Privacy Policy

Effective date: June 26, 2026  ·  Last updated: June 26, 2026

The short version. On the Mac app, almost all of your data — conversations, memories, personas, vault, API keys — stays on your device and never leaves it. On the web app, we host your conversation history, personas, memories, and vault, and route inference through a third-party LLM service provider — but we do not read or log message content for any purpose other than serving you, and we do not use your content to train any model. We do not sell or “share” personal information for advertising, and we do not embed third-party analytics, ad pixels, or behavioral trackers.

This Privacy Policy (the “Policy”) describes how the operator of dequid — PIGILABS LLC, a Wyoming limited liability company doing business as dequid (“dequid”, “we”, “us”, or “our”) — collects, uses, discloses, retains, and protects information when you use the dequid web app, the dequid Mac app, the website at dequid.com, and any related services (collectively, the “Service”). It also describes the choices and rights you have. Capitalized terms not defined here have the meanings given in our Terms of Service.

  1. 1. Scope
  2. 2. Who We Are and How to Contact Us
  3. 3. Quick Reference: Web vs Mac
  4. 4. Information We Collect
  5. 5. Information Stored Only on Your Device (Mac app)
  6. 6. How We Use Information
  7. 7. Legal Bases for Processing (EU/UK)
  8. 8. How We Share Information
  9. 9. Sub-Processors
  10. 10. LLM Service Provider and Inference
  11. 11. International Data Transfers
  12. 12. Data Retention
  13. 13. Security
  14. 14. Your Privacy Rights
  15. 15. California Residents (CCPA / CPRA)
  16. 16. EU, UK, and Swiss Residents (GDPR / UK GDPR)
  17. 17. Other U.S. State Privacy Laws
  18. 18. Children's Privacy
  19. 19. Cookies and Similar Technologies
  20. 20. "Do Not Track" Signals
  21. 21. Automated Decision-Making
  22. 22. Third-Party Links
  23. 23. Changes to This Policy
  24. 24. How to Contact Us About Privacy

1. Scope

This Policy applies to information processed by dequid in connection with the Service. It does not apply to:

  • The LLM Service Provider that ultimately performs inference (see Section 10). Inputs and outputs handled by that provider are governed by its own privacy notice.
  • Other third-party services we link to or integrate with (e.g., Stripe for payments, Google for sign-in). Their handling of your information is governed by their own policies.
  • For the Mac app: any direct LLM provider whose API key you configure. Those requests go from your device directly to that provider and are governed by its policy.
  • Information you publish or share through external channels (e.g., screenshots you post on social media, conversations you export and email).

2. Who We Are and How to Contact Us

The data controller for purposes of European data-protection law (and the “business” for purposes of California law) is dequid, as identified above. We do not maintain a Data Protection Officer, but you can reach our privacy team at any time at legal@dequid.com.

3. Quick Reference: Web vs Mac

DataWeb appMac app
Conversations & messagesStored on our servers (Cloudflare D1)Stored on your device only
Personas, memories, profileStored on our serversStored on your device only
Vault documentsFiles in Cloudflare R2; metadata in D1Stored on your device only
LLM API keysNot applicable (we use a server-side key)Stored in the macOS Keychain on your device
Inference routingThrough our servers to the LLM Service ProviderDirectly from your device to your configured provider
Account profile & billingRequired; stored on our serversNot required to use core features

4. Information We Collect

We collect only what is necessary to operate the Service. Specifically:

4.1 Account information

When you create an Account, we store your email address, display name, profile picture URL (if provided by your sign-in method), account creation date, and most recent sign-in date. We use this to identify your Account and to communicate with you about the Service. We do not sell or share this information for marketing.

4.2 Web-app User Content

To make the web app work across sessions and devices, we store on our servers: your conversation titles and message text, your personas and memory blocks, your vault document metadata (with the underlying files in Cloudflare R2), your usage settings, and your credit balance. We do not read or log message content for any purpose other than serving your sessions, providing support you request, debugging service-level errors, and protecting the Service against abuse. We do not use your User Content to train any machine-learning model.

4.3 Subscription and payment information

If you subscribe to Plus or Pro, or buy a credit pack, payments are processed by Stripe, Inc. We do not receive or store full payment card numbers, CVVs, or bank account details. From Stripe we receive: your subscription status and plan tier, billing history (amounts, dates, invoice identifiers), the last four digits and brand of the card or other payment method, and your billing country (used for tax determination). Stripe's processing is governed by the Stripe Privacy Policy.

4.4 Usage metering

To meter credit consumption, our servers record per-request metadata: the model identifier used, the input and output token counts, the credit cost, and the timestamp. These records do not contain message content — only the size and shape of each request. They are used for billing accuracy, fraud and abuse prevention, capacity planning, and required tax/accounting reporting.

4.5 Support and feedback

When you contact legal@dequid.com or use any in-app reporting feature, we receive the content of your message, your email address, and any attachments you choose to include. Conversation content is never automatically included; only what you choose to send reaches us.

4.6 Diagnostic and error logs

To diagnose and fix bugs, our servers retain short-lived application logs (request IDs, status codes, error stack traces). Logs do not include message content. The Mac app writes crash and error logs to a file on your Mac; those logs are not automatically transmitted to us. If you submit a bug report from the Mac app, a redacted snapshot of recent diagnostic logs may be included; that snapshot does not include your conversations, prompts, AI outputs, API keys, or vault files.

4.7 Website server logs

When you visit dequid.com, our hosting provider automatically receives standard HTTP request information — IP address, browser user-agent, referring URL, requested path, response status, and timestamp. These logs are used for security, abuse prevention, and aggregate diagnostics. They are retained for up to 30 days.

4.8 Information we do not collect

We do not embed third-party analytics (such as Google Analytics, Mixpanel, Plausible, or PostHog), advertising trackers, behavioral profiling, fingerprinting libraries, or social-media pixels on the Service. We do not maintain background telemetry from the Mac app to our servers. We do not collect biometric information.

5. Information Stored Only on Your Device (Mac app)

By design, the following Mac-app data is stored exclusively on your device under ~/Library/Application Support/dequid/ (or the macOS Keychain) and is never transmitted to dequid's servers:

  • All conversation history and messages, including attachments inlined into prompts.
  • Extracted memories, profile facts, phrases, and context blocks.
  • Persona configurations, including identity, voice, scopes, and API parameters.
  • Knowledge Vault documents, snippets, and any People records.
  • LLM provider API keys (stored in the macOS Keychain, encrypted at rest by macOS).
  • Usage metrics, token counts, and cost estimates computed locally.
  • Application settings, preferences, and feature toggles.

You can export or permanently delete this local data at any time via Settings → Privacy & Data. Once deleted, we cannot recover it for you — we never had a copy.

6. How We Use Information

We use the information we collect only for the following purposes:

  • To provide the Service — authenticate your Account, deliver inference responses, persist your web-app history, meter credits, and process subscriptions.
  • To operate, secure, and improve the Service — detect and prevent fraud, abuse, and security incidents; debug errors; conduct internal analytics on aggregate, de-identified data; and develop new product features.
  • To communicate with you — send transactional emails (receipts, account notices, security alerts) and respond to inquiries. We do not send marketing email unless you opt in.
  • To comply with legal obligations — maintain financial records, respond to lawful legal process, and enforce our Terms of Service.

We do not use personal information or User Content to train any machine-learning model.

7. Legal Bases for Processing (EU/UK)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal information on the following legal bases:

  • Performance of a contract — to provide the Service you have requested (e.g., maintain your Account, process subscriptions, deliver inference).
  • Legitimate interests — to secure and improve the Service, prevent fraud and abuse, and protect our legal rights, where these interests are not overridden by your rights and freedoms.
  • Consent — for any processing based on consent (e.g., optional diagnostic uploads, marketing email). You may withdraw consent at any time without affecting prior processing.
  • Legal obligation — to comply with applicable law (e.g., tax and accounting obligations).

8. How We Share Information

We do not sell or rent personal information. We do not “share” personal information for cross-context behavioral advertising as defined under California law. We disclose information only:

  • To service providers who process information on our behalf under written agreements that restrict their use of the information (see Section 9).
  • To the LLM Service Provider, when our servers route your web-app request for inference (see Section 10), and — for the Mac app — to any provider whose API key you configure.
  • To comply with law or protect rights, including in response to a lawful subpoena, warrant, court order, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of dequid, our users, or the public.
  • In connection with a corporate transaction, such as a merger, acquisition, financing, reorganization, or sale of all or part of our business. We will notify users of any such transfer affecting their information.
  • With your consent, for any other purpose disclosed to you at the time.

9. Sub-Processors

We rely on a small number of carefully selected service providers to operate the Service. Each is bound by contractual obligations to protect personal information and to use it only for the purpose for which we engaged them.

Sub-processorPurposeLocation
Cloudflare, Inc.Web-app hosting (Workers/Pages), database (D1), object storage (R2), CDN, and DDoS protectionUnited States (global edge)
Stripe, Inc.Payment processing for subscriptions and credit packsUnited States
Google LLCOAuth sign-in (where used)United States
LLM Service Provider (currently OpenRouter, Inc.)Model routing for web-app inference. Requests are forwarded with model identifier, prompt, and conversation context; responses are returned and persisted to your conversation history.United States

This list may change as we add or replace providers. Material changes will be reflected here and, where required, communicated to users.

10. LLM Service Provider and Inference

Web app. When you send a message on the web app, our servers forward the request — including the model identifier, prompt, and conversation context required for the model to respond — to the LLM Service Provider, which selects the underlying model and returns the response. The LLM Service Provider may, in turn, route the request to an upstream model operator (e.g., Anthropic, OpenAI, Google). Each operator processes the request under its own privacy notice. We have selected providers that contractually do not use forwarded content to train their models; we do the same.

Mac app. When you use the Mac app with your own provider API key, the request is made directly from your device to that provider; dequid's servers do not see, log, intercept, or proxy that traffic. Your data with that provider is governed by its policy. The most common providers' policies are:

11. International Data Transfers

dequid is based in the United States, and our sub-processors are primarily located in the United States. If you access the Service from outside the United States, the information we receive will be transferred to and processed in the United States, which may not provide the same level of data protection as your jurisdiction. For transfers of personal information from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards as required by applicable law, which may include the European Commission's Standard Contractual Clauses (and the UK Addendum) entered into with our sub-processors, and on supplementary measures as appropriate.

12. Data Retention

We retain personal information only for as long as needed to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements.

CategoryRetention period
Web-app User Content (conversations, personas, memories, vault metadata)Retained until you delete it; deleted within 30 days of Account closure.
Vault files (Cloudflare R2)Retained until you delete the corresponding document; deleted within 30 days of Account closure.
Account profile (email, name, picture URL)For the life of your Account; deleted within 30 days after Account closure.
Subscription & billing recordsUp to 7 years after the final transaction (tax/accounting requirement).
Usage-metering records (model IDs, token counts, credit deductions)Up to 24 months for fraud, audit, and accounting purposes.
Support emails and submitted log snippetsUp to 12 months from last activity on the ticket.
Server diagnostic logsUp to 30 days.
Website server logsUp to 30 days.
Mac-app data on your device (conversations, memories, vault, API keys)Retained on your device until you delete it. We never receive it.

We may retain information longer if required by law, to resolve disputes, or to enforce our agreements.

13. Security

We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit using TLS, encryption at rest where supported by our infrastructure (including macOS Keychain encryption of API keys on your device), least-privilege access controls, regular review of our security practices, and isolation of customer data by Account. No system is perfectly secure; we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and applicable regulators as required by law. Suspected security issues may be reported to legal@dequid.com.

14. Your Privacy Rights

Regardless of where you live, you may:

  • Access and download your Account information by emailing legal@dequid.com.
  • Correct inaccurate Account information by updating it in the web app or contacting us.
  • Delete your Account and any server-side data we hold about you by emailing legal@dequid.com. We will action verifiable requests within 30 days, subject to legal-retention obligations.
  • Delete all Mac-app data on your device via Settings → Privacy & Data → Delete all my data. (We never had this data; we cannot do it for you.)
  • Unsubscribe from any non-transactional email using the link in that email or by contacting us.

You may also lodge a complaint with your local data-protection authority.

15. California Residents (CCPA / CPRA)

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides California residents with specific rights regarding personal information. This section supplements the rest of the Policy.

15.1 Categories collected, sources, purposes, and disclosures

In the preceding 12 months we have collected the following categories of personal information about California residents, as defined by California law:

  • Identifiers — name, email address, account ID, IP address (server logs).
  • Customer records — Account profile, subscription and billing records.
  • Commercial information — products subscribed to, credit packs purchased, billing history.
  • Internet activity — server logs from visits to dequid.com, web-app request metadata.
  • User-provided content — web-app User Content (conversations, personas, memories, vault).
  • Inferences — none drawn for profiling or advertising purposes.

Sources: directly from you, from your device, and from our service providers (Stripe, sign-in providers, hosting). Business or commercial purposes: to provide and secure the Service, process payments, meter usage, respond to support requests, and comply with legal obligations. We disclose personal information only to the sub-processors listed in Section 9 and as described in Section 8.

15.2 No “sale” or “sharing”

We do not sell personal information, and we do not “share” personal information for cross-context behavioral advertising. We have not done so in the preceding 12 months.

15.3 Sensitive personal information

We do not collect sensitive personal information for purposes other than those permitted without a right-to-limit, as defined by California regulations.

15.4 Your California rights

  • Right to know the categories and specific pieces of personal information we have collected about you, the sources, purposes, and recipients.
  • Right to delete personal information we have collected from you, subject to certain exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing (not applicable; we do neither).
  • Right to limit the use and disclosure of sensitive personal information (not applicable; we do not engage in such uses).
  • Right to non-discrimination for exercising your privacy rights.

To exercise these rights, email legal@dequid.com. We will verify your request, typically by confirming control of the email address associated with your Account, and respond within the timeframes required by law (generally 45 days, extendable by an additional 45 days when reasonably necessary). You may use an authorized agent, subject to verification.

16. EU, UK, and Swiss Residents (GDPR / UK GDPR)

If you are located in the EEA, the UK, or Switzerland, you have the following rights, subject to the conditions and limitations set out in law:

  • Right of access — obtain a copy of the personal information we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete information.
  • Right to erasure — request deletion of personal information where one of the conditions in Article 17 GDPR applies.
  • Right to restriction — request that we suspend processing in certain circumstances.
  • Right to data portability — receive personal information you provided to us in a structured, commonly used, machine-readable format.
  • Right to object — object to processing based on legitimate interests on grounds relating to your particular situation, and at any time to processing for direct marketing.
  • Right to withdraw consent, where processing is based on consent.
  • Right to lodge a complaint with your local supervisory authority.

You may exercise these rights by emailing legal@dequid.com. We respond to verified requests without undue delay and in any event within one month, extendable by up to two further months where necessary.

17. Other U.S. State Privacy Laws

If you are a resident of a U.S. state with a comprehensive privacy law granting you rights similar to those described above — currently including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, and others as enacted — you may exercise those rights (access, correction, deletion, portability, and opt-out where applicable) by emailing legal@dequid.com. We respond to verified requests within the timeframes required by applicable law, and we honor appeals where required.

18. Children's Privacy

The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact legal@dequid.com and we will take reasonable steps to delete it. In jurisdictions where the relevant age threshold is higher (for example, 16 in some EEA member states), we apply that higher threshold.

19. Cookies and Similar Technologies

The dequid website uses only strictly necessary first-party cookies (e.g., to remember your theme and to maintain a sign-in session). We do not set advertising, analytics, or social-media cookies, and we do not embed third-party trackers. The dequid Mac app does not use cookies; it stores its preferences locally in its own database.

20. “Do Not Track” Signals

Because we do not engage in cross-site tracking, no special handling of Do Not Track signals is necessary. Global Privacy Control signals received through our website will be treated as a valid request to opt out of “sale” and “sharing” — although we engage in neither.

21. Automated Decision-Making

We do not use personal information to make automated decisions that produce legal or similarly significant effects about you. AI outputs generated through the Service are produced by third-party LLM Service Providers in response to prompts you initiate; you remain in control of how those outputs are used.

22. Third-Party Links

The Service may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policy of any third-party site or service you visit.

23. Changes to This Policy

We may update this Policy from time to time. For material changes, we will give reasonable advance notice — generally at least 30 days — by updating the Effective date at the top of this page and, where appropriate, by sending an email to the address associated with your Account or by displaying an in-app notice. Continued use of the Service after the new Effective date constitutes acceptance of the updated Policy.

24. How to Contact Us About Privacy