Privacy policy

U.S. and international users

1. Information we collect

1.1 You provide

  • Account: email address, third party account identifier, and auth tokens used at sign in.
  • Connector authorization: OAuth tokens and connection status when you connect Gmail, Slack, and similar channels.
  • Payment: transaction information handled by our payment processor when you buy or subscribe (we do not store full card numbers).
  • Feedback you submit: your optional note, a bounded structured diagnostic timeline, and any generated reply, conversation excerpt, transcript, counterpart information, or screenshot that you separately preview and choose to include.

1.2 Processed transiently to draft a reply

  • Conversation context: conversation text visible in the current window on your trigger, your instruction, and the local tone/profile memory needed for the reply.
  • Screenshots (fallback): an in memory, cropped image of the current conversation area when Accessibility can't read it (discarded after local OCR).
  • Voice: audio while you hold to talk (for speech recognition; the raw recording is not kept by ToneBird).

1.3 Collected automatically

Anonymous product metrics: event names, enums, counts, app version, OS version, an anonymous install id, and an optional signed in user id. Excludes message bodies, drafts, recipient names, screenshots, and raw audio.

2. What stays on your Mac

ToneBird's live read starts locally: Accessibility reads the current window's visible text; screenshots are handled in memory; OCR runs first on device via Apple Vision. Your tone profile, personal profile, person cards, reply events, learned corrections, and usage counts are stored locally in Application Support. You can view them, open the data folder, or clear them any time in Settings. Diagnostic traces also stay on your Mac unless you actively submit a feedback report; the submission screen shows the exact structured diagnostics and optional content you selected to send.

3. How we use information

  • Provide and operate ToneBird: read the current conversation on your trigger and draft replies in your voice.
  • Authenticate you, meter usage, and enforce quotas.
  • Maintain security, prevent abuse and fraud, and debug technical issues.
  • Improve the product using anonymous metrics.
  • Investigate a problem you deliberately report and track its resolution in our internal issue system.

We do not train foundation models on your conversations, and ToneBird's product metrics never include message content. When you use a model (managed or your own key), the model provider processes the content under its own policy.

4. Screenshots, OCR & voice

Screenshots are only for apps Accessibility can't read; ToneBird crops to the conversation area, runs OCR on device first, and discards the image. Only if OCR is insufficient may a vision capable model receive it for transcription. Raw push to talk audio is not stored by ToneBird; it uses Apple Speech and requests on device recognition where the locale supports it, otherwise Apple's cloud fallback applies under Apple's policy.

5. Service providers

We share only what is necessary, with providers acting as our processors or as independent controllers you direct data to:

We do not sell your personal information, and we do not share it for cross context behavioral advertising. We may disclose information if required by law or to protect rights and safety.

Google user data (Limited Use). ToneBird's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Chat data you authorize (spaces, messages, and memberships) is used only to provide the features you enabled: surfacing conversations awaiting your reply and learning your own writing tone to draft replies for you. We do not sell it, use it for advertising, or transfer it to others except as needed to provide the feature (e.g. the managed connector above), to comply with law, or in a merger. No human reads your Google data except with your consent, for security, to comply with law, or in aggregated or anonymized form.

6. Your choices & controls

  • Use your own model key so requests never pass through our servers.
  • Turn off learning from your sent messages; opt out of anonymous product metrics.
  • Open your local data folder; export or delete your local data from Settings › Privacy & Data.
  • Review each learned adjustment before applying it. Nothing changes how ToneBird writes until you approve it.
  • Review drafts in your own reply box. ToneBird never sends on your behalf; you use the host app to send.
  • Before sending feedback, review and remove every optional content attachment. Feedback is never submitted automatically.

7. U.S. privacy rights

Depending on your state (e.g. California/CCPA, and similar laws in Virginia, Colorado, Connecticut, Utah, and others), you may have the right to: know/access the personal information we hold; delete it; correct it; obtain a portable copy; and opt out of sale/sharing or targeted advertising. As noted above, we do not sell or share personal information for cross context behavioral advertising.

We honor opt out preference signals such as Global Privacy Control (GPC) where applicable. You will not be discriminated against for exercising your rights. To make a request, contact support@amplift.ai; we may need to verify your identity.

8. International transfers

ToneBird is operated from the United States, and our providers are largely based in the U.S.; using ToneBird involves transferring your information to the United States and other countries. Where required (e.g. for EEA/UK users), we rely on appropriate safeguards such as Standard Contractual Clauses. Payment for some regions may be processed by an affiliated entity; where that applies, the payment page will identify the processing entity.

9. Retention & security

Local data stays on your device until you delete it or uninstall. A submitted feedback report may remain in an encrypted local outbox for up to seven days while delivery is retried. The complete live Supabase feedback record, including its copy of your note, bounded structured diagnostics, and any selected private content, becomes inaccessible after 14 days and is scrubbed from live storage within 24 hours; encrypted provider backups may remain recoverable for up to seven additional days. The full delivery row is removed by 30 days. A minimal, long lived duplicate prevention record retains only the random report ID, account bound owner, terminal result or error, and any Linear receipt; it contains no note, diagnostics, environment data, or attachment reference and exists only to prevent report ID takeover and duplicate Linear issues. The safe Linear issue summary is retained for support, security, and product quality records until it is no longer needed or you request deletion where applicable. Account and connection status are kept while you use ToneBird and deleted or anonymized within a reasonable period after account closure, unless the law requires otherwise. We use transport encryption, access controls, encryption at rest, and encrypted token storage (Keychain). No assistant that must send context to an external AI model can claim 100% local privacy.

10. Children

ToneBird is not intended for anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child provided us information, contact us and we will delete it.

11. Changes & contact

We may update this policy periodically; material changes will be notified in the app or on the website. This policy is part of, and subject to, the ToneBird Terms of Service (U.S. & International); if they conflict, the Terms control.

Controller: Ampliftai Inc.
Privacy requests: support@amplift.ai · Support: support@amplift.ai