information attached to it. Reports may include app and device details, diagnostic events, selected message content, and agent console output. Console output can contain prompts, responses, file paths, source code, or other content from your work, including sensitive information that appears in an agent's session.
In the current Studio bug-report form, including agent console output is selected by default. You can turn it off and inspect the report preview before submitting. Turning off console output does not remove all other diagnostic or selected-message information. Review the preview before sending a report.
Website and email signup information
If you sign up for beta updates or release emails, we collect your email address and signup time. The signup handler also collects browser information and an approximate country supplied by our hosting provider. When available, it includes the referring page, campaign parameters, advertising click identifiers, and the version of the signup page. This helps us understand where signups came from.
Signup records are stored with Cloudflare, our hosting provider. We do not currently send them to a separate email-marketing service. Ordinary website requests also pass through our hosting and security providers.
3Why we use information
We use information to:
- Create accounts, authenticate users, manage workspaces, and deliver the features you request.
- Coordinate agents, route work and messages, store content, synchronize application state, and display activity and usage.
- Diagnose problems, respond to support requests, maintain compatibility, and understand how the Service performs.
- Protect accounts and systems, investigate abuse, and meet legal obligations.
- Send service-related notices and the beta or release updates you request.
- Understand signup sources and improve our onboarding and communications.
Providing account and workspace information is necessary to use the corresponding features. You do not have to subscribe to release emails or submit a bug report to use Studio.
4AI providers, local processing, and model training
When you use an external AI provider or another connected service, the information needed to perform the requested work may be sent to that provider. This can include your instructions, conversation context, relevant workspace information, file content, and generated results. Providers process information according to the applicable service, account settings, contracts, and privacy policies. Their retention and model-training practices may differ.
Local-model inference can occur on your Mac, but messages or results posted to a shared workspace still pass through AspectGraph's cloud service. Choosing a local model does not make every other feature local-only.
Some features support provider credentials stored on your device. If you explicitly configure server-side AI features, provider credentials may instead be stored by the Service in encrypted form so those features can operate. Do not assume every connection has the same storage arrangement.
AspectGraph model training: We may use content from the Service — including messages, agent outputs, and related workspace records — to fine-tune and evaluate the AI services that power AspectGraph, so that agents coordinate and respond better. Content is selected from ordinary use of the Service; we do not use bug reports or support messages for this purpose. Where this processing relies on legitimate interests, you may object by writing to [email protected], and we will exclude your workspace's content from future fine-tuning.
5Who receives information
Information is disclosed as needed to the following recipients:
- Workspace participants: People with access to the relevant workspace or content can receive the information you and agents share there, subject to the Service's access controls. Your organization may manage membership and access.
- Infrastructure providers: Cloudflare provides hosting, database, file-storage, and related infrastructure used by AspectGraph.
- Authentication providers: Clerk and the sign-in providers you choose process identity and authentication information.
- Connected AI and other services: Providers you configure or use receive information needed for the relevant feature or action.
- Support and authorized personnel: Authorized AspectGraph personnel can access account and operational information and the support materials you submit to investigate problems. Staff can view the work content attached to a bug report. Privileged access through our support console is logged. This is not a promise that stored content is technically inaccessible to the operator.
- Communication providers: We do not currently use a separate email-delivery or support-desk provider. Support and legal requests are handled through our own mailboxes.
- Legal and business recipients: We may disclose information where required by law, to respond to valid legal process, to protect rights and safety where lawful, or in connection with a merger, acquisition, financing, or sale, subject to applicable privacy obligations.
Sale, advertising, and cross-context sharing: We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by applicable law. We do not run advertising on the Service and do not upload information to advertising platforms. An advertising click identifier recorded at signup is used only to understand where a signup came from.
6Cookies and device storage
The account web application uses authentication cookies or similar mechanisms and browser storage for preferences and dismissed notices. The Mac application stores settings, cached workspace information, credentials, and agent session history on your device. Local information may remain after you sign out unless removed by the relevant feature or by you.
Our hosting and authentication providers may use cookies or similar technologies for their services. To understand how the Service is used, we may use product-analytics tools — Cloudflare analytics, Google Analytics, Amplitude, or Mixpanel, individually, in combination, or none at all — for aggregate measurement of features and performance. Any such tool receives usage events and technical information, not the content of your work, and is not used for advertising. Where applicable law requires consent for these tools, we will ask before enabling them.
Browser settings can limit cookies and storage, although blocking authentication storage may prevent sign-in. Our websites do not track visitors across other sites. Because we do not sell or share personal information for advertising, we do not currently change our processing in response to Do Not Track or Global Privacy Control signals.
7Retention and deletion
We retain information according to the purpose it serves, the operation of your account or workspace, support and security needs, applicable legal requirements, and the need to resolve disputes. The current system does not apply one automatic expiration period to every category of data.
Archiving content hides it from ordinary lists and is reversible; archiving is not deletion. Some item-level deletion uses a soft-delete record rather than immediately erasing the underlying information and its history.
Workspace owners can request workspace deletion. The implemented workflow schedules deletion after a seven-day grace period during which the owner can cancel it. This is a workspace-deletion workflow, not a promise that every related copy in every system disappears at the end of seven days. Files, diagnostic attachments, account records, backups, logs, and information retained by connected providers require their applicable deletion processes.
We do not apply fixed retention periods. Account records, workspace content and revisions, uploaded files, device reports, and signup records are kept for as long as the account or workspace they belong to exists, and are removed through the workspace-deletion workflow or on request. Bug reports are kept until the problem they describe is resolved. Operational and security logs are kept for a limited time by our infrastructure provider. Email subscriptions are kept until you unsubscribe.
Contact [email protected] to request deletion or ask about a particular category. We may need to verify your identity and authority over the information. Legal exceptions and the rights of other people may limit a request. Information already sent to an independent provider is subject to that provider's deletion procedures. Deleting cloud information does not automatically delete copies that you or collaborators have downloaded.
8Security
We use access controls, authentication, encrypted network connections, and encryption for designated stored information, including infrastructure-managed encryption for hosted databases and files. Selected credentials and local agent history use additional storage protections.
The Service is not represented as end-to-end encrypted. Information must be available to the systems that process it, and authorized access may be required for operations or support. No application, transmission method, or storage system is completely secure. Beta and experimental features may contain additional defects. These risks do not remove our legal duties to protect personal information.
Protect your device and accounts, review agent permissions, and avoid submitting unnecessary secrets or sensitive information. If you enable developer or remote diagnostic features, review what those features expose before sharing access.
9International processing and legal bases
We and our providers may process information outside your country. The fact that Studio runs on a Mac does not guarantee storage or processing in your country.
We are located in the United States, and the Service is operated and hosted there. If you use the Service from outside the United States, your information is transferred to and processed in the United States, where privacy law may differ from your country's. Where applicable law requires safeguards for such transfers, we rely on the contractual terms of our providers; contact [email protected] for information about them.
Where European or UK data-protection law applies, our bases for processing are performance of a contract for account and requested service functions; legitimate interests for proportionate security, reliability, support, product-operation analysis, device reporting, signup attribution, and fine-tuning of the AI services that power AspectGraph; compliance with legal obligations; and consent where required for optional communications, analytics, or other processing.
10Your choices and rights
You can choose what to submit, which services to connect, and what access to grant agents. You can decline to submit a diagnostic report or remove console output before sending one. The device report described in Section 2 is sent automatically when Studio launches and cannot currently be turned off in the app; it is limited to version and compatibility information.
To stop release emails, use the unsubscribe method in the message or contact [email protected]; we honor these requests. Necessary account, security, or service notices are separate from optional release emails.
Depending on your location and the law applicable to us, you may have rights to access, correct, delete, or obtain a copy of your personal information; restrict or object to processing; withdraw consent; or opt out of certain sales, sharing, or targeted advertising. Where applicable, you may use an authorized agent, appeal a decision, and exercise your rights without unlawful discrimination. Withdrawing consent does not affect processing already lawfully performed.
Send requests to [email protected]. We will respond within the time required by applicable law and may request proportionate identity verification. If we cannot fulfill a request, we will explain why, subject to legal restrictions. You may also complain to the data-protection authority or privacy regulator available to you. For an organization-managed workspace, contact its administrator about content the organization controls.
11Children
The Service is intended for adults aged 18 or older. If you believe a child has provided us with personal information, contact us so we can investigate and take appropriate action, including deletion where required. An age restriction is not a claim that we verify every user's age.
12Changes and contact
We may update this policy as our practices or legal requirements change. We will update the effective date and provide additional notice of material changes where required. If a new use requires consent, publishing a revised policy alone will not substitute for obtaining it.
For questions or privacy requests, contact [email protected] or write to the operator's address above.