Privacy overview

Your work is local by default.

Orylo is designed so that desktop Agent work does not pass through Orylo’s online backend.

Local first

Conversation history, managed attachment snapshots, Assistant configuration, workspaces, Teams, Actions, and local model files are stored on your Mac.

Orylo does not turn your local conversations into a cloud knowledge base or sync them through your Orylo account.

What gets sent

When you press Return, Orylo sends the prompt and the visible reference context to the Assistant you selected. The Assistant and its provider then apply their own privacy and retention rules.

The Orylo backend is not an Agent proxy.

Agent requests, responses, files, tasks, captures, and local paths do not travel through Orylo account services.

System permissions

Accessibility is requested only for features that read the current selection. Microphone is requested only for voice drafts. Screen recording may be required for screenshots.

Orylo reads the real macOS authorization state and never edits the system permission database or simulates successful access.

Orylo online services

The online backend is limited to account identity, purchase entitlement, and feedback. Public database tables use row-level security. Payment state changes only from verified, idempotent webhooks.

  • Publishable keys only in the website and app
  • Service Role, payment, and email secrets remain server-side
  • No prompt, response, capture, attachment, or workspace sync

Device activation

Orylo uses an installation identifier, a device public key, a generic Mac label, and activation and verification times to manage your license. It does not collect your hardware serial number or computer name. When your Mac activates or verifies access, Orylo also sends its macOS version, processor architecture and chip model, Mac model identifier, and Orylo version and build. We keep the latest configuration with your device record to understand compatibility and device distribution; it does not determine your license or device allowance. These records are removed when your account is deleted. Your personal license allows two active Macs. Manage devices on the Orylo website account page. During an active trial or purchase, you can deactivate an old Mac there, then click Refresh access in the app to activate your Mac. Up to four activations are available in any 30-day period, including your first two Macs. A deactivated Mac may retain offline access until its existing verification expires, for at most 72 hours.

Feedback

Diagnostics are optional and restricted to a small whitelist. Orylo excludes prompts, responses, file paths, file contents, window titles, tokens, API keys, and environment variables.

Policy status

This overview describes the current development baseline and will be replaced by the final public privacy policy before production release. Product behavior and public documentation must remain aligned.