This is the version identified by the date above.
A change gets a new version with its own effective date, and earlier versions stay at their own addresses. See Changes.
## The short version
- Speech is recognised on your computer. What you say and type, and the files your agent may read, go from your machine to your own AI provider, under that provider’s terms. Ginu’s servers are not in that path and do not store it.
- Phone access connects to your running computer; a relay may forward encrypted traffic.
- Your local files remain under your control. Log cleanup does not delete your memory vault or revoke permissions.
- Installing, signing in and sending feedback are described in their own rows below. Signing in and feedback are optional. Anonymous usage statistics are on by default and you can turn them off.
- Ginu is run from the United Kingdom, and anyone can install it.
- The Ginu website sets no cookies and runs no analytics. The app sets no cookies and has no trackers; anonymous usage statistics are on by default and you can turn them off in Settings › Data.
Who is responsible
Ginu · support@ginu.ai
United Kingdom
The point of contact for privacy questions is the support email.
Ginu is the controller for the services described here. There is no appointed data protection officer: Ginu is a small operation, its processing is not large-scale systematic monitoring and it does not process special-category data at scale, so the appointment the law requires of some controllers is not one it has to make. Privacy questions go to the support address and are answered by whoever runs Ginu.
Where Ginu is run, and where you are
Ginu is run from the United Kingdom and this notice follows UK data protection law. The hosted services described below store your data in London, except the website’s access log, which is stored in the United States (see the website row). If you are outside the UK, whatever you send to those services is sent to and stored in the UK.
Anyone can install Ginu. Wherever you live, you can contact the support address, and you can complain to the data protection authority in your country as well as to the ICO.
What stays on your computer
Ginu stores text transcripts, continuity notes, task records and diagnostic logs. Those logs can include turn-taking decisions, permission decisions and discarded utterances. Learned speaking rhythm, the owner voiceprint, acoustic measurements, cached speech and the memory vault are also local data. Voice-derived state is personal data.
The application data root is ~/.vori, unless you configure another location. Memory and project files live in its vault directory; transcripts use the configured transcript directory. Session startup sets the data root and transcript directory to owner-only mode (0700). This controls who can open the directories; it does not encrypt the files. Ginu does not encrypt them at rest. FileVault or another disk-encryption setting is a separate protection.
Raw utterance audio is not normally saved. The explicit --save-audio option saves it. The macOS microphone indicator may stay on while muted because the input stream remains open and muted frames are discarded in software.
Stop the session before cleanup. vori logs purge immediately deletes its listed transcripts, continuity notes, task records, snapshots and diagnostic logs. vori logs purge --all adds learned voice state and caches. Neither command asks for confirmation.
The memory vault, agent worktrees, saved preferences, standing permission grants and remote secrets survive both commands. Review memory separately, clean worktrees through git and revoke or rotate security controls deliberately. Deleting a log must not silently remove a permission boundary. See Files on your computer.
What reaches your AI provider
Ginu runs your AI agents through the command-line program you select as its main model. Claude Code is the default and the one Ginu recommends for the best experience, but it is not required: Codex CLI and Gemini CLI are supported alternatives, and a DeepSeek option runs through the Claude Code program pointed at DeepSeek’s endpoint with your own DeepSeek API key. Whichever you select, Ginu sends it your transcribed speech and the relevant context as text, and the CLI passes that to your AI provider under your own account with that provider and under that provider’s terms and privacy policy. Ginu’s operator has no server in that model-request path, does not receive or store that content merely because you use Ginu, and does not resell, repackage or proxy AI access: the model, the subscription and the relationship with your AI provider are yours.
The CLI can read files allowed by its configuration and permissions and may send their contents to its model. In the current Claude bridge, the working directory defaults to the launch directory and the default extra directory is your home directory. Configuring a project does not by itself remove that extra access. The other CLIs have their own permission rules. Review your selected CLI’s scope, and your AI provider’s data policy, before working with sensitive material.
Other connections
Model downloads. Speech and turn models are downloaded from Hugging Face during setup. That host receives your IP address and the model request. The request goes to the model host, not through Ginu’s operator.
Extension packs. Update checks for installed registry or git-hosted packs contact their configured host to check the revision. That host sees the request and its IP address. Ginu’s operator does not receive the request. Installing an update or an integration may make additional requests to the service you selected.
Your phone. Pairing exchanges connection information between your phone, your computer and the relay. Where possible, the session travels directly between your devices. TURN can forward encrypted DTLS-SRTP/SCTP traffic when the direct path is unavailable; the relay cannot read those encrypted contents. Your computer remains the machine doing the work.
A remote window has its own session identifier and credentials; another phone cannot simply join its occupied peer slot. The relay connection, and the app’s checks for a new version and for service notices, are activities with their own rows in the table below.
Hosted activities
These are the services that run today, one section each. For each one: what is collected, why and on what legal basis, who handles it, where it goes, how long it is kept, whether you have to provide it, and how to exercise your rights.
Visiting the Ginu website
- Purpose and basis: serving the web page you asked for and keeping the website reachable. Legitimate interests: a request that arrives has to be answered, and the log line is what shows an outage, an attack or a broken deploy.
- Data: Your IP address and basic connection details, the browser or program that made the request, the page you asked for and the page that linked to it.
- Recipients and processors: Amazon Web Services, as processor, which hosts the website and keeps its access log. The log is stored in the United States; the request itself is answered from whichever AWS location is nearest to you.
- Retention: Access-log entries are deleted automatically 30 days after they are written; AWS completes the deletion on its own schedule, so it may take slightly longer.
- Required: the request carries this information so that a web page can come back. You can decline to visit.
- Your rights: contact the support address. There is no account on the website, so a request needs something to search on — the date and the address you used are usually enough.
The app checking for updates and service notices
- Purpose and basis: telling an installed app whether a newer version exists, so it can offer one, and letting Ginu show a short message, such as a maintenance or outage notice, without releasing a new version. Legitimate interests: each check is a single static file, it needs no account, and it cannot be made without a request that carries an address.
- Data: the app asks for two file paths from the host that serves the Ginu website: the list of releases, once a day, and the service notice file, when it starts and then about every half hour. The notice file is usually empty. Each request carries your IP address, the port it came from, the client identification the app sends, the path it asked for and the name of the host it asked. It carries no app version, no operating system, no architecture, no query string, no cookie and no body, so what reaches Ginu is an ordinary request for a file, not a description of your installation.
- Recipients and processors: the host that serves the Ginu website, so Amazon Web Services, as processor, through the same CloudFront distribution that serves the website's pages.
- Transfers: the request goes to the same CloudFront distribution as a website page request, so the same location applies: its configuration and log bucket are in us-east-1, in the United States.
- Retention: the request is recorded in the same access log as a website page request and deleted on the same schedule, 30 days after it is written.
- Required: the update check runs by itself once a day, and the notice check about every half hour, while Ginu is running. You are not asked for anything to make either happen, and neither carries anything about your installation beyond the request itself.
- Your rights: contact the support address. There is no account to look up, so a date and an address are what a search needs.
Pairing your phone through the relay
- Purpose and basis: carrying the connection between your phone and your computer. Performance of the service you requested under the applicable agreement: the relay does this one thing and nothing else.
- Data: the pairing request, and the connection that follows it. The relay’s own log records the public IP address your phone connected from and the public IP address your computer connected from, together with the session identifier the connection is carried under. The conversation itself is not in that log.
- Recipients and processors: Amazon Web Services, as processor, runs the relay on a server in London. When a direct path cannot be found, TURN forwards the media; it forwards encrypted packets and cannot read them.
- Transfers: none — the relay runs in the United Kingdom, and so does everything it forwards.
- Retention: Details of a connection are held only in the relay’s memory while it runs. Nothing about a connection is written to the relay’s storage, and no record of one is kept once the relay stops.
- Required: the addresses are necessary for the relay to connect the two devices. Pairing is optional: Ginu runs on your computer without a phone.
- Your rights: end the connection from either device. Contact the support address about anything held for the relay connection.
Signing in
- Purpose and basis: letting you optionally link a Google, Apple or GitHub identity to Ginu, so a small number of features that need a way to reach you — an emailed reply about a report you sent, recovering your account from another device — have an address. Performance of the service you requested: you asked to sign in.
- Data: whichever identity provider you choose confirms your name, an email address if the provider shares one, and a picture if the provider has one. Ginu never receives or stores your password. If you add a verified email directly, only that address and its verification status are stored.
- Recipients and processors: Amazon Web Services, as processor — the account link, and any linked email, are stored in a table in eu-west-2 (London). Your identity provider (Google, Apple or GitHub) is itself a separate controller for the sign-in exchange, under its own terms.
- Transfers: none for Ginu's own store — it stays in the United Kingdom. Your identity provider's own handling of the sign-in request is outside Ginu's control.
- Retention: kept for as long as the account exists. Deleting your account removes the identity link, any linked email, and the sessions and reports tied to the account within a few days.
- Required: optional. Ginu runs fully signed out.
- Your rights: delete the account yourself from Settings, or contact the support address.
Sending feedback or a bug report
- Purpose and basis: letting you tell Ginu about a bug, ask for something, or leave feedback, optionally with a short excerpt of your own local session log attached so a bug can be reproduced. Performance of the service you requested: you chose to send it.
- Data: the title and text you write, which feedback type you chose, your app version and operating system for a bug report, and — only if you explicitly attach one — an excerpt of your own session log. You see and can edit or shorten that excerpt before it is sent; nothing is attached without that step. If you are signed in, the report is linked to your account so a reply can reach you; if you are not, it carries a one-way hashed device key that cannot be turned back into that key or into you.
- Recipients and processors: Amazon Web Services, as processor — the report's title, text and metadata are stored in a table in eu-west-2 (London); an attached log excerpt is stored separately, in the same region.
- Transfers: none — both stores are in the United Kingdom.
- Retention: the report itself is kept for up to 400 days. An attached log excerpt is deleted automatically after 30 days regardless of the report's own status.
- Required: optional in every respect — sending feedback at all, and attaching a log excerpt within it, are both your choice.
- Your rights: contact the support address to ask for a report, to have it corrected, or to have it deleted, subject to the exceptions that apply.
Anonymous usage statistics
- Purpose and basis: understanding whether Ginu is being used and roughly how, so Ginu can tell whether something it shipped works. Basis: Ginu’s interest in knowing whether what it ships works. The app discloses this in the same screen where you agree to these terms, with a switch that starts on; nothing is sent until you have accepted, and turning the switch off there means nothing is ever sent.
- Data: a random identifier generated on your machine when Ginu is first installed (not tied to an account, a name or an email address), your app version, your operating system family, and the start and end time of a session. No file content, transcript, command, model name, or CLI provider is included.
- Recipients and processors: Amazon Web Services, as processor — stored in eu-west-2 (London).
- Transfers: none — the store is in the United Kingdom.
- Retention: a day's tally of which installations were seen is kept 90 days; an individual session's start/end record is kept 90 days. A record of an install still running right now is kept 24 hours past its last check-in. Aggregated daily counts with no installation identifier in them are kept longer, to show trends.
- Required: no. It is on by default; turn it off in the switch on the first-run screen or at any time in Settings › Data, and it stops immediately. Off does not limit anything Ginu does. A choice to turn it off is kept, including when these terms change.
- Your rights: turn it off at any time from Settings › Data. Because the identifier is not linked to anything that names you, Ginu cannot look up or delete one person's history from it on request — turning it off going forward is the control that exists.
Emailing Ginu
- Purpose and basis: answering what you sent and keeping a short record of the answer. Legitimate interests: a reply needs the message, and a record that is destroyed on arrival cannot answer the follow-up.
- Data: your email address, what you wrote, anything you attach, and the history of the exchange.
- Recipients and processors: Cloudflare Email Routing, as processor: it receives the message and passes it on without keeping a mailbox of its own.
- Retention: Until the enquiry is answered and for 12 months after the final reply, then deleted.
- Required: writing to that address is optional and nothing else depends on it. Your address is needed if you want a reply; send only what explains the problem.
- Your rights: contact the support address to ask for the correspondence, to have it corrected or erased, or to object to it being kept, subject to the exceptions that apply.
Installing Ginu on a computer
- Purpose and basis: handing you the installer when you paste the install command, counting completed installs so a failed install can be told apart from an abandoned one, and limiting how many installers one network can request in an hour so the download cannot be used up. Performance of the service you requested for the download itself; legitimate interests for the count and the limit, which need no account and hold no name.
- Data: the command carries no code and you give no name or email. The install server sees the address your request came from, the kind of program that made it (curl or PowerShell) and the time. When the install finishes, the script sends one short note with your operating system, your processor family and the Ginu version installed; if that note cannot be sent, nothing changes and the install still completes. The server stores each finished install as one record: the operating system, processor family, Ginu version, the country CloudFront derives from your address, the kind of program, and the time. The record holds no name, email address or IP address. Your IP address is not stored: a one-way digest of it, salted per release, keys a counter that limits an address to 30 installer downloads an hour.
- Recipients and processors: Amazon Web Services, as processor: a DynamoDB table in eu-west-2 (London) stores the install records and the counter, and the installer is delivered from S3 and CloudFront, which log the request as the Ginu website's pages are logged.
- Transfers: none for the table, which stays in the United Kingdom. The installer is delivered by CloudFront, whose configuration and log bucket are in us-east-1, in the United States.
- Retention: the counter expires when the hour it counts ends, and the database then deletes it automatically, usually within a few days. The CloudFront log line is deleted 30 days after it is written. Install records have no automatic expiry.
- Required: optional. You can install from another place where one is offered, and Ginu runs the same either way.
- Your rights: contact the support address. An install record holds nothing that names you, so Ginu cannot pick out one person’s record on request; not running the install command is the control that exists.
Installing the iPhone app through TestFlight
- Purpose and basis: letting you install the iPhone app without an invite, through the public TestFlight link on the download page. Performance of the service you requested under the applicable agreement: you asked to install the app.
- Data: TestFlight is Apple’s service. Apple handles your Apple account, the install and any feedback or crash report you send from TestFlight, under Apple’s terms and privacy policy, and Apple is a separate controller for that. A public link does not give Ginu a list of who joined. Ginu sees what Apple shows its developers, which is counts of installs, sessions and crashes for each build, and any feedback or crash report you choose to send through TestFlight.
- Recipients and processors: Apple. Ginu does not pass anything to Apple to make the install work; the link and QR code on the download page are static.
- Transfers: Apple’s handling of your data is outside Ginu’s control and is described in Apple’s own privacy policy.
- Retention: Ginu keeps no separate record of who installed through TestFlight. Anything Apple holds is kept under Apple’s terms.
- Required: optional. The iPhone app is one way to use Ginu on your phone; the browser connection works without it.
- Your rights: for what Apple holds, use Apple’s privacy tools. For anything you sent to Ginu through TestFlight feedback, contact the support address.
Sending a contact message
- Purpose and basis: answering a message sent through the contact form. Performance of the service you requested under the applicable agreement: a reply needs the message.
- Data: your email address, your name and your message. The request also carries the address it was sent from, kept only to enforce a request limit.
- Recipients and processors: Amazon Web Services, as processor: a DynamoDB table in eu-west-2 (London) stores the row.
- Transfers: none — the table is in the United Kingdom.
- Retention: a contact message expires 180 days after it arrives and is then deleted automatically, usually within a few days. The rate-limit counter, keyed to the address the request came from, expires five minutes after the window it limits ends, and the database then deletes it automatically, usually within a few days.
- Required: using the form is optional. Your email address is needed so a reply can reach you.
- Your rights: contact the support address to ask for the message, to have it corrected, or to have it deleted, subject to the exceptions that apply.
The earlier beta waiting list
- Purpose and basis: the waiting list was kept so invitations could be sent while Ginu was invite-only. Performance of the service you requested under the applicable agreement. That purpose has ended, because anyone can now install Ginu without an invitation.
- Data: for each person who joined the list: their email address, the desktop and mobile platforms they chose, the version of the beta email consent they agreed to, and a one-way digest of their email address that keyed a request limit.
- Recipients and processors: Amazon Web Services, as processor: a DynamoDB table in eu-west-2 (London).
- Transfers: none — the table is in the United Kingdom.
- Retention: Ginu sends each person on the list one message saying the beta is open and where to download it, then deletes the list within 30 days of this notice taking effect. The website no longer takes new entries.
- Required: the form that collected these entries is no longer on the website.
- Your rights: contact the support address to ask for your entry, to have it corrected, or to have it deleted now, subject to the exceptions that apply.
What does not exist yet
The desktop app supports optional sign-in, a switchable usage-statistics report, and an opt-in feedback and bug-report path, each described in its own row above. The website sets no cookies and runs no analytics, and the app does neither (see Cookies and analytics).
Anything else that would collect data is not built. When one of them is built, this notice changes before that collection begins, and the version below changes with it: the new activity appears as its own row, with the fields it sends, the purpose, the basis, the recipients, the retention and the control that turns it off. Nothing here is a claim about a service that does not exist yet.
Children
Ginu is a tool for developers and is offered to people aged 18 or over; the terms say so. It is not designed for, aimed at or likely to be used by children, and Ginu does not knowingly hold a child’s personal data. If you believe a child has signed in or sent feedback, contact the support address and the record will be removed.
Your rights
Where Ginu processes your personal data, applicable rights include:
- Access: ask for a copy of personal data held about you.
- Rectification: ask for inaccurate personal data to be corrected.
- Erasure: ask for personal data to be deleted where the right applies.
- Restriction: ask for processing to be limited in the circumstances the law provides.
- Objection: object to processing based on legitimate interests.
- Portability: ask for eligible data in a reusable form where the right applies.
Contact the support email with enough information to identify the relevant activity. Rights have conditions and exceptions; the response should explain any that apply. Local app files are under your control, rather than held by Ginu: inspect them on your computer and use the cleanup commands above for their stated scope.
Complaints. If you think Ginu has handled your personal data wrongly, say so at the support email, with “privacy complaint” in the subject line. You will get an acknowledgement within 30 days, Ginu will look into it and tell you the outcome without undue delay.
You can also complain to the Information Commission’s Office (the ICO), or, if you are in the EU or EEA, to the data protection authority in the country where you live.
Cookies and analytics
The website. The Ginu website sets no cookies and runs no analytics. It serves its fonts, images and scripts from its own origin. There is no cookie consent banner because the website does not use optional cookies or tracking that require a choice. The tutorial saves the lessons you choose to mark complete in session storage in your browser tab. This is not sent to Ginu and disappears when the tab’s session ends. Form fields are not saved in browser storage.
The app. The Ginu app sets no cookies and contains no advertising or third-party analytics trackers. The only measurement it can send is the anonymous usage statistics described above, and that is on by default: the switch on the first-run screen starts on, nothing is sent before you accept, and nothing is sent once you turn it off. You can change the choice at any time in Settings › Data.
If analytics is added to the website or the app, this notice and any required consent control change in the same release, before that collection begins.
Changes
This notice is version 2. Its effective date is shown with the version.
Every version is kept. The number identifies what you are reading, the change line in the version history says what moved in one sentence, and an earlier version stays at its own address and is not edited afterwards. Version 1 is at /privacy/v1.
Version history
- Version 2 · 2026-10-10 · Current
Ginu is open to everyone now, so the invite-install and waiting-list wording is gone. The notice says who runs Ginu and where, how the public install and the iPhone TestFlight link handle your data, and what applies if you are in the EU. - Version 1 · 2026-10-03 · Superseded by version 2
First effective version of the privacy notice, in force from 2026-10-03. Describes the model-request path generically as going to your AI provider through whichever CLI you select, and says Ginu does not resell or proxy AI access, states what the app itself does about cookies and analytics, and sets out each hosted activity in plain terms.