Privacy Policy
On this page
- Overview
- What we collect
- Usage analytics
- Push notifications
- Account & sign-in
- AI providers
- Connected accounts
- Assistant connectors
- Optional on-device downloads
- Web search & browsing
- Community features
- Messaging channels
- WhatsApp Business
- Encrypted backup
- Health
- Device permissions
- On-device processing
- Payments & billing
- Third parties
- How we protect your data
- Data retention & deletion
- Your choices & rights
- US state privacy rights
- EEA / UK rights
- India (DPDP Act 2023)
- Grievance redressal
- International transfers
- Children
- This website
- Google Play Data Safety
- Changes to this policy
- Contact
Overview
OpenAlly™ is a mobile-first AI platform for Android, iPhone, and Mac. Its conversations and most working data are kept on the device you are using. When you choose an external AI service, messaging service, search service, or other integration, that service receives the information needed for the action you requested. If you choose OpenAlly cloud AI, the OpenAlly service processes the information needed for that AI request. When you connect WhatsApp Business, a dedicated OpenAlly service also processes the connection and temporary message delivery described below.
Almost everything you do in OpenAlly stays on your device, including Health records, medicines, and authorized health-store copies, which live in an encrypted vault on the device. A few things do leave it: your account, crash diagnostics, usage analytics on Android (never Health screens), a push-notification subscription, the notes you write in the Notes app, and whatever you send to the model provider, channels, or tools you connect. A request also reaches the OpenAlly service when OpenAlly cloud AI is the model you select. WhatsApp Business uses a dedicated delivery service even though its agent runs on your designated device. Health facts reach a cloud model only if you turn that on. This page walks through each one, plainly, so there are no surprises.
Which platforms this covers. This policy covers the Android, iOS, and macOS/desktop builds of OpenAlly. One difference matters for privacy and we call it out where it applies: the usage analytics described below ship only in the Android build. The iOS build sends no usage analytics, and neither does the desktop app.
Who's responsible. This app and this policy are operated by Matterward Labs, the data controller for your personal information. You can reach us anytime at [email protected].
What We Collect
The app-service data flows. These are the recurring signals the app sends to us or processors we use. Requests you direct to a chosen model, messaging service, search provider, or other integration are covered separately below:
- crash diagnostics;
- usage analytics on Android, limited to categorical information, covered in the next section;
- a push-notification subscription for your install (OneSignal), covered below; and
- your account record (email, display name, plan) and the settings that follow you to a new device, covered below;
- the relevant model request, only if you select OpenAlly cloud AI.
- the notes you write in the Notes app: the title, the text, the tags and whether you pinned it, stored in your account so the same notes appear on your other devices. Covered below.
Each is described in the sections below. OpenAlly stores your conversations, business records, Health vault, and local feature data such as SMS Analyser, Voice Notes, automations, and connections on your device. When you use your own AI or integration account, the service you choose receives the information needed for that request; we do not receive or store it. OpenAlly cloud AI is a separate option processed by the OpenAlly service. Health is described in its own section because Play and privacy law treat it as sensitive, even when it never reaches us.
Crash reports. When the app crashes, OpenAlly sends a diagnostic report to Google so we can find and fix the problem. A report includes your device model, OS version, app version, a random installation identifier, and technical details about the error. It does not include your conversations or message content, and we don't use it to identify you personally, but a random installation ID and crash data are still considered personal data under some laws, so we count it here. This data is processed by Google as our processor; crash reporting is enabled as part of using the app under our Terms, and you can turn off Google-level crash and usage sharing in your device settings. You can read more in Google's privacy policy.
Usage Analytics (Android)
We do measure how the app is used on Android. The Android build of OpenAlly includes Google's usage analytics. We use it to see which features people use and where they encounter problems. The iOS and desktop builds do not send usage analytics.
What we measure. The fixed categories are:
- screens and features you open;
- broad actions such as starting a conversation, sending a request, changing an agent or AI service, or connecting an integration;
- whether a request included an attachment, without the attachment itself;
- setup milestones and changes to permissions you control; and
- general app-readiness and error status.
What this information never carries. We limit analytics to fixed categories rather than names or text you provide. It never carries message content, prompts, model responses, chat or session titles, contact names, phone numbers, SMS, file contents, URLs, API keys, Health readings, medicine names, or anything else you typed or received. Use of Health screens, Health features, and Health permissions is not recorded at all.
Who this information is attached to. Google gives your installation a random identifier. If you are signed in, we also link the analytics to your OpenAlly account identifier, the same account identifier behind your profile, so activity across your devices lines up. Said plainly: while you are signed in, your analytics identifier is your account identifier, and this analytics data is not anonymous. Signed out, it is tied only to the random installation identifier. We also record broad account, setup, app-readiness, and preference categories. These do not contain text you supplied.
Turning it off. Analytics collection is enabled in the Android release build. You can turn it off in the app under Settings → Privacy & data. That takes effect immediately. You can also email [email protected] and we will disable analytics collection for your account and erase the analytics data already held against it. Uninstalling the app also ends collection. Where the law requires your consent before we may store an identifier on your device or process this data at all, we will not treat you as having given it merely because you kept using the app.
Push Notifications
OpenAlly uses OneSignal to deliver push notifications, for example, when a feature request you submitted changes status. OneSignal acts as our processor for this, and pushes are delivered through Google's and Apple's push services.
What OneSignal holds. The installation and device-delivery identifiers needed to address a notification, plus basic device and app information (device model, operating-system and app versions, language, and timezone) used to route and time it. It holds none of your conversations or message content.
Your account identifier is linked while signed in. When you sign in, OpenAlly links the notification subscription to your OpenAlly account identifier, so a notification meant for you reaches your devices and not someone else's. When you sign out, we unbind it. As with analytics: while signed in, the push identifier is linked to your account rather than being anonymous.
Your control. The push subscription is registered at first launch, but nothing is delivered until you grant the notification permission, and you can revoke it at any time in your device's system settings, which stops delivery. To have the subscription record itself deleted, email [email protected], or delete your account, which unbinds and removes it. OneSignal's own handling is described in its privacy policy.
Account & Sign-in
You need an OpenAlly account to use the app, and signing in is part of setup. You can sign in with a one-time code sent to your email, with WhatsApp, with a passkey you added in Settings, or with Google, Apple (on iOS), Facebook, GitHub, Discord, LinkedIn, X, or Spotify. The information that keeps you signed in is protected by your device's credential safeguards.
Our servers keep your account record: your email, display name, and subscription plan. They also keep the settings that follow you when you sign in on another device: your assistant's name, look, and tone, your language and country, the AI model you chose and how each AI provider is set up, and your workspace names and display preferences. API keys, sign-in tokens, and other credentials are never part of this; a new device asks for them again. Your conversations, messages, and business records are not stored in your account. The notes you write in the Notes app are, as described above.
If you sign in with WhatsApp, you send a sign-in message from your own WhatsApp to OpenAlly Miro, our WhatsApp agent. That links your WhatsApp number to your account so the same number can sign you in again, and the message travels through Meta like any WhatsApp message.
Signing in also authorizes optional downloads for on-device AI and voice features. The SMS, audio, and other content on your device is never uploaded when you request one. You can delete your account and server-side profile in the app, or via our data deletion request page. Deleting your account also removes its synced settings and the WhatsApp number linked to it.
AI Providers You Choose
You choose where each AI request is handled. You can keep it on your device, use an AI service with your own provider key or existing subscription, use a service you host yourself, or select OpenAlly cloud AI. For an external service you connect, that service receives the prompt, conversation context, and images you chose for the request under its own privacy terms; OpenAlly does not receive or store that request. If a Health question is involved, see the Health section: Health facts are not sent unless you turn on remote-model access.
OpenAlly cloud AI. When you select it, the OpenAlly service and its disclosed AI-processing provider receive the content you chose for the request. We keep service usage totals and information needed to keep the service reliable and prevent abuse, but not the prompt or response text. The recipient and purpose are also listed in the table below.
What our AI-processing provider commits to. OpenAlly cloud AI runs on Cloudflare Workers AI. Cloudflare states, on its Workers AI data-usage page:
“You own, and are responsible for, all of your Customer Content.”
“Cloudflare does not make your Customer Content available to any other Cloudflare customer.”
“Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services, and would not do so unless we received your explicit consent.”
“Your Customer Content for Workers AI may be stored by Cloudflare if you specifically use a storage service (e.g., R2, KV, DO, Vectorize, etc.) in conjunction with Workers AI.”
These are Cloudflare’s words about its own service, quoted so you can hold them to it, and they are not a promise we make on their behalf. They say nothing about the AI services you connect yourself, which are governed by their own terms.
Connecting your own service. The app identifies the service before you connect it. You may enter a provider key, sign in to a supported subscription on that provider's page, or supply an address you control. The information that authorizes future requests is protected by your device's credential safeguards and is not uploaded to us.
Connected Accounts
Separately from the AI providers above, you can connect an account you already own on another service so the assistant can act on it for you, an Instagram professional account, for example. A model provider receives your prompts, whereas a connected account is something the assistant acts on, using access you granted.
What connecting does. You sign in on that platform's own page, never inside OpenAlly, and never by typing that account's password into our app, and choose which permissions to grant. The resulting connection credential is protected by your device's credential safeguards. It is not retained by us, included in backups, or synced between your devices.
When our service is involved. Some platforms require an OpenAlly service to complete the account connection. The temporary sign-in information used for that step is not retained. If you publish a post with an image, we may also hold the image briefly so the platform can retrieve it. It is not listed or browsable and is deleted after publishing, and in every case within one day.
What the assistant may do with a connected account, and what it may never do. It can act only on the account you connected. Anything published goes out because you approved that specific thing, or because you armed a rule that says exactly what to reply and to whom, and a rule can be disarmed at any time. When someone comments on your post or messages your account, the assistant can reply to that person about that interaction. It cannot start a conversation with someone who did not contact you first, cannot message your followers, cannot browse or export your audience, and cannot post because a comment or a message told it to.
Your account's own numbers. If you grant that permission, the assistant can also read the connected account's own audience metrics (reach, follower counts, and how individual posts performed) to show them to you in the app and to answer questions about them. These are the aggregate figures the platform already shows you about your own account, not information about the individual people behind them. They are read when you open that screen, they stay on your device, and they are not sent to us. Granting this is optional: decline it and everything else still works, minus those screens.
Other people's data. Answering a comment or a message means handling something a third party wrote. That content is handled on your device to produce a reply. If you use an external or cloud AI service for that reply, the relevant content is also sent to that service under the choices described above; if you use local AI, it stays on the device. We do not store it on our servers, and we do not use it to train anything.
Disconnecting. Disconnecting removes the connection credential from your device and asks the platform to revoke OpenAlly's access. You can also revoke access from the platform's own settings at any time, without opening our app. That is the control that does not depend on us. Content already published stays published; it belongs to your account, and removing it is done where it lives.
The connected accounts available to you may vary by platform and app version. These privacy rules apply to each one.
Assistant Connectors
You can connect an assistant you already use to your OpenAlly account, so that it can act on your account from its own chat. ChatGPT is the assistant this works with today; each assistant's operator is named in the third-parties table below, and receives nothing until you connect that assistant. This is the mirror image of a connected account above: there, OpenAlly acts on a service you own; here, another service acts on OpenAlly, with access you granted. How it works and what it can do is described on the assistant connectors page.
What the assistant's operator receives. When the assistant makes a request on your behalf, our service receives the arguments of that request and returns a reply; the assistant's operator, named for each assistant in the third-parties table, receives that reply because it runs the assistant you are talking to. That is all it receives from us. It never receives your OpenAlly conversations, your credentials, your account email, or anything on your device the assistant did not ask for and you did not approve. What the operator does with its own chat is governed by its own privacy policy, not this one.
What we receive and store. A record of each connection: which assistant, what it may access, when it was connected and when it was last used. If you choose to approve a sign-in in the OpenAlly app rather than with an email code or password, a record of that request: the code the sign-in page showed you, the two decoys shown beside it on your phone, and which of your devices approved it. Signing in with an email code or password creates no such record, and the address you type there is used to find the account, not stored with the request. A record of each action an assistant asked your device to run, including the request and the result the device returned. That record is kept for 30 days from the moment the action was created and is then deleted, whether the action ran, was declined, or expired unanswered. Notes an assistant creates or edits are stored in your account like any other note, marked with the assistant's name. We do not receive the assistant's conversation, and we do not use anything an assistant sends or receives to train anything.
What you approve. Signing in happens in one place: the OpenAlly sign-in page the assistant sends you to. You can use a code we email to the account address, your existing account password, or approval in the OpenAlly app. Ordinary account passwords are sent to our authentication provider, Supabase. Dedicated store-review passwords for our sample account are verified by OpenAlly, which stores only their hashes. Neither kind is sent to the assistant. In every case the request names the assistant and lists what it will be able to access before you approve it. The assistant never signs you in inside its own chat, and it cannot produce a sign-in link of its own. Reading your account, devices, notes and tickets, and writing notes and tickets, then happens on your instruction in the chat. Anything that runs on your device, a prompt to the agent or a read of your business counts, runs automatically within the access you grant when connecting. Its outcome is recorded and you receive a notification. Some of these actions need an OpenAlly plan; without one the assistant says so and sells nothing.
Device action records. We record the requesting connection, the device session that claims the action, its status, timestamps and result. These records are kept for thirty days. A request can be claimed by only one signed-in device. The connection's access, account status and any required plan are checked before execution. OpenAlly must be available on the device; a queued request may expire without running.
Your control. In the app, under Profile, Security, every connected assistant is listed and can be disconnected. Disconnecting takes effect within seconds: the assistant's next request is refused, and any action it had already sent to your device is expired in the same moment, so a queued request cannot start after disconnecting. An action already running may have performed work before revocation; disconnecting does not undo it. You can also remove OpenAlly from the assistant's own settings. Deleting your account removes every connection and every record above.
Optional On-Device Downloads
Some on-device AI and voice features need an optional download from OpenAlly. You choose whether to request it, and a signed-in account is required to authorize the download. Only the requested supporting files are delivered. None of your prompts, audio, SMS, or other content is uploaded during this process.
Web Search & Browsing
When you ask OpenAlly to search the web or open a page, your query is sent to the search provider you've configured (DuckDuckGo by default, or Brave, Google Custom Search, or SerpAPI if you enable and set them up), and each visited site receives the requested address and ordinary connection information. These requests are subject to those providers' and sites' own policies. OpenAlly does not receive or store them.
Community Features
If you use the in-app Feature Requests or What's New screens, your votes and any feature-request text you submit are stored on our servers. Please don't include personal or sensitive information there, since other users may see what you post.
Messaging Channels
A messaging service you connect, such as WhatsApp, Telegram, Discord, Slack, Signal, LINE, Google Chat, iMessage, Mattermost, Nextcloud Talk, Twitch, or Zalo, receives the messages sent and received through that account under its own privacy policy. Direct device connections handle messages on your device. WhatsApp Business uses the dedicated OpenAlly delivery service described next. If you ask an external or cloud AI service to help with a reply, the relevant message content is also sent to that AI service under the choices described above.
Credentials for direct device connections are protected by your device's credential safeguards. WhatsApp Business authorization grants are instead encrypted in the dedicated OpenAlly service so it can operate the connection.
WhatsApp Business
If you connect WhatsApp Business, Meta and a dedicated OpenAlly service process your business correspondence. We keep encrypted Meta authorization grants and verified business, phone-number, workspace and designated-device mappings. Messages, attachments, customer numbers, selections and submitted forms pass through this service to operate the inbox you connected.
Temporary queued correspondence is encrypted and deleted after your device confirms durable receipt, or after seven days, whichever comes first. Pending outbound content is also encrypted and expires within seven days. Delivery identifiers, timestamps, consent, approval and cost-policy records support reliable delivery and prevent duplicate sends. Tokens and message bodies are excluded from our logs and usage analytics. Removal from the active service is not immediate removal from our hosting provider's database recovery history, which can cover the previous 30 days.
Your designated OpenAlly device keeps inbox history, notes, business records and agent activity. The agent runs on that device; the AI provider you select receives the context needed to generate its reply. If you enable eligible Business App coexistence, only history Meta makes available with your consent is imported. Importing history does not send fresh AI replies.
We process this correspondence to support the connected business's customer conversations and the actions its owner authorizes. The business is responsible for its customer notices, permissions and handling of customer requests. We do not use correspondence from this service for advertising or training a general AI model. Your selected AI provider's separate data terms still apply.
Disconnect a number from WhatsApp Business in OpenAlly to stop its connection. This does not delete your Meta business account, unrelated numbers, device history, or copies held by Meta or customers. To request deletion of service records, use Request Data Deletion and identify the affected business number. A customer can also contact the business directly about copies in its inbox. Delete device history and backups separately.
Encrypted Backup (Optional)
If you enable backup, your data is encrypted on your device before it is uploaded to the private OpenAlly area of your own Google Drive account. OpenAlly does not request access to the rest of your Drive. Your recovery code is created on your device, shown only to you, and never sent to us; without it, a backup cannot be opened, including by us.
Backups are not deleted when you uninstall the app. If you want them gone, remove them from your Google Drive yourself.
Health is not in the backup. Health Connect and Apple Health copies, and the Health vault itself, are excluded from backups. Turning backup on does not upload your Health records.
Health
OpenAlly includes an optional Health app: a local records-and-medicines store, not a clinical product. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Use it to organise facts you already have. For medical advice, diagnosis, or treatment, consult a qualified clinician. OpenAlly is an AI agent platform; Health exists so your assistant can answer from records you keep on this device, not so we can run a health service in the cloud.
What Health accesses, and only with your say-so. On Android, Health can read from Health Connect the categories you allow:
- steps;
- heart rate;
- sleep;
- weight;
- distance;
- active calories burned;
- exercise / workouts.
Those permissions are read-only. OpenAlly never writes to Health Connect. You can skip Health Connect entirely and enter measurements and medicines yourself. On iOS, the same read-only pattern uses Apple Health after you grant it. You can also import a prescription or lab report you choose: camera or files, for on-device review before it enters the vault.
Where it is stored. Accepted Health records live in an encrypted vault on your device, not on our servers. We do not sell Health data, use it for advertising, credit, insurance, employment, or unrelated profiling, or train our own models on it. Uninstalling the app deletes the local vault. It does not delete the originals in Health Connect or Apple Health. In the app, Health → Privacy lets you disconnect a source and delete the OpenAlly copy.
When it can leave the device. By default it does not. Your assistant can read granted Health categories on the device. A cloud model sees Health facts only if you turn on Remote model under Health → Privacy and then ask a Health question. That send is purpose-bound to the turn you approved. OpenAlly still does not receive a copy. The provider you chose processes that projection under its own terms; we cannot promise they will delete it. Turn Remote model off to revoke future sends. Health notifications on the lock screen are generic. They never include a medicine name, dose, or reading.
What we never do with Health data. No advertising, data brokerage, insurance or employment eligibility, public sharing, or Health Connect access in a child-directed product. Crash reports and usage analytics are not allowed to carry Health values; Health screens and Health skill grants are excluded from analytics entirely.
Device Permissions
OpenAlly requests device permissions only when needed for features you choose to use:
Camera: AI camera tool, photo capture for vision tasks, and photographing a prescription or lab report you import into Health.
Microphone: Voice input and text-to-speech playback.
Location: Location-aware AI queries when you ask for local information. Not used to collect Health data.
Notifications: Push notifications you allowed, the Flare notification automation app, AI notification tools, and generic Health reminder alerts that never include a medicine name or reading.
Storage: File access for AI tools, Health document import, and the optional encrypted backup.
Health Connect (Android): Read-only access to the Health categories you allow: steps, heart rate, sleep, weight, distance, active calories, and exercise. OpenAlly never writes back, and never reads medications or medical records.
SMS and contacts. SMS reading and contacts access are handled by the separate Aster companion app (the accessibility companion), not the core OpenAlly app. The core app does not request SMS permission. When you use the SMS Analyser or AI SMS tools, the Aster companion reads your messages on-device so they can be analysed locally; they are never uploaded.
The accessibility and screen-control capability used for App Automations is Android-only and owner-gated: it works only after you explicitly enable screen control in the separate Aster companion.
On-Device Processing
You can keep the following work on your device, without sending its content to us or an external service:
- AI tasks you choose to run locally;
- voice-note transcription;
- SMS safety analysis through the separate Aster companion;
- search across knowledge you keep in OpenAlly;
- image preparation, including resizing, conversion, and removal of hidden photo details;
- spoken playback using your device's built-in voices; and
- Health record organisation, read-only Health Connect / Apple Health imports, medicine reminders, and document imports.
Your conversations, SMS Analyser data, Voice Notes, automations, connections, and Health vault are kept on your device. The Notes app is the exception and is deliberately different: it is the one feature built to follow you across devices, so a signed-in account keeps a copy of those notes.
Payments & Billing
We never see your card. Payment is taken by a payment processor, not by OpenAlly. On Android that is Google Play Billing; outside an app store, mainly in India, it is Razorpay. Your card number, UPI ID and banking credentials go to them under their own privacy policies and never reach us.
What they tell us. Google Play sends a purchase token for the transaction, the product bought, an order identifier and the storefront country. Razorpay sends the subscription or payment-link identifier, the amount, the currency and whether the payment succeeded. We store the purchase token only as a one-way fingerprint, never the token itself.
What we keep. The plan you are on and the dates of the period you paid for, the amount and currency charged, the billing country, your numbered receipts, and usage totals for the AI included with your plan so that your allowance and credits can be counted. The billing country tells us which price list applied to your purchase and is kept as part of the payment record; we do not use it to calculate tax.
We do not charge tax and we issue payment receipts, not tax invoices. Where a purchase goes through Google Play or the App Store, that store is the seller of record and handles any tax itself. A receipt from us records what you paid and is not a tax document.
Cancelling and deleting are different things. Deleting your OpenAlly account does not cancel a subscription. Cancel a Google Play or App Store subscription in that store, and a Razorpay subscription from the plan screen in OpenAlly (or email us and we will cancel it for you). See Request Data Deletion for how, and Refunds and Cancellations for what a cancellation returns.
Third Parties We Share Data With
OpenAlly keeps your conversations and working data on your device. When you use an AI provider or connected service, that service receives the information needed for the request. Direct device connections do not send those requests to us; WhatsApp Business uses our dedicated service as described above. If you choose OpenAlly cloud AI, the OpenAlly service processes the relevant AI request. The recipients below are the parties that receive data for the purposes shown. Local conversations, SMS, and audio are not uploaded unless you choose to include them in an AI or integration request. The "category" column uses Google Play's collect / share wording so this page lines up with our Data Safety disclosures.
| Recipient | What is shared | Purpose | When | Category |
|---|---|---|---|---|
| Google (crash reports) | Device model, operating-system and app versions, a random installation identifier, and technical error details (no conversation content) | Diagnose crashes and fix stability issues | When the app crashes | Collected |
| Google (usage analytics, Android build only) | Categorical usage information such as screens and features used, broad integration and AI-service categories, setup and app status, a random installation identifier, and (while you are signed in) your OpenAlly account identifier. No message content or use of Health features. | Understand which features are used and where the app breaks | While you use the Android app (iOS and desktop send no usage analytics) | Collected |
| OneSignal (push delivery) | The installation and device-delivery identifiers needed to address a notification, basic device and app information, and (while you are signed in) your OpenAlly account identifier. No message content. | Deliver push notifications you allowed (e.g. feature-request status updates) | From first launch; notifications are only delivered if you grant the OS permission | Collected |
| Our servers (account) | Account email, display name, plan, the settings that follow you to a new device (never API keys or other credentials), and your WhatsApp number if you sign in with WhatsApp. No conversations or business records. | Your account and sign-in | From sign-in, which the app requires | Collected |
| OpenAI (ChatGPT, only if you connect it) | The requests the assistant makes on your behalf and the replies our service returns: the arguments of each request (for example the text of a note, or a message for your phone) and the result (for example your device list, a note, or the text the agent on your device returned). OpenAI operates the assistant you are talking to, so it receives the reply; it never receives your OpenAlly conversations, credentials or account email from us. | Let an assistant you connected act on your OpenAlly account, at your request | Only after you connect ChatGPT to your account, and only for the requests you make there | Shared at your request |
| Anthropic (Claude, only if you connect it) | The same as for ChatGPT: the arguments of each request the assistant makes on your behalf and the reply our service returns. Anthropic operates the assistant, so it receives the reply; it never receives your OpenAlly conversations, credentials or account email from us. | Let an assistant you connected act on your OpenAlly account, at your request | Only after you connect Claude to your account, and only for the requests you make there | Shared at your request |
| Google Play Billing (Android purchases) | Google issues a purchase token for the transaction and tells us the product, the order identifier and the storefront country. Google, not us, handles the payment itself, so your card or payment-method details never reach OpenAlly. | Take payment for a plan or credit pack, and keep your access in step with it | Only when you buy or renew a plan or credit pack on Android | Collected |
| Razorpay (card, UPI and netbanking payments) | Razorpay receives your payment details directly and tells us the subscription or payment-link identifier, the amount, the currency and the payment status. Your card and UPI details never reach OpenAlly. | Take payment for a plan or credit pack outside an app store, mainly in India | Only when you pay by card, UPI or netbanking rather than through a store | Collected |
| Our servers (billing records) | A one-way fingerprint of the purchase token (never the token itself), the plan, the period dates, the amount and currency charged, the billing country, your numbered receipts, and per-request usage totals for the AI included with your plan. No prompt or response text. | Give you the plan you paid for, issue receipts, and meet tax and accounting duties | Only if you buy a plan or credit pack | Collected |
| OpenAlly download service | An authenticated request for the optional download (nothing of yours is uploaded) | Provide optional on-device AI and voice features (sign-in required) | When you request an optional download | Not collected |
| Our servers (community) | Your votes and any feature-request text you submit | Feature Requests and What's New | Only when you use those screens | Collected |
| OpenAlly cloud AI and Cloudflare Workers AI | The prompt, conversation context, and images you choose to include in that AI request. Service records keep usage totals and information needed for reliability and abuse prevention, not prompt or response text. | Generate an AI response under your OpenAlly plan | Only when you choose OpenAlly cloud AI for the request | Collected |
| The AI service you select (used with your own provider key, an existing subscription, or an address you host yourself) | Your prompts and chat content under your own key or subscription. If you turn on Health remote-model access, also the Health facts you approved for that turn, never the raw Health Connect store. | Prepare and process the AI request and generate a response | When you choose that service for the request | Not collected by us |
| Connected messaging platforms (WhatsApp, Telegram, Discord, Slack, Signal, LINE, Google Chat, iMessage, Mattermost, Nextcloud Talk, Twitch, Zalo) | The messages you send and receive on that channel | Operate the channel you connected | When a channel is connected; WhatsApp Business also uses the OpenAlly service described below | Not collected by us for direct device connections |
| OpenAlly WhatsApp Business service (hosted on Cloudflare) | Encrypted Meta authorization grants; business, number and device mappings; temporary messages and media; consent, approval and delivery status records | Connect the business, deliver correspondence to its designated device, enforce owner controls and prevent duplicate sends | Only when WhatsApp Business is connected | Collected |
| A third-party account you connect (for example an Instagram professional account, or Swiggy) | Only what the action you asked for requires. For Instagram, that is the post or reply you approve, the account's own comments and messages read back so the assistant can answer them, and, if you grant it, that account's own audience metrics. No other account of yours, and nothing from your conversations with the assistant. | Carry out the actions you asked for on that account | Only while that account is connected, and only for the action in front of you | Not collected by us |
| OpenAlly connection service | Temporary sign-in information needed to complete the connection. When you attach an image to a post, that image is held briefly so the platform can fetch it. Never your conversations. | Complete the account connection and give the platform temporary access to an image you chose to publish | When you connect an account, and when you publish a post with an image | Collected |
| Your chosen web-search provider (DuckDuckGo by default; Brave, Google Custom Search, or SerpAPI if you configure them) and websites OpenAlly opens at your request | Your search query text and the URLs requested | Web search and page retrieval | When you ask OpenAlly to search or open a web page | Not collected by us |
| Your own Google Drive (private OpenAlly area only) | An encrypted backup file we cannot open. Health Connect / Apple Health copies and the Health vault are not included. | Optional encrypted backup | When you enable backup | Not accessible to us |
How We Protect Your Data
Sensitive credentials (API keys, channel tokens, your backup recovery code) are protected using your operating system's credential safeguards and encrypted storage. Health records use a separate encrypted vault on your device. Optional backups are encrypted on your device before they leave it, using a recovery code shown only to you. OpenAlly does not hold that code and cannot open the backup. Health vault contents are not included in backups.
Data Retention & Deletion
Most of your data, conversations, settings, credentials, session history, Health vault, lives on your device, and we keep it only until you delete it or uninstall the app. Uninstalling removes all local data, including Health. Backup data stored in your Google Drive is not removed when you uninstall; you'll need to delete it from Google Drive separately. Health Connect and Apple Health originals are not deleted when you uninstall OpenAlly or purge the Health vault.
How long we keep things:
- On-device data is kept until you delete it or uninstall the app.
- WhatsApp Business temporary correspondence is deleted after device acknowledgement or within seven days; our hosting provider's database recovery history can keep copies for up to 30 days after that. Encrypted grants and connection/control records support the connected account; request deletion of service records through the deletion page. Device and Meta copies have separate deletion controls.
- Health vault data is kept on the device until you delete it from Health → Privacy, or uninstall. Health Connect / Apple Health originals stay where they are.
- Account data (email, display name, plan, synced settings, and a linked WhatsApp number) is kept on our account service until you delete your account or request deletion.
- Server-side deletion requests are processed within about 90 days, with an email confirmation.
- Billing records, the plan, the period dates, the amount and currency charged, the billing country and the fingerprint of the purchase token, are kept for as long as the law requires us to keep accounting records, and then deleted.
- Receipts are kept for the same period, for the same reason. A receipt is a record of a payment that was really made, so it is one of the few things a deletion request does not erase; it is retained under our legal obligation to keep it and is not used for anything else.
- AI usage totals, the counts that meter your plan’s allowance and any credits, are kept while the period they belong to is open and for a short window after it closes so that a dispute can be answered, then deleted. They are counts, never prompt or response text.
- An assistant connection is kept until you disconnect it in the app or delete your account. Records of actions an assistant asked your device to run, including the request and the result, are kept for 30 days, then deleted. A sign-in request you approve in the app expires after 15 minutes and its record is deleted about a week later. Notes made through an assistant are your notes, kept until you delete them, with a deletion marker kept for 30 days so your devices can sync the deletion.
- Crash data is kept by Google under its own policies.
- Analytics events are held by Google for the user-level retention window configured with Google, which is at most 14 months from your last activity, after which they expire automatically. Aggregate reports that cannot identify you or your device may be kept for longer.
- Your push subscription record is kept by OneSignal while the app is installed. It is deleted when you delete your account, when you ask us to remove it, or when the subscription goes permanently unreachable (for example, after you uninstall).
Analytics and push are inside the deletion promise. A deletion request covers them both. When you delete your account or use the data deletion request page, we delete the analytics data recorded against your account identifier and the push subscription bound to it, within the same ~90-day window and with the same email confirmation. Analytics recorded while you were signed out is tied only to a random per-install identifier, which we cannot match to you, tell us your install's identifier, or simply uninstall, and it expires on the schedule above.
To request deletion of any server-side data associated with your account, visit our data deletion request page.
Your Choices & Rights
You can delete your account in the app or via our data deletion request page. You can also ask to access, correct, or get a copy of the limited account data we hold by emailing [email protected]. Because your conversations, Health vault, and most of your data live only on your device, you control them directly, uninstalling removes everything local, though Drive backups have to be deleted separately. Health Connect and Apple Health originals are not ours to delete.
Analytics and notifications specifically. To turn off usage analytics, use Settings → Privacy & data in the app, or email us with "Analytics opt-out" in the subject and we will erase what we already hold. To stop push notifications, revoke the notification permission in your device settings. That takes effect immediately, and email us if you also want the push subscription record deleted. Neither choice degrades the app in any way.
Your US State Privacy Rights (California & Other States)
We do not sell your personal information for money, and we do not share it for cross-context behavioral advertising under the California Consumer Privacy Act (CCPA/CPRA) and similar US state laws.
Analytics is not a sale or a share. The usage analytics described above are processed by Google as our service provider, for our own product purposes only. They are not used for cross-context behavioural advertising, not disclosed to any advertising network, and not exchanged for money or anything of value.
Your privacy rights. You can ask us for help with a privacy request by emailing [email protected].
California residents also have the right to know, delete, and correct their personal information, and the right not to be treated differently for exercising these rights. Health records on your device are sensitive personal information under CPRA. We collect them only on the device, for the Health features you use, and we do not sell or share them for advertising.
Your Rights (EEA, UK & Similar Regions)
If you're in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, restrict, and port your personal data, and to object to its processing. You can withdraw consent at any time, and you can lodge a complaint with your local data protection authority. To exercise any of these, email [email protected].
Our legal bases (Article 6 GDPR):
- your consent (Art. 6(1)(a)), for usage analytics, for push notifications, and for crash reporting where consent is required;
- performance of a contract, or steps taken at your request (Art. 6(1)(b)), to provide the app and your account; and
- our legitimate interests (Art. 6(1)(f)), app stability, security, and fraud prevention. We do not rely on legitimate interests for analytics.
Health data (Article 9 GDPR). Health records are a special category of personal data. We process them only with your explicit consent: you set up Health, you grant Health Connect or Apple Health categories (or enter records yourself), and a cloud model sees Health facts only if you separately turn on Remote model. You can withdraw that consent by disconnecting the source, turning Remote model off, deleting the vault, or uninstalling. OpenAlly is not a covered entity under HIPAA; encryption on the device is not a HIPAA certification.
Consent for the identifier itself (ePrivacy). Storing or reading an analytics identifier on your device is regulated separately from the question of a lawful basis: under Article 5(3) of the ePrivacy Directive (and the national laws implementing it), it needs your consent unless it is strictly necessary to deliver a service you asked for. The analytics identifier described above is not strictly necessary (the app works exactly the same without it), so we treat it as requiring consent in its own right, on top of the Article 6 basis. If you are in the EEA or UK and have not given that consent, email [email protected] and we will switch analytics off for your account and erase what was collected. The push subscription identifier is stored to deliver notifications you asked for; if you never grant the notification permission, nothing is delivered, and you can have the record deleted on the same request.
Withdrawing consent is as easy as giving it and costs you nothing, the app keeps working, in full, either way. Withdrawal takes effect going forward and, for analytics and push, we also erase what we already hold.
India · Digital Personal Data Protection Act, 2023
Matterward Labs Private Limited is incorporated in India, and if you are in India your personal data is handled under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"). We are the Data Fiduciary; you are the Data Principal.
Consent, and only consent. The DPDP Act has no "legitimate interests" basis. Except for the narrow legitimate uses the Act itself lists, we may process your personal data only with your consent, and section 6 requires that consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data actually necessary for the stated purpose. So, for users in India:
- Usage analytics and push notifications are opt-in. We ask, you choose, and we do not read "you kept using the app" as a yes. Bundling them into your acceptance of our Terms would not be valid consent, so we don't do that.
- Health is opt-in on the device. Setting up Health, granting Health Connect categories, and turning on Remote model are each a clear affirmative action. Refusing any of them still leaves the rest of OpenAlly working.
- Refusing costs you nothing. Consent cannot be conditioned on access, so every feature of OpenAlly works whether you say yes or no.
- Purpose is capped. We use the data only for the purpose we stated when asking, and only the data needed for it.
Withdrawal means erasure, not just "we'll stop". You can withdraw consent at any time, and it must be as easy as giving it. Under section 8(7), once you withdraw (or once the purpose is served) we must erase your personal data and cause our processors to erase it too, unless a law requires us to keep it. That is what we do: withdrawal of analytics or push consent triggers deletion of the analytics data and the push subscription held against your account, not merely a switch flipped to off.
Your rights. You have the right to a summary of the personal data we process and what we do with it, including the processors we share it with (s.11); the right to correction, completion, updating and erasure (s.12); the right to grievance redressal (s.13, below); and the right to nominate someone to exercise these rights if you die or become incapacitated (s.14). To use any of them, email [email protected].
Children. Under section 9, anyone under 18 is a child for the purposes of the Act. We may not process a child's personal data without verifiable consent from a parent or lawful guardian, and we may not track a child, serve them targeted advertising, or otherwise monitor their behaviour, at all, and with no opt-in that could authorise it. See the Children section below for how that works in practice.
You can complain to the regulator. If our response to a grievance doesn't satisfy you, or we don't respond in time, you may complain to the Data Protection Board of India. Please raise it with us first through the process below, but this right is yours, and nothing on this page limits it.
Grievance Redressal
If something about how we handle your data isn't right, we want to hear it from you before you hear it from anyone else. Section 13 of the DPDP Act requires us to publish a readily available means of grievance redressal, and this is it.
- Grievance Officer: the Data Protection Officer, Matterward Labs Private Limited
- Email: [email protected], put "Grievance" in the subject line so it is routed correctly
- Acknowledgement: within 72 hours of receipt
- Resolution: within 30 days of receipt. If a matter genuinely needs longer, we'll tell you why and when to expect an answer
Please include enough detail for us to find you, the email address on your account, if you have one, and what you'd like us to do. Exercising your rights or raising a grievance is free, and we won't treat you differently for it.
If you are not satisfied with the outcome, or we miss the deadline above, you may complain to the Data Protection Board of India. Users in the EEA or UK may equally complain to their local supervisory authority.
International Data Transfers
Some of our processors, for example Google (Crashlytics and Analytics), OneSignal, our account and storage provider, and the AI providers you choose, may handle data on servers outside your country, including in the United States. Where required, those transfers rely on appropriate safeguards, such as the EU Standard Contractual Clauses or the relevant provider's certification. Prompts you send to an AI provider are transferred under that provider's own terms and safeguards.
Children
OpenAlly is not directed at children, and we do not knowingly collect personal information from them. Health Connect and Apple Health are not used in a child-directed product. Health is for an adult owner of the device. Where the age threshold sits depends on where you are, and we apply the higher one:
- India (DPDP Act, s.9): under 18. Anyone under 18 is a child under the Act. We will not process a child's personal data without verifiable consent from a parent or lawful guardian.
- EEA / UK: the age of digital consent set by your country, between 13 and 16.
- United States (COPPA): under 13.
No behavioural monitoring of children, ever. Section 9(3) of the DPDP Act prohibits tracking a child, behavioural monitoring of a child, and targeted advertising directed at a child. There is no consent that unlocks this, so we don't offer one: OpenAlly is not directed at children, and we do not knowingly use a child's data for analytics or a behavioural profile.
If you believe a child has provided personal data through the app, email [email protected] and we will erase it and the associated analytics and push records.
This Website
This policy is about the OpenAlly app. The website at openally.ai is informational, it doesn't set advertising or tracking cookies. It uses only essential local storage, such as remembering your light or dark theme preference.
Google Play Data Safety
This policy is consistent with our Google Play Data Safety disclosures. In Play's terms: crash diagnostics, app interactions and other app-performance data (the usage analytics above), your push subscription as a device or other ID, and your account email are collected; Health and fitness data (steps, heart rate, sleep, weight, activity, medications, and records you enter or import) are collected on the device and are not sent to OpenAlly; and your conversations, SMS, audio, business records, and Health vault are not collected by us, they're processed on your device. If you turn on Health remote-model access, the Health facts you approve for a turn are sent to the AI provider you chose, not to us. Data in transit is encrypted, and you can request deletion of everything held server-side.
Changes to This Policy
If we update this privacy policy, we'll update the "Last updated" date at the top of this page and post the new version here. For material changes that affect how we use your personal data, we'll give you a more prominent heads-up, such as an in-app notice, and, where required, ask for your consent again. We encourage you to check back from time to time.
What changed in this version. This update adds the Health section, Health Connect / Apple Health read-only access, the on-device vault, optional remote-model sends, deletion, and the matching Data Safety and permission disclosures. It also records that usage analytics can be turned off in Settings → Privacy & data, and that Health screens are excluded from analytics. An earlier version of this page said we collected no usage analytics; the Android build does, it did when that sentence was live, and correcting it is why a prior revision existed. Because Health is a material change, it gets an in-app disclosure before Health Connect access is requested, not a silent edit to this page.
It also corrects the Account & Sign-in section. An earlier version said an account was optional; the app requires one, and the section now lists every way to sign in, including WhatsApp, and the settings your account carries between devices.
It also corrects the Assistant Connectors section. An earlier version said an assistant started the sign-in and that email was the route for people with no phone to hand. Neither is true any more: an assistant cannot start a sign-in or produce a sign-in link, signing in happens only on the OpenAlly sign-in page, and the emailed code is the ordinary route, with an existing account password or approval in the app as alternatives. The records described there changed with it, so the retention entry for a sign-in request was corrected too.
Contact
Questions about this privacy policy? Reach us at [email protected].
Matterward Labs
OpenAlly™ and the OpenAlly logo are trademarks of Matterward Labs Private Limited.