Exo โ Privacy notice
Last updated: June 2026 (legitimate-interest diagnostics). We may update this notice and will take reasonable steps to surface material changes in the app or on exosites.ch.
Who we are
This notice covers Exo โ our desktop and mobile applications from Exosites, 21 places d'Armes, 1227 Carouge, Geneva, Switzerland. It does not replace the exosites.ch website privacy policy for marketing pages and the contact form. Unless your organisation has a separate agreement with us, the data controller is Exosites at that address, reachable at studio@exosites.com or +41 22 301 08 12.
Plain summary
โข Exo processes your files on your device by default (desktop and mobile). โข On desktop, coarse usage analytics and crash reports run on our legitimate interest to improve reliability; you may object in Settings โ Privacy. Mobile crash reporting stays opt-in. โข Google, Microsoft, and other connectors run only when you start a flow in the app. โข You can download, export, or delete your cloud account and erase local assistant data in Settings. โข You can disconnect integrations anytime. โข We do not sell your data.
Local processing and on-device data
Sorting and classification run primarily on your computer. On mobile, synced memories and tasks are stored encrypted on the device; the cloud relay holds ciphertext only. You choose workspace folders, output locations, models, and rules; configuration and UI preferences are stored locally. File contents and paths are not uploaded for core sorting unless you enable separate features (remote model calls, mail or cloud imports, GO SYNC ciphertext, or other network flows you start). You are responsible for the sensitivity of folders you authorise, device security, encryption, and backups.
Google user data and Limited Use
When you connect Google in External sources, Exo accesses only the products and permissions you approve on the consent screen. We do not scan Gmail, Drive, or Calendar in the background. Access happens when you start a sort or import, connect the integration, or use assistant tools you enabled. Exo's use of Google user data is limited to user-facing features (sort Gmail/Drive attachments, calendar for briefing and assistant). We do not sell Google user data, use it for ads, or train generalized models on it. Human access occurs only with your consent, for security, or when required by law. Exosites' use of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy. Scopes in plain language: Gmail read/modify/label/move โ search and read messages, apply labels, move or trash mail when you run mail sort/import or when assistant mail tools perform an action you requested. Gmail send โ only when you or the assistant explicitly triggers a send. Google Drive full access โ list, search, download or export to local staging for sorting; organize or upload files only when you approve assistant actions. Google Calendar read and events โ read events for briefing and calendar-aware assistant actions; create or update events when you request them. OAuth tokens and local staging copies stay on your device until you disconnect in External sources, delete local app data, or tokens expire or are revoked. Disconnect in the app or at https://myaccount.google.com/permissions.
Other integrations
Microsoft Graph (OneDrive, Outlook mail): OAuth tokens stored on your device; accessed when you start sort, import, or assistant flows you enable. Dropbox: same pattern โ tokens on device, access on user-initiated jobs; files may be staged locally for sorting. Notion: integration token stored locally; used for assistant context when enabled. Slack: token on device; used for assistant features you turn on. Amazon S3: credentials you configure; used for assistant access to buckets you specify. iCloud: accessed when you connect and start flows in the app. Infomaniak (kDrive, Mail, Calendar): tokens on device; mail/drive for sort staging; calendar for briefing and assistant (see Memory and Today). Prompts sent to external chat or model providers follow those vendors' policies.
Local AI vs cloud AI
Sorting uses a local AI runtime on your machine. Optional API keys you provide to OpenAI, Anthropic, Google Gemini, or other providers are sent directly from your configured client to those endpoints for chat, voice, meeting transcription summaries, activity-timeline vision (when enabled), or other features you turn on โ separate from local sorting. The app discloses when cloud chat or voice may send conversation text or audio to your chosen provider. We do not route your file contents through our servers for core classification.
Exo account service (api.exosites.ch)
Signing in with email, Google, or Apple uses our account service at api.exosites.ch for authentication, trial status, license entitlement, and GO SYNC relay metadata. Cloud sign-in uses openid, email, and profile only โ it does not grant Gmail, Drive, or Calendar access. That is separate from connecting Google in External sources. We store account identifiers, entitlement metadata, sync device registrations, and encrypted blob envelopes (ciphertext only) on our servers โ not your file contents or plaintext memories. Crash ingest may receive technical reports under our legitimate interest unless you object (see Telemetry). No credit card is required to start the 14-day trial.
Telemetry and crash reports
On desktop, coarse usage analytics and crash reporting are processed on our legitimate interest in operating, securing, and improving Exo (GDPR Art. 6(1)(f) / Swiss FADP equivalent) โ not on consent. They are on by default; you may object anytime under Settings โ Privacy by unchecking Usage analytics and/or Crash reports. When active, the app sends allowlisted UI events (for example app started, tab changed, job started) with an anonymous instance id, app version, platform, and locale โ never file paths, file names, folder names, prompts, or responses. When signed in, events may be linked to an internal account id (not your email in telemetry). Local telemetry rows are trimmed after about 90 days. Crash reports may include scrubbed stack traces, breadcrumbs, and technical context to api.exosites.ch; paths and contents are stripped. Cloud telemetry, feedback, crash reports, and session rows linked to your account are deleted when you delete your account. Cloud crash rows are also pruned after about 90 days. Some builds may use Sentry when configured; session replay is disabled. On mobile, crash reporting remains opt-in under Settings โ Privacy.
Memory, activity timeline, and encrypted sync
Memory stores facts the assistant keeps; you can review, edit, and delete them. Today shows briefing, tasks, and sync status. Optional daily briefing may read calendar and mail highlights when those connectors are connected. Activity timeline is opt-in: periodic screenshots may be sent transiently to a cloud or local vision model to produce a one-line activity summary; raw screenshot pixels are not stored โ only the summary text is kept (about 14 days). You can pause capture, exclude sensitive apps, and clear the timeline. Encrypted sync (trial/Pro) stores memories and tasks across desktop and mobile with end-to-end encryption โ our servers relay ciphertext only and cannot read the plaintext.
Voice, microphone, and speech
Optional voice features include push-to-talk, conversation mode, clap-to-talk, read-aloud of replies, and meeting capture on desktop. The microphone is used only while you use those controls or while voice listening is enabled in settings. Speech-to-text may run on-device or via OS/browser or cloud services depending on your mode and provider. We do not sell voiceprints or use voice data for advertising. Disable voice in Settings or deny microphone permission at the OS level if you prefer.
Retention and deletion
OAuth tokens and local staging data remain on your device until you disconnect, erase local data in Settings โ Privacy, or tokens expire or are revoked. Staging areas are cleared after jobs complete. Account, trial, and license metadata on our servers are kept while your account is active and as needed for legal obligations. Usage telemetry on device: about 90 days. Activity timeline summaries: about 14 days. Crash reports on our servers: about 90 days (or deleted sooner when you delete your account). GO SYNC ciphertext on our servers is deleted when you delete your cloud account.
Your rights and in-app controls
Where the GDPR, Swiss Federal Act on Data Protection, UK GDPR, or similar laws apply, you may have rights of access, rectification, erasure, restriction, objection, withdrawal of consent (where consent applies), and data portability. In the app: Settings โ Account โ Download my data (JSON of cloud-held metadata) and Delete account (removes linked telemetry, feedback, and crash reports); Settings โ Privacy โ object to usage analytics or crash reports, and Erase local assistant data (memories, chats, tasks, activity on this device). You may lodge a complaint with a supervisory authority (for example the Swiss FDPIC or an EU/UK authority). Contact studio@exosites.com with subject "Privacy objection" or "Data request".
International transfers and subprocessors
Because you may route data to global model, identity, or speech providers, processing may occur outside Switzerland or the EEA. Where we act as controller and the law requires safeguards, we rely on appropriate mechanisms (such as standard contractual clauses or adequacy decisions). Subprocessors and infrastructure we use for Exo include, where applicable: Infomaniak (hosting, api.exosites.ch), Google and Apple (OAuth sign-in only for the account service), optional Sentry (crash reporting when enabled in a build), and identity or model providers you configure yourself. Contact studio@exosites.com for an updated list.
Children, changes, and contact
Exo is not aimed at children. AI-assisted sorting is an assistive tool, not solely automated legal decision-making under Article 22 GDPR. We may update this notice; material changes are summarized in the app or release notes. For the marketing site, use the website privacy policy in the footer. Contact: studio@exosites.com, +41 22 301 08 12, Exosites, 21 places d'Armes, 1227 Carouge, Geneva, Switzerland.
Mobile applications
The Exo mobile app (iOS and Android) connects to the same account service and optional GO SYNC relay as desktop. Access and refresh tokens are stored in the device secure enclave (Keychain / Keystore). The sync master key never leaves your devices in plaintext. Optional mobile crash reporting is opt-in under Settings โ Privacy and follows the same scrubbing rules as desktop. Microphone permission may be requested for future voice features; disable permissions in system settings if you do not use them. App Store and Play privacy labels should match this notice.
Assistant automation (meetings, codegen, terminal)
When you enable assistant features, Exo may: transcribe or summarize meetings you start and extract tasks or memories you approve; write or edit project files in folders you designate (codegen sessions); or run a restricted allowlist of read-only terminal commands you request. These actions run on your device under your control. Outputs may be sent to cloud models if you configured a cloud provider. Review suggestions before moving files, sending mail, or running commands. You can delete resulting memories, tasks, or generated files at any time.