Skip to content
Trust & control

What stays yours. What you control.

Start with the questions that matter: where your work goes, who can access it, what you can verify, and what happens when you change your mind.

These principles apply across Android, iPhone, and Mac. Platform-specific permissions and background behaviour are labelled where they matter.

  • A clear route, know whether a job stays local or uses a service you chose
  • Visible access, review what each agent and connection is allowed to use
  • A real exit, switch providers, remove access, or disconnect a service
You choosemodel & services
You allowspecific access
You can seestatus & activity
You stay in controlpause or disconnect
Your knowledge

Give it facts you can recognise

OpenAlly can work from your own material, so answers reflect your prices, policies, plans, and preferences, not a generic guess.

This is useful for an individual keeping personal context together and for a business that needs consistent answers from changing documents. You choose the sources, keep them current, and can check the result against material you recognise.

Interface view: Your material, organised around the work
  • Your sources set the facts

    Use the contracts, notes, policies, price lists, and reference material that matter to you or your business.

  • You can check the answer

    Compare an answer with the material you supplied, ask a follow-up, and correct the source when reality changes.

  • Keep each job focused

    Give an agent the knowledge it needs for that role instead of exposing every part of your life or business by default.

  • Change or remove it yourself

    Your knowledge is not trapped inside a provider. Update the material, remove it, or change the model you use with it.

Know the boundary before you ask

Where the material is stored and where a particular request is processed are different questions. OpenAlly makes room for both local and connected choices, so here is the plain-language split.

  • Stored knowledge

    The knowledge you add is kept with your working data on your device.

  • Supported local work

    When you choose an on-device option for a supported task, that request does not need a remote model service.

  • A remote model you choose

    If you choose a remote model, the prompt and relevant context needed for that request go to that service. OpenAlly Cloud requests are processed by the OpenAlly service.

Your processing choice

Choose the right route for each job

Keep supported work on your device, use a provider or plan you already trust, connect a server you control, or choose OpenAlly Cloud. The route is a choice, not a lock-in.

Privacy depends on the route you choose. “On your device” means no remote model service is needed for that supported task. A remote model means the request and the context it needs go to the selected service. OpenAlly makes that difference clear before it becomes a surprise.

Interface view: Change the model when the job changes
  • On your device

    Choose a supported on-device option when the job and your hardware are a good fit. The request does not go to a remote model provider.

    Availability varies by feature and device

  • A provider you already trust

    Bring your own key and your device talks directly to that provider for the request. Their privacy terms and retention rules apply.

    Your key is not stored on an OpenAlly server

  • Your plan or your server

    Reuse a supported subscription or connect a server you control. You can change the route without rebuilding your agents or workflows.

    No model or provider lock-in

  • OpenAlly Cloud

    If you select OpenAlly Cloud, the OpenAlly service processes that AI request. This is a distinct choice, not the hidden route for every conversation.

    Covered by the OpenAlly privacy policy

Three things to check before sensitive work

These practical controls determine who receives the request and what the agent may do with it. Check them before personal, financial, or business-sensitive work.

  • The selected model

    See which provider and model will handle the work, then change it when the job changes.

  • The agent's access

    Review the files, tools, and connections an agent may use instead of granting everything by default.

  • Your connected services

    Disconnect a provider or integration when you no longer want OpenAlly to use it.

Local capability and performance depend on the feature, client, and hardware you use. OpenAlly is cross-platform; individual feature pages carry the exact Android, iPhone, or Mac availability where a capability differs.

Privacy & permissions

Private by design. Clear about exceptions.

Your working data stays on your device. When a model or connected service needs information, the route you chose determines where that request goes.

Bring-your-own AI and integration requests go directly to the service you selected. OpenAlly Cloud requests are processed by the OpenAlly service. Those are different privacy boundaries, and the product should never blur them into one broad “everything is local” promise.

WhatsApp Business works differently: an OpenAlly delivery service receives your business messages from Meta and passes your replies back, holds your Meta authorisation encrypted, and keeps messages encrypted for at most seven days until your device collects them. It never runs your agent. Premium's agent mailbox is hosted too: mail to and from your agent's address is kept by an OpenAlly service, within your plan's mail storage.

Your controls

Clear enough to act on

  • Agent accessReviewable
  • Model choiceChangeable
  • ConnectionsRemovable
  • Local dataClearable
  • Working data stays with you

    Your messages, notes, knowledge, and business records are stored on your device rather than saved as part of your OpenAlly account.

  • OpenAlly does not keep your provider keys

    Your provider keys and passwords are protected in secure device storage and presented only to the service you chose. An OpenAlly server cannot reveal a key it never stores.

  • Your backup needs your recovery phrase

    A backup is encrypted on your device before it reaches your Google Drive. OpenAlly does not hold the recovery phrase that opens it.

  • Agents work within access you grant

    Choose which files, tools, and services an agent may use. Review that access, narrow it, or remove it as the job changes.

Android permissions you can inspect

Android

Open Android's app-permission settings and check these claims for yourself. The list is intentionally platform-specific: iPhone and Mac expose their own permission controls in system settings.

  • Draw over other apps

    OpenAlly does not request the Android power to place its own interface over another app.

    Not requested
  • Read all notifications

    OpenAlly does not request notification-listener access to watch your notification shade.

    Not requested
  • Control other apps

    OpenAlly does not request Android accessibility-service access. That optional power belongs to the separate Aster companion.

    Separate app
  • Camera, microphone, location, and files

    A feature asks when it needs one of these ordinary permissions. You can decline it or revoke it later in system settings.

    Asked in context

Aster is an optional, separately installed Android companion for screen control. It has its own permissions and approval flow. You do not need it for OpenAlly's wider work across Android, iPhone, and Mac.

Learn about Aster

The honest small print: Crash diagnostics exclude your conversation content. Remote providers and connected services apply their own privacy and retention terms to information you send them. Review those terms and disconnect a service when it no longer belongs in your setup.

Trust should survive a settings check.
Direct when you bring your own provider. Clear permissions. Your work, your choice.
Verification & reliability

Promises you can check. Limits you can see.

Clear settings, visible choices, useful records, honest platform labels, and a documented exit make trust practical.

Reliability is not only speed. It is knowing which service is doing the work, seeing whether a long-running job is active, having a recovery path, and being able to stop or switch when the situation changes.

A useful trust test

Questions the product should answer

  • Where did this request go?

    Visible choice

  • What could the agent use?

    Review access

  • Can I stop or disconnect it?

    Yes

  • Where are the full details?

    Privacy & deletion

  • System permissions

    Open your device settings to see what OpenAlly can access and revoke an ordinary permission whenever you want.

    Check on your device

  • Provider and model choice

    Open the provider picker to see what is connected, which model is selected, and which route you can change next.

    Check in OpenAlly

  • Request activity and cost

    Review which model handled a request and the estimated cost recorded for it, so a reply is not a billing black box.

    Check the activity record

  • The full data boundary

    Read the privacy policy for account data, analytics, optional services, local data, remote processing, retention, and your choices.

    Read the privacy policy
  • Deletion paths

    Clear local data from the app and use the documented request path for account and OpenAlly service data.

    See deletion options
  • Platform availability

    Check the platform row on a feature before relying on it. Android-only powers are labelled as Android-only, not presented as the whole product.

    Browse feature details

Reliable when plans change

These are the outcomes worth holding OpenAlly to. They explain how the product behaves when a service changes, work continues in the background, or you need to recover and move on.

  • A provider problem is not a platform dead end

    Switch to another connected model, a supported plan, your own server, or an on-device option without rebuilding the work around it.

  • Background work should stay visible

    On Android, supported background work shows a system status while active. iPhone and Mac follow their own operating-system limits, and platform-specific behaviour is labelled.

  • Recovery remains in your hands

    Your encrypted backup and recovery phrase give you a path back without turning OpenAlly into the keeper of your private workspace.

  • You can stop, narrow, or disconnect

    Pause work, remove an agent's access, or disconnect a provider or service. Reliability includes a clear way to change course.

Want the complete wording?

The privacy policy and deletion page carry the detailed service boundaries. This page keeps the product story readable; those pages carry the full disclosure.

Ready when you are

Keep the control. Put it to work.

Start with the provider and permissions you are comfortable with, then use OpenAlly across Android, iPhone, and Mac for real life and real business.

Mobile-first on Android and iPhone, with Mac continuity.