---
title: "Privacy and data"
description: "Understand what stays local, what reaches an Assistant, and what the Orylo backend stores."
locale: "de"
canonical: "https://orylo.io/de/docs/privacy-security"
product_status: "in-development"
last_reviewed: "2026-09-01"
---

# Privacy and data

Understand what stays local, what reaches an Assistant, and what the Orylo backend stores.

## Stored locally

- Conversation messages and activities
- Managed attachment snapshots
- Assistant and Agent configuration
- Workspaces, tags, Teams, tasks, and Actions
- Downloaded speech and OCR models

## Sent to your Assistant

When you press Return, Orylo sends the prompt and visible reference context to the Assistant you selected. That Assistant and its provider then apply their own privacy and retention rules. Orylo does not route the request through its account backend.

## Orylo online services

Orylo uses an installation identifier, a device public key, a generic Mac label, and activation and verification times to manage your license. It does not collect your hardware serial number or computer name. When your Mac activates or verifies access, Orylo also sends its macOS version, processor architecture and chip model, Mac model identifier, and Orylo version and build. We keep the latest configuration with your device record to understand compatibility and device distribution; it does not determine your license or device allowance. These records are removed when your account is deleted. Your personal license allows two active Macs. Manage devices on the Orylo website account page. During an active trial or purchase, you can deactivate an old Mac there, then click Refresh access in the app to activate your Mac. Up to four activations are available in any 30-day period, including your first two Macs. A deactivated Mac may retain offline access until its existing verification expires, for at most 72 hours.

The online backend is limited to account identity, purchase entitlement, and feedback. Public database tables use row-level security, and payment state advances only from verified, idempotent payment webhooks.

## Feedback diagnostics

Diagnostics are opt-in and limited to an explicit whitelist such as app/build version, macOS version, architecture, Assistant type/version/status, non-sensitive error code, and source page. Prompts, responses, file paths, file contents, window titles, tokens, and environment variables are excluded.
