# Privacy notice

> Your data stays on your computer: we never handle your accounts or API keys, and there is no telemetry. When data goes to AI services, Telegram or Photon.

## In one sentence

Universe Bot runs on your computer. Your conversations, memory, settings and API keys stay on your computer, we run no servers that collect them, and the app has no telemetry.

## Where your data lives

| Data | Location | Protection |
|---|---|---|
| Conversations, agent settings, memory, routines, usage history | The app's folder on your computer (plain JSON files) | Folder permissions allow only your user account to read it |
| API keys, passwords, bot tokens and other secrets | Same folder, encrypted | Encrypted with a key from your system keychain (the macOS keychain or a Linux keyring). If no system keychain is available, the app refuses to save them rather than storing plain text |
| Files agents work on | UniverseBot/workspace in your home folder (or a folder you choose) | Managed by you |
| Each agent's browser sign-ins | Inside the app's folder, separate per agent | Your everyday Chrome data is never touched |

## We never handle your accounts or keys

- For subscriptions, you sign in yourself inside the official tools (Claude Code, Codex CLI, Gemini CLI). Universe Bot only runs those tools; it does not read or store your account password.
- API keys you enter in the app are only used to call the service you chose and are not sent anywhere else.
- Text written to logs or error messages is scrubbed of anything that looks like a key first.

## When data leaves your computer

| Situation | Where the data goes | Whose privacy policy applies |
|---|---|---|
| An agent does any work | The AI service you chose for that agent (Anthropic, OpenAI, Google, or an API service you entered such as OpenRouter) | That service's terms and privacy policy; free plans may train on your conversations |
| Web search or the browser is on | The websites the agent searches or opens | Each website |
| The Telegram channel is on | Your messages and photos with the coordinator pass through Telegram's servers | Telegram |
| The iMessage channel is on | Messages and photos pass through the servers of the third-party service Photon (photon.codes), then Apple iMessage | Photon, Apple |
| External MCP servers | The servers you attached yourself | Whoever provides that server |

All of these channels and features are off by default and only used once you set them up and turn them on.

## Telemetry

Universe Bot has no usage statistics, crash reporting or analytics tracking. Apart from the services you set up, the app does not connect to the internet on its own.

## Deleting your data

- Deleting an agent also deletes its memory, routines and browser profile.
- Pressing Clear credentials in the Messaging settings deletes that channel's token or secret and unpairs it.
- To delete everything, uninstall the app and delete the app's folder.

## Contact

Universe Bot is operated by Frank Lin. If you have any questions about this notice or your data, email support@universebot.si.
