OpenAlly from your assistant
What a connected assistant can do
Once connected, the assistant acts on your OpenAlly account and nothing else. It can, in plain words:
- Account. Summarise your account, tell you whether setup is finished, report your plan state in facts, and list every assistant connected to the account.
- Devices. Tell you which devices are signed in and whether a notification can reach each one.
- Reach your phone. Send you a short notification, send a notification that opens one screen of the app when tapped, or send a link to your phone.
- Notes. List, search, create, edit and delete your OpenAlly notes. A note made by an assistant appears in Notes on every signed-in device and is marked as added by that assistant.
- Support. Open a support ticket, check its status, reply on it, close it, or file a feature request, as you.
- With an OpenAlly plan. Ask the agent running on your device to do something, and read today's business counts (orders, bookings, open orders, low stock). Each of these is shown to you on the device and runs only after you approve it there. Without a plan the assistant says so in one sentence, with no link and no price; plans are managed in the OpenAlly app.
It cannot read your OpenAlly conversations, your Health vault, your credentials, or anything on the device it did not ask for and you did not approve. It answers questions about the app from the same guide the app ships.
How sign-in works
Sign-in starts in the chat and finishes on your phone. You give the assistant the email of your OpenAlly account. It sends a sign-in request to the phones signed in to that account and shows you a six-character code. On the phone, OpenAlly opens a full-screen request that names the assistant, says what it will be able to access, and shows three codes. You tap the one the assistant showed you, then Allow. Back in the chat you choose Connect and enter the same code.
The three codes are what stop a sign-in you did not start: someone who only knows your email cannot pick the right one. A wrong tile declines the request. A request expires after fifteen minutes. The assistant never learns which device approved until you have approved, and it never learns whether an email has an account at all.
If you have no phone to hand, the Connect page also accepts a code sent to your email, the same way the app signs you in. Creating an account there is the same as creating one in the app.
Only allow a sign-in you started. If a request appears on your phone that you do not recognise, tap Deny.
What you approve
The sign-in screen lists what the assistant will be able to access before you approve anything, in words like these:
- See when your OpenAlly account was created, whether setup is complete and your plan state, and which other assistants are connected to it, what each can access and when each was connected and last used.
- See which devices are signed in to your OpenAlly account.
- Send notifications to your OpenAlly devices, open screens in the app, and send a web link that opens when you tap it.
- Ask the agent on your device to do things. You approve each one on the device.
- Read and search your OpenAlly notes.
- Create, edit and delete your OpenAlly notes.
- Open and reply to support tickets and file feature requests as you.
- Read today's counts from your OpenAlly Business. Nothing about your customers.
Reading your account, devices, notes and tickets happens without a further tap, because you approved it at sign-in and the assistant confirms each write with you in the chat. Anything that runs on your device is different: the device shows you what the assistant asked for, and nothing runs until you tap Run there. Dismissing the request sends nothing and it expires on its own.
There is one exception, and it exists only on accounts we run ourselves. A connection can be marked in our database to run device actions without the prompt, so that a platform reviewer who does not have our test phone in hand can watch an action finish. The device still checks the request and still tells you what ran. Nothing in the app and nothing an assistant can send sets that mark, and we do not set it on an account that is not ours.
Where it works
OpenAlly runs on Android, iPhone and Mac, and the assistant looks up which devices your account has before it tries anything. A few things differ by platform, and the assistant is told to say so rather than guess.
| Capability | Android | iPhone | Mac |
|---|---|---|---|
| Notifications, opening a screen, sending a link | Works | Works | No: the Mac app has no notification runtime, so these go to your phones |
| Notes: read, search, create, edit, delete | Works; the note appears in Notes on the next sync | Works; the note appears in Notes on the next sync | Works; the note appears in Notes on the next sync |
| Ask the agent on the device (plan) | Runs after you approve it on the phone | Runs after you approve it, the next time you open OpenAlly | No: it needs a phone to approve it on |
| Today's business counts (plan) | Read after you approve it on the phone | Read after you approve it, the next time you open OpenAlly | No: it needs a phone to approve it on |
| Opening an Android-only screen | Works | Refused with written steps instead; nothing is sent | Refused with written steps instead; nothing is sent |
Android-only is a property of a few screens, chiefly the separate Aster companion and the features that need it, never of OpenAlly as a whole. When a screen cannot open on your device, the assistant gives you the written path instead.
Disconnecting
In the OpenAlly app, open Profile, then Security. Under Connected apps every assistant with access to your account is listed with what it may access, when it was connected and when it was last used. Disconnect removes its access within seconds, and its next request is refused. An action it had already sent to your device is expired in the same moment, so nothing it asked for is left waiting on the device for you to notice. You can also remove OpenAlly from the assistant's own settings, but the app is the control that does not depend on the assistant.
The assistant can tell you what has access to your account, and cannot take it away. That asymmetry is deliberate.
What we keep
The record of a connection is kept until you disconnect it or delete your account. Records of actions an assistant asked your device to run, including the request and the result, are kept for thirty days. Sign-in requests expire after fifteen minutes and their records are kept for about a week. Notes made through an assistant are your notes, kept until you delete them. Nothing an assistant sends or receives is used to train anything, and the assistant's operator never receives your OpenAlly conversations from us. The full statement is in the privacy policy, and the conditions of use are in the terms.
Questions and problems
Email [email protected] with "assistant" in the subject line, or open a ticket from the assistant itself. For a security problem, see the security page.