Privacy Policy

One listens to you, looks at your screen, and reads what your coding agents are doing. This page explains what that involves, why, and what you control.

Effective 28 September 2026 · Version 0.6

In short

  • One only listens and looks at your screen while you are talking to it. It is not an always-on recorder.
  • What you say, what is on your screen, and what your agents are showing are sent to AI providers to understand and act on your request. We do not keep a server-side archive of it.
  • Product analytics never include the contents of your prompts, audio, screenshots, or terminal output. The app has no switch to turn them off; they are deleted with your account.
  • You can delete your account from Settings → Account in One on your Mac, iPhone, or phone browser. Your account is removed immediately; remaining service-provider copies are removed within 30 days.

Who we are

One (“One”, “we”, “us”) provides apps for Mac, iPhone, and iPad and companion services published at oneplace.buzz. The app lets you drive coding agents running on your Mac by speaking or typing to it. This policy covers the One macOS and iOS apps, the One phone remote, the services behind them, and the oneplace.buzz website.

Questions or requests: support@oneplace.buzz.

What we collect

Account information

  • Sign-in. When you sign in with Apple or Google we receive an account identifier and, when the provider supplies them, your email address, display name, and avatar image. Apple may provide a private relay address instead of your personal email. We use these details to create your account, show who is signed in, and contact you about the service.
  • Connected AI accounts. If you connect an AI provider account (such as ChatGPT) so that an agent can run on your plan, we keep an account identifier and plan tier for that account. We never see your password for that account, and the credentials stay on your Mac.
  • Download signup. When you enter your email to download One we store that address and basic information about how you signed up, so we can send the release notes and product updates you requested. Joining this mailing list is optional; creating a One account does not subscribe you. You can unsubscribe at any time.

What One uses when you talk to it

Each time you speak or type a request, One works with:

  • Your voice: the audio of the request you speak.
  • Your screen: a capture of what you are looking at, so the model can see what you are pointing at.
  • Your agents’ activity: what your coding agents are currently showing and recent context from their sessions on your Mac, so the model knows what each agent is doing.
  • The exchange itself: the transcription of what you said, One’s response, and the instruction it passed to an agent.

This is what makes One work; there is no way to act on a spoken request without it. It is sent from your Mac to the AI providers we use to process the request. We do not build a server-side archive of your audio, screenshots, or terminal text.

Phone remote

When you pair a phone, One shares the names and status of your agents and short summaries of what they are working on, so you can pick one from your phone. Anything you type or attach on the phone is relayed to your Mac and the coding agent you choose. Live conversation state is held while the remote is connected. Device approvals, encrypted machine keys, and notification tokens are retained so your devices can reconnect; they are removed when you delete your account.

The iPhone app accesses only the photos you select for a request. The iPhone app and phone browser cache recent conversation and agent state on your device so you can return to it. Signing out, an expired session, or confirmed account deletion clears that cache. A connected device also clears it when notified of deletion from another device; an offline device clears it when it next detects that its session has ended. Voice dictation uses Apple speech recognition and may send audio to Apple when recognition on the device is unavailable. If you allow notifications, Apple receives a device token and notification delivery data. One encrypts the notification content before sending it through Apple’s push service.

Product analytics

We collect usage events (such as completing onboarding or starting a request) together with app version, operating-system version, and coarse device information, associated with your account. Analytics events never include prompt contents, transcripts, audio, screenshots, terminal output, file paths, or project names. The app does not currently offer a switch to turn analytics off. Account deletion includes your analytics profile and events. For other privacy requests, email support@oneplace.buzz.

Crash and error reports

If the app crashes or hits an unexpected error, a report containing technical details about the failure, the app version, and the operating-system version may be sent to us. We try to keep prompt contents out of these reports.

Where it goes

We rely on third-party service providers to run One. Each receives only what it needs for its role and is bound by its own terms and data-processing commitments. They fall into these categories:

  • OpenAI processes One requests and requests sent to Codex. Anthropic processes requests sent to Claude. Other coding agents use the provider you configured.
  • OpenRouter routes supported requests and agent summaries to the selected model provider, which can include OpenAI, Anthropic, or Google. Voice transcription may use OpenAI, Groq, AssemblyAI, Google, or Apple, depending on the device and selected engine.
  • Infrastructure providers that host our services, store account data, and relay traffic between your devices.
  • PostHog receives the product events and technical diagnostics described above. Loops holds account contact records and sends optional email updates to people who explicitly join the website mailing list.

Sending content to these providers is how One works: your messages, voice, attachments, screen captures, and the agent context each feature needs, including background summaries of agent threads, go to the providers that handle them. The iPhone app asks for your permission before you can use it; if you withdraw it in Settings, the app stays closed until you allow it again. It cannot recall a request already sent. Some of these providers are located in the United States. By using One you acknowledge that your data will be processed there. We rely on the providers’ standard contractual protections for international transfers.

How long we keep it

  • Voice and screen captures are used for the request at hand and are not retained on our servers. Copies on your Mac are removed automatically shortly afterwards.
  • Live phone remote state is cleared when the remote disconnects. Device registration and trust records remain until you remove the device or delete your account.
  • Sign-in sessions expire after a period of inactivity. Signing out ends them immediately.
  • Account and download-signup information is kept until you delete your account or ask us to remove it.
  • Account deletion immediately removes your account, sign-in sessions, and device connections. We keep a minimal deletion receipt while our providers remove remaining analytics, email, and Apple sign-in records, within 30 days; the receipt is then removed.
  • Analytics events and any associated profile are submitted for deletion when you delete your account.
  • Crash and error reports are stored with our product analytics. Reports associated with your account are included in account deletion.

What stays on your Mac

One stores its conversation history, working memory, and agent-thread summaries locally on your Mac. Relevant parts may be included in AI requests, as described above. When you delete your account on that Mac, or the connected Mac receives confirmation of deletion from another device, One removes this local history, memory, and summaries, including its own history backups. If local removal fails, Settings shows a retry action.

A Mac that was offline may still hold these local files. An expired sign-in alone does not prove that you deleted the account, so it does not erase them. You can remove One’s local data from its data folder; One also clears the previous account’s content before a different verified One account signs in. Your projects, general app settings, and separate coding-agent conversations, credentials, and accounts are kept.

Your choices and rights

  • Permissions. One only works with the system permissions you grant. On Mac these include Microphone, Screen Recording, Accessibility, and Automation; on iPhone they include Microphone, Speech Recognition, and Notifications. You can revoke them in your device’s Settings at any time.
  • Analytics. The app has no analytics switch right now. To object to analytics or have them deleted, email support@oneplace.buzz.
  • Sign out. Signing out ends the One session on that device and removes its One sign-in credential. Your separate coding-agent accounts are kept.
  • Delete your account and data. In One on your Mac, iPhone, or phone browser, open Settings → Account → Delete account. Your account and connected devices are removed immediately, with confirmation in the app. Remaining service-provider copies are deleted within 30 days. Your own projects and coding-agent accounts are kept. For help, email support@oneplace.buzz.
  • Access and correction. You can ask us for a copy of the account data we hold about you, or to correct it, at the same address.

If you are in the EU, UK, or another region with data-protection law, you may also have the right to object to or restrict certain processing, to data portability, and to lodge a complaint with your local supervisory authority. Our legal basis for processing is performance of the service you asked for, and our legitimate interest in keeping it secure and improving it.

Security

Traffic between the app, the website, and our services is encrypted in transit. App sign-in credentials are stored using the secure storage built into macOS and iOS; the phone website uses an HTTP-only session cookie. Access to our systems is limited to the people operating the service. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.

Children

One is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

This policy may change as One develops. We will post the new version here with an updated effective date, and notify signed-in users in the app or by email when the changes are material.

Contact

support@oneplace.buzz