Attyn is a local-first personal AI application for macOS, with Windows support planned. This Privacy Policy explains how Attyn ("Attyn," "we," "us," or "our"), operating from Chennai, Tamil Nadu, India, collects, uses, discloses, and protects personal data when you use:
- the Attyn website at https://www.attyn.com and its subdomains;
- the Attyn desktop application;
- Attyn accounts, trials, memberships, one-time licenses, credits, support, and related online services;
- Attyn agents, workflows, connected tools, and optional cloud-powered features; and
- team deployments, custom services, or Attyn AI Box services that refer to this Policy.
Together, these are the "Services."
This Policy does not govern third-party services that you choose to connect to Attyn or third-party AI providers that you use with your own account or API key. Those providers process data under their own terms and privacy policies.
1. The short version
- Your working data is local by default. Attyn stores workspaces, profiles, memory, sessions, activity, schedules, workflows, and plugin state on your computer.
- Secrets are stored in your system keychain. On macOS, API keys, provider secrets, refresh tokens, and integration credentials are stored in Apple Keychain rather than ordinary configuration files.
- Attyn does not need a copy of your local workspace to operate. We do not routinely receive the contents of local chats, files, memory, generated documents, or activity logs.
- Data leaves your computer when you choose a cloud feature. If you select a cloud AI model, use Attyn credits, connect an external service, send a support request, or use another network feature, the data needed for that request is transmitted to the relevant provider or service.
- You control sensitive permissions. Microphone, screen recording, accessibility, input monitoring, file, and connected-app permissions are granted and managed through your device or the relevant service.
- We do not sell personal data. We do not sell or rent your personal data, and we do not use your private workspace content for cross-context behavioural advertising.
- We do not train general-purpose AI models on your private content. We do not use prompts, files, recordings, connected-app content, or AI outputs to train a general-purpose AI model unless we first obtain your express, separate consent.
2. Who is responsible for your data
For personal data collected through the website, account, billing, support, and Attyn-operated online services, the controller or responsible organisation is:
Attyn Chennai 600062, Tamil Nadu, India Privacy and grievance contact: Attyn Grievance Officer, contact@attyn.com
For purposes of applicable Indian data-protection law, Attyn is the body corporate responsible for personal data under its control and, as the relevant provisions of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") take effect, will act as the Data Fiduciary for digital personal data for which it determines the purpose and means of processing.
When an organisation provides Attyn to its staff or users, that organisation may be the controller of information it asks those users to process. In that situation, Attyn may act as a service provider, processor, or data intermediary under the organisation's instructions. Questions about organisation-controlled data should usually be directed to that organisation first.
3. Information we collect
The information we collect depends on how you use Attyn.
3.1 Account and identity information
When you create or use an Attyn account, we may receive and store:
- your name, email address, profile image, and provider account identifier from Google sign-in;
- an Attyn account identifier;
- authentication tokens and session information;
- trial start and end dates, plan, license, workspace entitlement, and account status; and
- account security and sign-in events.
Google handles your password. Attyn does not receive it. The desktop session is stored in the system keychain where supported.
3.2 Purchase, subscription, and credit information
If you make a purchase, we and our payment processor may process:
- your name, email address, billing address, country, and tax information;
- the product, membership, credit pack, workspace, or service purchased;
- transaction identifiers, payment status, invoice, refund, and chargeback information; and
- limited payment-method information, such as card brand and last four digits.
Payment card numbers and security codes are processed by the payment processor and are not stored in full on Attyn systems.
3.3 Website, waitlist, contact, and support information
When you visit the website, join a waitlist, contact us, request a demo, submit feedback, or ask for support, we may collect:
- your name, email address, company, areas of interest, and message;
- information you voluntarily include in correspondence or attachments;
- basic request and security data, such as IP address, browser type, device type, timestamps, referring page, and request status; and
- diagnostic data that you choose to send, such as app version, operating-system version, error details, or logs.
Please remove private workspace content and third-party personal data from support materials unless it is necessary to resolve your request and you are authorised to share it.
3.4 Local workspace and app data
Attyn may create and process the following information locally on your device:
- chats, prompts, instructions, and AI outputs;
- workspaces, profiles, personas, preferences, and permission settings;
- memory, context summaries, pinned documents, and context folders;
- files, attachments, generated images, decks, documents, spreadsheets, and PDFs;
- activity history, tool calls, approval records, schedules, background runs, and workflow state;
- local calendar data and other local app state; and
- local model files and configuration.
This data remains on your device unless you direct Attyn to transmit it through a cloud model, connected tool, email channel, support request, sync feature, or other network service.
3.5 Voice, meeting, screen, cursor, and accessibility data
If you enable the relevant features, Attyn may process:
- microphone audio for dictation, voice conversations, or meeting notes;
- meeting audio, transcripts, summaries, and extracted action items;
- screenshots or other screen content when you invoke Screen Assist;
- selected text and surrounding app context used for Inline Assist or formatted dictation;
- keyboard shortcut signals used to detect push-to-talk or other commands; and
- accessibility events needed to insert approved text or interact with supported applications.
Dictation can use a local speech model. When local transcription is selected, audio stays on the device and temporary recordings are deleted after transcription. If you choose a supported cloud transcription or AI service, the relevant audio, transcript, screen content, selected text, or other request content is sent to that provider.
Attyn does not intentionally activate the microphone or capture your screen unless the relevant feature is invoked, scheduled, or otherwise enabled by you. Operating-system permissions can be withdrawn in your device settings.
3.6 AI request content
Depending on the feature and model you select, AI request content may include:
- prompts, chat history, workspace instructions, and relevant memory;
- selected text, attachments, files, images, screen captures, or transcripts;
- content retrieved from a connected tool;
- tool definitions and the minimum context needed to perform a request; and
- the AI provider's response and usage information.
If you use a local model, this processing occurs on your device. If you use your own API key, the request is sent to the provider you configured. If you use Attyn credits, the request may pass through Attyn's model-routing or billing infrastructure before reaching the selected model provider. See Section 6.
3.7 Connected services and channels
If you connect services such as Gmail, Google Calendar, or Google Sheets, or use an email channel or another supported integration, Attyn may process:
- the connected account and workspace identifier;
- OAuth tokens, API keys, and granted permission scopes;
- messages, recipients, headers, calendar events, spreadsheet ranges, files, or other content needed for the action you request;
- event or webhook data needed to start an approved workflow; and
- action results, errors, and audit information.
On macOS, connection secrets are stored in Apple Keychain where supported. Content is accessed only within the permissions you grant and in response to your instructions, configured workflows, schedules, or allowed senders. Connected services may independently record your activity under their own policies.
3.8 Usage, reliability, and security information
We may collect limited information needed to operate account, download, licensing, billing, credit, website, and security functions, including:
- app version, operating system, device type, language, and general region;
- sign-in, entitlement, credit balance, purchase, and license-validation events;
- feature counts or content-free usage events;
- API endpoint, status code, latency, crash, and error information; and
- fraud, abuse, and security signals.
We do not intentionally include the contents of local chats, files, prompts, recordings, or outputs in content-free analytics. If an error report may contain content, we will ask you before it is submitted or clearly identify what will be sent.
3.9 Information about other people
You may provide information about other people through files, emails, meetings, contacts, calendars, or other content. You are responsible for having a lawful basis and any required notices or permissions before providing that information to Attyn or a connected service.
4. How we use information
We use personal data to:
- create and secure accounts and authenticate users;
- provide trials, memberships, licenses, workspaces, downloads, updates, and support;
- process purchases, credits, refunds, taxes, and transaction records;
- route requests to the local model, cloud model, or connected tool you select;
- carry out scheduled, approved, or otherwise authorised agent actions;
- maintain activity records and permission boundaries;
- respond to enquiries, support requests, demos, and waitlist submissions;
- send service, security, billing, and account communications;
- send marketing communications where permitted, with an unsubscribe option;
- prevent fraud, abuse, security incidents, and violations of our Terms;
- debug, maintain, and improve the reliability and usability of the Services;
- enforce agreements and protect users, Attyn, and others; and
- comply with legal, tax, accounting, and regulatory obligations.
We may aggregate or de-identify information so it no longer reasonably identifies an individual. We may use that information for lawful product, security, analytics, and business purposes.
5. Legal bases for processing
We process personal data only for lawful purposes connected with the Services. For individuals in India, we provide notice and obtain consent where required, or rely on another ground or legitimate use permitted by applicable Indian law. Until superseded or displaced by provisions brought into force under the DPDP Act, our handling of sensitive personal data or information is also governed, where applicable, by the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules").
Where another applicable law requires a specific legal basis, including in the European Economic Area or United Kingdom, we rely on one or more of the following:
- Contract: to create your account, provide the Services, process your purchases, and respond to support requests.
- Legitimate interests: to secure, maintain, understand, and improve the Services; prevent fraud and abuse; communicate with customers; and protect legal rights, provided those interests are not overridden by your rights.
- Consent: for optional permissions, non-essential cookies, marketing, meeting recording, and other processing where consent is required. You may withdraw consent at any time, without affecting earlier lawful processing.
- Legal obligation: to comply with tax, accounting, consumer protection, law-enforcement, sanctions, and other legal duties.
Where Singapore's Personal Data Protection Act applies, we collect, use, and disclose personal data with consent, deemed consent, or another permitted basis, and only for purposes that a reasonable person would consider appropriate in the circumstances.
5.1 Sensitive personal data in India
Under the SPDI Rules, sensitive personal data or information may include passwords; financial information; physical, physiological, or mental health information; sexual orientation; medical records and history; and biometric information. If we collect such information through an Attyn-operated service, we will obtain consent where required, use it for a lawful and necessary purpose, apply reasonable security practices, retain it only as necessary or legally required, and permit review or correction as applicable. You should not submit sensitive information to a cloud model, connected service, or support channel unless it is necessary and you are authorised to do so.
6. When information leaves your device
Local-first does not mean that every feature is offline. Data may leave your device in the following situations.
6.1 Your own AI provider key
When you configure a third-party AI provider, Attyn sends the content needed for your request directly to that provider or its designated endpoint. The provider's terms, retention settings, training choices, region, security, and charges apply. Attyn is not responsible for the provider's independent processing.
6.2 Attyn credits
When you use Attyn credits, Attyn must authenticate the request, measure usage, deduct credits, and route the request to a supported AI provider. The request content and output may therefore be processed by Attyn's infrastructure and the selected provider solely to deliver the feature, secure the service, and account for usage.
We do not use that content to train a general-purpose AI model unless you separately opt in. Provider retention and abuse-monitoring practices may apply as described in the provider information presented in the app or our subprocessors list.
6.3 Connected tools
When you ask Attyn to read from or act in a connected service, the necessary data is exchanged with that service. For example, sending an email requires the draft, recipients, and related metadata to be sent to the email provider. Your use of the connected service remains subject to its terms and privacy policy.
6.4 Web research and external content
Research, browsing, and retrieval features send search queries, URLs, and technical request data to search, browsing, content, or model providers. Website operators may receive ordinary web request information such as IP address and user agent.
6.5 Support and diagnostics
Information you include in a support request or diagnostic report is sent to us and to the service providers we use to manage support and communications.
7. How we disclose information
We may disclose personal data to:
- identity and account providers, including Google/Firebase authentication and Supabase-hosted account and plan services;
- payment processors, tax, and billing providers that process purchases and manage payment records;
- hosting, delivery, security, communications, and support providers that operate the website and online account services;
- AI model, speech, image, search, and browsing providers selected by you or used to fulfil a credits-based request;
- connected services when you authorise an integration or action;
- professional advisers and auditors subject to appropriate confidentiality obligations;
- authorities or other parties when reasonably necessary to comply with law, legal process, or valid government requests, or to protect rights, safety, and security; and
- a successor or transaction counterparty in connection with a merger, financing, reorganisation, acquisition, insolvency, or sale of assets, subject to appropriate safeguards.
We do not sell or rent personal data. We do not share personal data for cross-context behavioural advertising as those terms are defined under applicable US state privacy laws. If that changes, we will update this Policy and provide any required opt-out mechanism before the new practice begins.
8. Cookies and similar technologies
The website may use cookies, local storage, and similar technologies that are necessary for sign-in, security, preferences, checkout, and core website operation. Third-party checkout or sign-in pages may set their own cookies.
If we use non-essential analytics, personalisation, or advertising technologies, we will provide any notice and consent controls required by applicable law. You can also manage cookies in your browser, although blocking necessary technologies may prevent parts of the website from working.
Attyn does not respond to browser "Do Not Track" signals because there is no consistent industry standard for those signals. Where required, we honour legally recognised opt-out preference signals, such as Global Privacy Control, for processing to which the signal applies.
9. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide a perpetual license, maintain transaction records, meet legal obligations, resolve disputes, and enforce agreements.
Retention is determined by the type of information:
- Local workspace data: remains on your device until you delete it. Removing the application may not delete files you exported, local backups, or app-support data retained by your operating system.
- Account and entitlement data: kept while the account or license remains active and for a reasonable period afterwards for security, restoration, dispute, and legal purposes. Data needed to verify a perpetual license or purchase may be retained for the life of that entitlement.
- Billing and tax records: retained for the period required by tax, accounting, payment-network, and anti-fraud laws.
- Support and contact records: retained while the request is active and for a reasonable period afterwards to maintain support history and protect legal rights.
- Security and technical logs: retained for a limited period appropriate to security, fraud prevention, debugging, and reliability, and for any minimum period required by applicable Indian law.
- AI or connected-service content: retained according to the configuration and policy of the provider you selected. Attyn retains credits-based content only when necessary to deliver the request, investigate security or abuse, comply with law, or when you expressly ask us to save it.
When information is no longer required, we delete or de-identify it. Residual copies may remain in encrypted backups until those backups are overwritten in the ordinary course.
10. Your choices and privacy rights
You can control much of Attyn directly by:
- choosing local models instead of cloud providers;
- connecting or disconnecting external services;
- changing model, workspace, memory, schedule, and agent settings;
- granting or withdrawing microphone, screen recording, accessibility, input monitoring, file, and other device permissions;
- deleting local chats, memory, files, schedules, activity, or other app data using available controls;
- managing or deleting local data through your operating system;
- unsubscribing from marketing emails; and
- contacting us to close your account or exercise a privacy right.
Depending on where you live, you may have rights to:
- know whether we process your personal data and access a copy;
- correct inaccurate or incomplete data;
- delete personal data;
- restrict or object to processing;
- receive certain data in a portable format;
- withdraw consent;
- opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
- limit certain uses of sensitive personal data where applicable;
- appeal a refusal of a privacy request where applicable;
- receive information about how your data was used or disclosed; and
- complain to your local privacy or data-protection authority.
To make a request, email contact@attyn.com. We may need to verify your identity and authority. You may use an authorised agent where the law allows. We will not discriminate against you for exercising a privacy right.
These rights apply to information in our possession or control. Because most workspace content is stored only on your device, we may not be able to access, export, correct, or delete it for you.
10.1 Rights and grievances in India
Subject to applicable Indian law and the relevant provisions being in force, individuals in India may have rights to obtain information about personal data processing, request correction or completion, request erasure, withdraw consent, and seek grievance redressal. Withdrawing consent does not affect processing already carried out lawfully, and we may retain or process information where required or permitted by law.
To exercise a privacy right or raise a grievance, email contact@attyn.com and include enough information for us to identify the relevant account or request. Our Grievance Officer will acknowledge consumer grievances within 48 hours and seek to resolve them within one month, as applicable. Other privacy requests will be handled within the period required by applicable law.
Once the relevant DPDP Act provisions are in force, you may also have the right to nominate another individual to exercise your rights in the event of death or incapacity and, after exhausting our grievance process, to complain to the Data Protection Board of India in accordance with applicable law. You are responsible for providing authentic information and must not impersonate another person or submit a false or frivolous grievance.
10.2 California privacy notice
This section applies only if the California Consumer Privacy Act, as amended ("CCPA"), applies to Attyn's processing. The categories below describe personal information we may have collected in the preceding 12 months. Whether we collect a category from you depends on the features you use.
| CCPA category | Examples in Attyn | Sources | Main purposes and disclosures |
|---|---|---|---|
| Identifiers | Name, email, account ID, IP address, connected-account ID | You, Google sign-in, connected services, and your device | Account, security, support, integrations; disclosed to identity, hosting, support, and connected-service providers |
| Customer records and commercial information | Billing contact, plan, license, purchases, credits, invoices, refunds | You and payment providers | Checkout, entitlement, accounting, fraud prevention; disclosed to payment, tax, hosting, and professional-service providers |
| Internet or electronic activity | Website requests, sign-in events, feature counts, status codes, device and app version | Your browser, device, and use of online Services | Security, reliability, debugging, and service improvement; disclosed to hosting, security, and technical service providers |
| Approximate geolocation | General region inferred from IP address or billing country | Your network connection and payment provider | Security, tax, localisation, and legal compliance; disclosed to hosting, security, payment, and tax providers |
| Audio, visual, and electronic information | Audio, screen content, attachments, messages, prompts, and outputs when you choose a cloud feature | You, your device, connected services, and permitted senders | Delivering the requested AI, transcription, research, support, or connected-service feature; disclosed to the provider you select and infrastructure needed for the request |
| Professional or education information | Company, role, school, workspace context, or similar information you provide | You or an organisation that provides Attyn to you | Account setup, personalisation, team services, support, and the feature you request; disclosed to service providers only as necessary |
| Inferences | Persona, preferences, memory, or task classification generated from your instructions | Your Input and use of Attyn | Local personalisation or providing the cloud request you choose; disclosed to a selected provider only when needed for that request |
| Sensitive personal information | Account credentials or message contents processed for an authorised service, and sensitive details you choose to include in a cloud request | You, your device, and connected services | Providing and securing the requested service; not used to infer characteristics or for purposes beyond those permitted by the CCPA |
We may disclose these categories to service providers and contractors for the business purposes described above, or to third parties at your direction, such as an AI provider or connected service. We do not sell personal information or share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information to infer characteristics about you.
California residents may exercise applicable rights to know, access, correct, delete, and obtain a portable copy; to opt out of sale or sharing; to limit certain use of sensitive personal information; and to receive equal service and pricing. Because we do not sell or share personal information or use sensitive personal information for a purpose that triggers a limitation right, we do not currently provide "Do Not Sell or Share" or "Limit" links. If our practices change, we will add the required controls before the new processing begins.
11. International data transfers
Attyn and its service providers may process account, billing, support, and network-feature data in countries other than India or the country where you live. Those countries may have different data-protection laws.
Where required, we use contractual, organisational, or other lawful transfer safeguards intended to provide a comparable level of protection, including applicable standard contractual clauses. Transfers of sensitive personal data from India will comply with the SPDI Rules, where applicable, and transfers governed by the DPDP Act will be subject to any restrictions notified by the Government of India after the relevant provisions take effect. You may contact us for more information about relevant safeguards.
12. Security
Attyn uses technical and organisational safeguards designed to protect personal data, including local storage by default, operating-system keychain storage for supported secrets, encryption in transit, access controls, approval gates, and security monitoring for online services.
No product, device, network transmission, or storage system is completely secure. You are responsible for securing your device, operating-system account, connected accounts, API keys, and backups; reviewing permission and approval settings; and installing appropriate updates.
If we become aware of a personal-data breach affecting information under our control, we will investigate and provide legally required notifications.
13. Children and young users
Individual Attyn accounts and consumer purchases are intended only for people who are at least 18 years old and legally able to enter into a binding contract. We do not knowingly permit a child to create an individual account or purchase the Services.
If we offer a school, family, or organisation-managed service for a person under 18, it must be governed by a separate written arrangement and legally valid, verifiable consent from a parent or lawful guardian where required. When the child-protection provisions of the DPDP Act apply, we will not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, except to the extent an exemption or other rule lawfully applies. If you believe a child has provided personal data unlawfully, contact contact@attyn.com.
14. Third-party links and services
The Services may link to websites, downloads, models, integrations, or services that Attyn does not control. This Policy does not cover their independent practices. Review their terms and privacy policies before providing data or credentials.
15. Changes to this Policy
We may update this Policy to reflect changes to the Services, law, or our practices. We will post the revised version and update the "Last updated" date. If a change materially affects your rights or how we use personal data, we will provide additional notice where required.
16. Contact us
Questions, complaints, and privacy requests can be sent to:
Attyn Chennai 600062, Tamil Nadu, India Grievance Officer: Attyn Grievance Officer Privacy and grievance email: contact@attyn.com
You may also have the right to contact the privacy or data-protection authority where you live.