← Back to Ownware Studio
Privacy Policy
Last updated · 21 June 2026
Ownware Studio is a local-first desktop application. The short version: your data stays on your computer. Your conversations, the files your agents read or write, and the credentials you connect live in a folder on your own Mac and in your operating system's secure keychain — they never reach us, because we don't run servers that store your product data.
This policy explains: what data the app handles, the limited cases where data leaves your device and exactly who receives it, the legal basis for processing, international transfers, how we secure and retain data, and your rights. Part A covers the desktop app; Part B covers this website (ownware.studio).
Part A — The Ownware Studio desktop app
1. What we collect, and what stays on your device
Ownware Studio handles the following categories of data. Unless §2 says it leaves your device, all of it stays only in the ~/.ownware folder on your machine and your OS keychain, and we never receive it:
- Account data — your email, name, and profile picture, from signing in (see §2, Auth0).
- Conversations & agent activity — your prompts, messages, agent transcripts, and any facts an agent records about you.
- Files — files you create, or that agents read or write on your machine.
- Profiles, workspaces & settings — your agents' configuration and your app preferences.
- Credentials — your AI provider API keys and connected-account tokens, encrypted (AES‑256‑GCM) and stored in your OS keychain (macOS Keychain / Windows Credential Manager / Linux libsecret).
- Connected-account content — when you connect an account (e.g. Gmail, Slack, Calendar, Notion), the messages, events, or items your agent works with (see §2, Composio).
- Voice audio — only if you use dictation (see §2, speech-to-text).
- Crash logs — written to your local logs folder; never uploaded.
2. What leaves your device, to whom, and why
Ownware Studio connects to the network only in the specific cases below. In each case the data goes directly from your machine to the named service — never through an Ownware-operated server.
Services Ownware Studio operates or provides:
- Sign-in — Auth0 (Okta, Inc.): when you sign in, your email/name are processed by Auth0 to manage your login. Purpose: provide and secure your account.
- Anonymous usage analytics — PostHog, Inc. (OFF by default, opt-in): only if you turn on "Share anonymous usage data" in Settings → Data & Privacy do we send anonymous product-usage events (fixed labels and counts, plus your anonymous account identifier). These never include your email, name, location, message content, file names/contents, or credentials. Turn it off anytime in the same screen.
- In-app feedback — PostHog: when you choose to submit feedback from within the app, your message, the app version, and an anonymous identifier are sent so we can read and act on it. Because this is something you deliberately send, it is delivered even when analytics sharing is off.
- Automatic updates — GitHub (GitHub, Inc.): to keep the app secure, Ownware Studio checks for new versions when it starts and every six hours, by contacting GitHub. This sends only the current app version and your operating system/architecture — no personal data or account information.
Services you choose, using your own keys or accounts (data goes directly to the provider; we are not in the middle):
- AI model providers: when you send a message to an agent, the content needed for that request is sent directly to the provider you chose — for example Anthropic, OpenAI, or Google — or to a router such as OpenRouter, using your own API key.
- Connected accounts via Composio (Composio, Inc.): when you connect an account, Composio acts as the connection broker — it securely holds the access token for that account and passes requests and responses between your agent and the provider. This means the content of those actions (for example an email's recipient, subject, and body, or a Slack message) passes through Composio's servers, configured with your own Composio API key.
- Voice dictation (speech-to-text): if you dictate, the audio you record is sent to the transcription provider you've configured (e.g. Groq, OpenAI, or OpenRouter), only while you are actively dictating.
- Web search: when an agent searches the web, your search query is sent to the search provider in use — by default DuckDuckGo, or Brave / Tavily if you configure them.
- Tool & profile catalogs: when you browse the tool catalog or install a profile or tool, Ownware Studio fetches listings from the Model Context Protocol registry and from GitHub. If you install from a private GitHub repository, an access token you provide is sent to GitHub to authorize it.
- Page fetching: agents can fetch web pages that you or they specify; those requests go directly to the site named.
3. Google user data & Limited Use
If you connect a Google account (e.g. Gmail or Google Calendar), Ownware Studio accesses, on your behalf, only the Google data needed for the features you use — such as reading and organizing messages so an agent can help you triage or draft replies.
Limited Use. Ownware Studio's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we use Google user data only to provide user-facing features visible in the app; we do not transfer or sell it for advertising; no humans read it except for security, to comply with law, or with your explicit consent; and we do not use it to train generalized AI models. As described in §2, Google requests are brokered through Composio using your own credentials.
4. What we do not do
- We do not run servers that store your conversations, files, or credentials. There is no Ownware Studio database of your product data.
- We do not sell or share your personal information, and we do not use it for advertising.
- We do not track you across other websites or apps, and we do not record your screen or sessions.
5. Who receives data, and where (recipients & international transfers)
The third parties named above process data in the regions below. Where data is transferred internationally, we (or you, for services you connect with your own keys) rely on the appropriate legal basis — your consent, necessity to provide the service you requested, or the provider's own transfer safeguards.
Recipient
What it receives
Region
Auth0 (Okta)
Email, name, login data
Australia
PostHog
Anonymous events; feedback you submit
United States
GitHub
App version + OS (update check); catalog/install requests
United States
AI providers / OpenRouter
Your prompts & conversation content (your key)
United States
Composio
Connected-account tokens & action content (your key)
United States
Speech-to-text provider
Dictation audio (your key)
United States
Search provider
Search queries
United States
6. Legal basis for processing (GDPR / UK GDPR)
- Your account & sign-in: performance of our agreement with you (providing the app) and our legitimate interest in securing access.
- Analytics: your consent (opt-in; withdraw anytime).
- Automatic update checks: our legitimate interest in keeping the app secure and working.
- Services you connect with your own keys (AI, Composio, search, speech-to-text): you direct your own data to those third parties using your own credentials; for that processing you are the controller and the provider's terms apply.
7. How we secure your data
Credentials are encrypted with AES‑256‑GCM and stored in your operating system's secure keychain; the local app database and files live under your user account on your own machine; the app communicates with its local engine only over your computer's loopback interface. Because we hold no server-side copy of your product data, there is no central store for an attacker to breach.
8. How long we keep it
App data is retained on your device for as long as you keep it, and is fully removed when you delete it (see §9). We hold no server-side copy to retain. Anonymous analytics, if enabled, are retained by PostHog under our project settings.
9. Your rights and choices
- Analytics: turn on/off anytime in Settings → Data & Privacy (off by default).
- Export: Settings → Data & Privacy → Export all data.
- Delete: Settings → Data & Privacy → Delete account, or remove the ~/.ownware folder and the app's keychain entries.
- Disconnect an account: revoke any connected account from the app and from that provider's own security settings.
Depending on where you live, you may also have the right to access, correct, delete, restrict, or object to processing of the limited personal data handled by Auth0 and (if enabled) PostHog, to data portability, and to withdraw consent at any time. To exercise any of these, email hello@ownware.studio. You also have the right to lodge a complaint with your local data-protection authority (for example, your EU supervisory authority, the UK ICO, or the Australian OAIC).
Part B — This website (ownware.studio)
10. What we collect, why, and where it goes
When you submit the private-beta application, we collect exactly what you type — your name, email, where you work (optional), and what you'd build first. This site sets no cookies, runs no analytics, and loads no third-party trackers. We use your application only to assess fit for each beta wave and email you an invite; our legal basis is your consent. The form sends your application to our inbox at hello@ownware.studio through EmailJS, then it lives only in our inbox — no marketing database, never sold or shared. If you're in the EU/UK, submitting the form may transfer your application internationally for delivery.
11. How long we keep it
We keep your application only while the private beta is running, or until you ask us to delete it. Applications we don't act on are deleted when the beta ends.
Children
Ownware Studio is not directed to children under 16, and we do not knowingly collect their data.
Changes
If this policy changes, we'll update the date at the top, and for material changes we'll notify you in-app.
Contact
Questions about privacy, or want to exercise a right above? Email hello@ownware.studio.