Privacy Version 1 Effective 2026-10-03 A change gets a new version with its own effective date, and earlier versions stay at their own addresses. See Changes. The short version - Speech is recognised on your computer. What you say and type, and the files your agent may read, go from your machine to your own AI provider, under that provider’s terms. Ginu’s servers are not in that path and do not store it. (#models) - Phone access connects to your running computer; a relay may forward encrypted traffic. (#connections) - Your local files remain under your control. Log cleanup does not delete your memory vault or revoke permissions. (#local) - Signing in, sending feedback and anonymous usage statistics are each optional, described in their own row below. (#activities) - The Ginu website sets no cookies and runs no analytics. The app sets no cookies and has no trackers; usage statistics are sent only if you opt in. (#website) Who is responsible Ginu · support@ginu.ai The point of contact for privacy questions is the support email (mailto:support@ginu.ai). The provider is the controller for the services described here, and there is no appointed data protection officer: Ginu is a small operation, its processing is not large-scale systematic monitoring and it does not process special-category data at scale, so the appointment the law requires of some controllers is not one it has to make. Privacy questions go to the support address and are answered by the provider. What stays on your computer Ginu stores text transcripts, continuity notes, task records and diagnostic logs. Those logs can include turn-taking decisions, permission decisions and discarded utterances. Learned speaking rhythm, the owner voiceprint, acoustic measurements, cached speech and the memory vault are also local data. Voice-derived state is personal data. The application data root is ~/.vori, unless you configure another location. Memory and project files live in its vault directory; transcripts use the configured transcript directory. Session startup sets the data root and transcript directory to owner-only mode (0700). This controls who can open the directories; it does not encrypt the files. Ginu does not encrypt them at rest. FileVault or another disk-encryption setting is a separate protection. Raw utterance audio is not normally saved. The explicit --save-audio option saves it. The macOS microphone indicator may stay on while muted because the input stream remains open and muted frames are discarded in software. Stop the session before cleanup. vori logs purge immediately deletes its listed transcripts, continuity notes, task records, snapshots and diagnostic logs. vori logs purge --all adds learned voice state and caches. Neither command asks for confirmation. The memory vault, agent worktrees, saved preferences, standing permission grants and remote secrets survive both commands. Review memory separately, clean worktrees through git and revoke or rotate security controls deliberately. Deleting a log must not silently remove a permission boundary. See Files on your computer (/guide/reference#files). What reaches your AI provider Ginu runs your AI agents through the command-line program you select as its main model. Claude Code is the default and the one Ginu recommends for the best experience, but it is not required: Codex CLI and Gemini CLI are supported alternatives, and a DeepSeek option runs through the Claude Code program pointed at DeepSeek’s endpoint with your own DeepSeek API key. Whichever you select, Ginu sends it your transcribed speech and the relevant context as text, and the CLI passes that to your AI provider under your own account with that provider and under that provider’s terms and privacy policy. Ginu’s operator has no server in that model-request path, does not receive or store that content merely because you use Ginu, and does not resell, repackage or proxy AI access: the model, the subscription and the relationship with your AI provider are yours. The CLI can read files allowed by its configuration and permissions and may send their contents to its model. In the current Claude bridge, the working directory defaults to the launch directory and the default extra directory is your home directory. Configuring a project does not by itself remove that extra access. The other CLIs have their own permission rules. Review your selected CLI’s scope, and your AI provider’s data policy, before working with sensitive material. Other connections Model downloads. Speech and turn models are downloaded from Hugging Face during setup. That host receives your IP address and the model request. The request goes to the model host, not through Ginu’s operator. Extension packs. Update checks for installed registry or git-hosted packs contact their configured host to check the revision. That host sees the request and its IP address. Ginu’s operator does not receive the request. Installing an update or an integration may make additional requests to the service you selected. Your phone. Pairing exchanges connection information between your phone, your computer and the relay. Where possible, the session travels directly between your devices. TURN can forward encrypted DTLS-SRTP/SCTP traffic when the direct path is unavailable; the relay cannot read those encrypted contents. Your computer remains the machine doing the work. A remote window has its own session identifier and credentials; another phone cannot simply join its occupied peer slot. The relay connection, and the app’s daily check for a new version, are activities with their own rows in the table below. Hosted activities These are the services that run today, one section each. For each one: what is collected, why and on what legal basis, who handles it, where it goes, how long it is kept, whether you have to provide it, and how to exercise your rights. Visiting the Ginu website - Purpose and basis: serving the web page you asked for and keeping the website reachable. Legitimate interests: a request that arrives has to be answered, and the log line is what shows an outage, an attack or a broken deploy. - Data: The address the request came from, the port it came from, any forwarded-for address, the client identification it sent, the page it asked for and the page it was linked from. - Recipients and processors: Amazon Web Services, as processor: CloudFront serves the request and writes the log line. The log bucket and the distribution configuration are in us-east-1, in the United States, and the edge location that answers you is whichever is nearest to you. - Retention: Access-log lines are deleted 30 days after they are written, by a lifecycle rule on the log bucket. AWS deletes on its own schedule after that point, not at a fixed hour. - Required: the request carries this information so that a web page can come back. You can decline to visit. - Your rights: contact the support address. There is no account on the website, so a request needs something to search on — the date and the address you used are usually enough. The app checking whether a newer version exists - Purpose and basis: telling an installed app whether a newer version exists, so it can offer one. Legitimate interests: the check is a single static file, it needs no account, and it cannot be made without a request that carries an address. - Data: the app asks for one file path, once a day, from the host that serves the Ginu website. The request carries your IP address, the port it came from, the client identification the app sends, the path it asked for and the name of the host it asked. It carries no app version, no operating system, no architecture, no query string, no cookie and no body, so what reaches the operator is an ordinary request for a file, not a description of your installation. - Recipients and processors: the host that serves the Ginu website, so Amazon Web Services, as processor, through the same CloudFront distribution that serves the website's pages. - Transfers: the request goes to the same CloudFront distribution as a website page request, so the same location applies: its configuration and log bucket are in us-east-1, in the United States. - Retention: the request is recorded in the same access log as a website page request and deleted on the same schedule, 30 days after it is written. - Required: the check runs by itself once a day while Ginu is running. You are not asked for anything to make it happen, and it carries nothing about your installation beyond the request itself. - Your rights: contact the support address. There is no account to look up, so a date and an address are what a search needs. Pairing your phone through the relay - Purpose and basis: carrying the connection between your phone and your computer. Performance of the service you requested under the applicable agreement: the relay does this one thing and nothing else. - Data: the pairing request, and the connection that follows it. The relay’s own log records the public IP address your phone connected from and the public IP address your computer connected from, together with the session identifier the connection is carried under. The conversation itself is not in that log. - Recipients and processors: Amazon Web Services, as processor: one server in eu-west-2 (London) runs the relay and the TURN fallback. When a direct path cannot be found, TURN forwards the media; it forwards encrypted packets and cannot read them. - Transfers: none — the relay runs in the United Kingdom, and so does everything it forwards. - Retention: A session is held in the relay process's memory and ends with it. Nothing about a session is written to the relay's storage, and no record of one outlives the process. - Required: the addresses are necessary for the relay to connect the two devices. Pairing is optional: Ginu runs on your computer without a phone. - Your rights: end the connection from either device. Contact the support address about anything held for the relay connection. Signing in - Purpose and basis: letting you optionally link a Google, Apple or GitHub identity to Ginu, so a small number of features that need a way to reach you — an emailed reply about a report you sent, recovering your account from another device — have an address. Performance of the service you requested: you asked to sign in. - Data: whichever identity provider you choose confirms your name, an email address if the provider shares one, and a picture if the provider has one. Ginu never receives or stores your password. If you add a verified email directly, only that address and its verification status are stored. - Recipients and processors: Amazon Web Services, as processor — the account link, and any linked email, are stored in a table in eu-west-2 (London). Your identity provider (Google, Apple or GitHub) is itself a separate controller for the sign-in exchange, under its own terms. - Transfers: none for Ginu's own store — it stays in the United Kingdom. Your identity provider's own handling of the sign-in request is outside Ginu's control. - Retention: kept for as long as the account exists. Deleting your account removes the identity link, any linked email, and the sessions and reports tied to the account within a few days. - Required: optional. Ginu runs fully signed out. - Your rights: delete the account yourself from Settings, or contact the support address. Sending feedback or a bug report - Purpose and basis: letting you tell the provider about a bug, ask for something, or leave feedback, optionally with a short excerpt of your own local session log attached so a bug can be reproduced. Performance of the service you requested: you chose to send it. - Data: the title and text you write, which feedback type you chose, your app version and operating system for a bug report, and — only if you explicitly attach one — an excerpt of your own session log. You see and can edit or shorten that excerpt before it is sent; nothing is attached without that step. If you are signed in, the report is linked to your account so a reply can reach you; if you are not, it carries a one-way hashed device key that cannot be turned back into that key or into you. - Recipients and processors: Amazon Web Services, as processor — the report's title, text and metadata are stored in a table in eu-west-2 (London); an attached log excerpt is stored separately, in the same region. - Transfers: none — both stores are in the United Kingdom. - Retention: the report itself is kept for up to 400 days. An attached log excerpt is deleted automatically after 30 days regardless of the report's own status. - Required: optional in every respect — sending feedback at all, and attaching a log excerpt within it, are both your choice. - Your rights: contact the support address to ask for a report, to have it corrected, or to have it deleted, subject to the exceptions that apply. Anonymous usage statistics - Purpose and basis: understanding whether Ginu is being used and roughly how, so the provider can tell whether something it shipped works. Consent: the app discloses this in the same screen where you agree to these terms, with a switch, before anything is sent. - Data: a random identifier generated on your machine when Ginu is first installed (not tied to an account, a name or an email address), your app version, your operating system family, and the start and end time of a session. No file content, transcript, command, model name, or CLI provider is included. - Recipients and processors: Amazon Web Services, as processor — stored in eu-west-2 (London). - Transfers: none — the store is in the United Kingdom. - Retention: a day's tally of which installations were seen is kept 90 days; an individual session's start/end record is kept 90 days. A record of an install still running right now is kept 24 hours past its last check-in. Aggregated daily counts with no installation identifier in them are kept longer, to show trends over a beta. - Required: optional, and off does not limit anything Ginu does. The switch is in Settings › Data and takes effect immediately. - Your rights: turn it off at any time from Settings › Data. Because the identifier is not linked to anything that names you, the provider cannot look up or delete one person's history from it on request — turning it off going forward is the control that exists. Emailing the provider - Purpose and basis: answering what you sent and keeping a short record of the answer. Legitimate interests: a reply needs the message, and a record that is destroyed on arrival cannot answer the follow-up. - Data: your email address, what you wrote, anything you attach, and the history of the exchange. - Recipients and processors: Cloudflare Email Routing, as processor: it receives the message and passes it on without holding a mailbox of its own. - Retention: Until the enquiry is answered and for 12 months after the final reply, then deleted. - Required: writing to that address is optional and nothing else depends on it. Your address is needed if you want a reply; send only what explains the problem. - Your rights: contact the support address to ask for the correspondence, to have it corrected or erased, or to object to it being kept, subject to the exceptions that apply. Installing from a beta invite - Purpose and basis: letting an invited tester install Ginu with one command, and counting completed installs so an invite can be limited and a failed install can be told apart from an abandoned one. Performance of the service you requested under the applicable agreement: you asked to install the beta. - Data: the invite code in the command, your operating system and processor family, the Ginu version installed, the country CloudFront derives from your address, the kind of program that made the request (curl or PowerShell), and the time. When the install finishes, the script sends one short note to say so; if that note cannot be sent, nothing changes and the install still completes. Your IP address is not stored: a one-way digest of it, salted per release, keys a counter that limits wrong guesses and is gone within the hour. - Recipients and processors: Amazon Web Services, as processor: a DynamoDB table in eu-west-2 (London) stores the invite and its redemptions, and the installer is delivered from S3 and CloudFront, which log the request as the Ginu website's pages are logged. - Transfers: none for the invite table, which stays in the United Kingdom. The installer is delivered by CloudFront, whose configuration and log bucket are in us-east-1, in the United States. - Retention: an invite and its redemptions have no automatic expiry: they are kept until the beta ends and are then deleted by hand, as the waiting list is. The guess counters expire within the hour. - Required: optional. You can install from a download instead where one is offered, and Ginu runs the same either way. - Your rights: contact the support address to see, correct or delete the invite recorded for you, subject to the exceptions that apply. Submitting the contact form or the beta-access request - Purpose and basis: answering a message sent through the contact form, and holding a place on the beta waiting list. Performance of the service you requested under the applicable agreement: a reply needs the message, and a place on the list needs to be kept until an invitation is sent. - Data: for the contact form, your email address, your name and your message. For the beta-access request, your email address, the desktop and mobile platforms you chose, and the version of the beta email consent you agreed to. Either request also carries the address it was sent from, kept only to enforce a request limit. - Recipients and processors: Amazon Web Services, as processor: a DynamoDB table in eu-west-2 (London) stores the row. A beta request also triggers one acknowledgement email, sent through Amazon SES from the support email (mailto:support@ginu.ai). - Transfers: none — the table and the acknowledgement email are both in the United Kingdom. - Retention: a contact message expires 180 days after it arrives and is then deleted automatically, usually within a few days. A beta request has no deletion date: it stays on the waiting list, with no automatic expiry, until the beta ends. The rate-limit counters — one keyed to the address the request came from, and for a beta request, one keyed to a one-way digest of your email rather than the email itself — expire five minutes after the window they limit ends, and the database then deletes them automatically, usually within a few days. - Required: using either form is optional. Your email address is needed so a reply or an invitation can reach you. - Your rights: contact the support address to ask for the message or the request, to have it corrected, or to have it deleted, subject to the exceptions that apply. What does not exist yet The desktop app now supports optional sign-in, an opt-in usage-statistics report, and an opt-in feedback and bug-report path — each described in its own row above. The website sets no cookies and runs no analytics, and the app does neither (see Cookies and analytics (#website)). The Contact form and the beta-access request are no longer described here: the service that receives them is now running, and they are described under Hosted activities (#activities) above instead. Anything else that would collect data is not built. When one of them is built, this notice changes before that collection begins, and the version below changes with it: the new activity appears as its own row, with the fields it sends, the purpose, the basis, the recipients, the retention and the control that turns it off. Nothing here is a claim about a service that does not exist yet. Your rights Where the provider processes your personal data, applicable rights include: - Access: ask for a copy of personal data held about you. - Rectification: ask for inaccurate personal data to be corrected. - Erasure: ask for personal data to be deleted where the right applies. - Restriction: ask for processing to be limited in the circumstances the law provides. - Objection: object to processing based on legitimate interests. - Portability: ask for eligible data in a reusable form where the right applies. Contact the support email (mailto:support@ginu.ai) with enough information to identify the relevant activity. Rights have conditions and exceptions; the response should explain any that apply. Local app files are under your control, rather than held by the provider: inspect them on your computer and use the cleanup commands above for their stated scope. Complaints. If you think the provider has handled your personal data wrongly, say so at the support email (mailto:support@ginu.ai), with “privacy complaint” in the subject line. You will get an acknowledgement within 30 days, the provider will look into it and tell you the outcome without undue delay. You can also complain to the Information Commissioner’s Office (https://ico.org.uk/make-a-complaint/). Cookies and analytics The website. The Ginu website sets no cookies and runs no analytics. It serves its fonts, images and scripts from its own origin. There is no cookie consent banner because the website does not use optional cookies or tracking that require a choice. The tutorial saves the lessons you choose to mark complete in session storage in your browser tab. This is not sent to the provider and disappears when the tab’s session ends. Form fields are not saved in browser storage. The app. The Ginu app sets no cookies and contains no advertising or third-party analytics trackers. The only measurement it can send is the anonymous usage statistics described above, and that is off until you turn it on: the switch on the first-run screen starts off, and nothing is sent unless you have chosen to enable it. You can change the choice at any time in Settings › Data. If analytics is added to the website or the app, this notice and any required consent control change in the same release, before that collection begins. Changes This notice is version 1, in force from 2026-10-03. The effective date is shown with the version. Every version is kept. The number identifies what you are reading, the change line in the version history says what moved in one sentence, and an earlier version stays at its own address and is not edited afterwards. Change: First effective version of the privacy notice, in force from 2026-10-03. Describes the model-request path generically as going to your AI provider through whichever CLI you select, and says Ginu does not resell or proxy AI access, states what the app itself does about cookies and analytics, and sets out each hosted activity in plain terms.