Privacy Policy
Effective Date: September 18, 2026
Dessix Ltd. (“we,” “our,” or “us”) respects your privacy. This Policy explains how information moves through Ducoro’s local-first Space runtime, on-device voice input, cloud account and remote-access services, connectors, optional paid AI services, problem reports, and limited product measurement and error monitoring.
1. Scope and who controls your data
This Policy applies to ducoro.ai, the Ducoro desktop application and CLI, the Ducoro Gateway, and related services. Dessix Ltd. is the controller of personal data held for Ducoro accounts, billing, communications, and service operation. A third-party AI, connector, or account provider may act as a separate controller under its own terms when you choose to use that provider.
2. Information we process
Account and profile information
- Your email address, display name, profile text, avatar reference, sign-in methods, and email verification state.
- Onboarding information you submit, such as your role, intended use, how you found Ducoro, contact channels, and separate choices for research invitations and product updates.
- Authentication and security records, including password hashes, hashed six-digit email sign-in codes and short-lived action tokens, sign-in method events, and rate-limit records. Plaintext passwords, sign-in codes, and one-time action tokens are not stored.
Google Sign-In data
When you choose Google Sign-In, Ducoro requests the openid, email, and profile scopes. Google provides your Google account identifier, email address, email-verification status, display name, and profile image. We use this information only to create, secure, link, and sign you into your Ducoro account and to display your account identity.
Ducoro does not request access to Gmail, Google Drive, Google Calendar, contacts, or other Google Workspace content through Google Sign-In. We do not use Google user data for advertising, sell it, or use it to develop, improve, or train generalized or non-personalized AI or machine-learning models.
We store the Google account identifier and the account and profile fields above while your Google sign-in method or Ducoro account remains active. We share them with Google for authentication and with the service providers identified in Section 5 only as needed to operate Ducoro. You can unlink Google in account security settings or request deletion of your cloud account data as described in Section 7.
Ducoro’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Local Space and agent data
Spaces, timelines, agent memory, local folders, credentials, and runtime-native sessions are stored on the device running your Ducoro daemon. They remain under your control in local files until you edit or delete them. We may read and send the portions you direct an agent to use when performing a request.
Voice input and speech models
Microphone audio and speech-recognition context are processed on your device using Apple Speech or a local speech model. The transcription session and native helper do not retain the audio or recognized text after the session closes. Recognized text is placed into your draft and becomes Space content only when you choose to send it. Your device may download speech or model assets from Apple, ModelScope, or Hugging Face; those services receive the ordinary network information needed to deliver the files, such as your IP address and request metadata, but they do not receive your microphone audio from Ducoro.
Device and relay information
When you pair a device, we keep its Ducoro device identifier, name, platform, hostname, last-seen time, revocation state, and public encryption key. Browser-to-device traffic uses an end-to-end encrypted relay. The Gateway routes encrypted frames and maintains connection metadata; the private key needed to open those frames remains on your device.
A remote session may also establish a direct WebRTC path between your browser and paired device on the same network. The encrypted connection negotiation can include local-network address candidates and cryptographic fingerprints. It passes through the existing end-to-end encrypted session, is used only to establish that session, and is not stored by the Gateway. If the direct path is unavailable, traffic continues through the encrypted relay.
Product measurement and error diagnostics
To understand whether Ducoro is reachable and reliable and which capabilities are used, we send limited first-party product events through the Ducoro Gateway to PostHog Cloud EU. Depending on the event, this can include internal account and device identifiers; service, release, and platform; account and device lifecycle or presence state; Space lifecycle; message role and actor type; run, automation, and inbox status; runtime and model; token counts or buckets; duration; error code; and timestamp.
Product events do not contain message bodies, prompts, responses, reasoning, tool inputs or results, headers, cookies, environment-variable values, URL queries, or absolute local paths. Error reports can include an error type, a fixed content-free message, structural stack-frame locations and source-map identifiers, failure mechanism, and handled status. The original error message and stack first line are not uploaded; absolute local paths are reduced before upload. PostHog autocapture, pageview, pageleave, Session Replay, person profiles, and GeoIP enrichment are disabled for this integration.
Problem reports and support context
When you or an agent choose to send a problem report, we store the report text together with the account and paired-device identifiers and a bounded diagnostic snapshot. The snapshot can include the submitting app, version, interface language, browser family, device platform, operating-system version, chip and memory class, installed agent runtime versions and sign-in state, subscription tier, configured model provider and model, broad endpoint location category, and whether a required credential is present. Timeline and conversation history, log files, prompts, responses, tool inputs, and tool results are not attached automatically.
Known credential shapes and URL query values are redacted before storage. Because local paths can be necessary to reproduce a fault, full local file paths may remain in a report when you include them. Reports are available to authorized Ducoro operators for support, security, and product diagnosis.
AI requests, connectors, and files
Ducoro is not a network-wide activity monitor or universal AI proxy. It does not capture activity in unrelated applications and does not receive a copy of every prompt, response, or tool call merely because Ducoro is running. Your local Space timeline and the selected runtime’s native session can still keep the execution record on your device as described above.
When you use an external runtime or a provider connection configured to communicate directly with an AI provider, request content is sent by software on your device through that selected provider path and does not pass through the Ducoro Gateway. Ducoro receives content only when you deliberately use a cloud-mediated Ducoro feature described in this Policy, such as the Built-in Agent, a connector, Web Search, Web Fetch, or a problem report. Encrypted remote-access frames can pass through the Gateway relay, but the Gateway cannot open their contents.
When you run an external runtime such as Claude Code, Codex, or Pi Agent, the runtime and AI provider you selected receive the prompts, file excerpts, tool inputs, and outputs needed to perform the run. When you use the Built-in Agent, the Ducoro Gateway forwards request content to our AI routing and model providers and streams the response back. We retain billing and operational metadata for that request, such as model, token counts, cost, status, and time; the Gateway billing ledger does not store prompt or response bodies.
The runtime or AI provider you select may independently log, retain, review, or use that data under its own terms, privacy policy, account plan, and data controls. Ducoro does not control those providers or promise how they handle data. Review the provider’s terms and settings before sending sensitive information.
If you connect an external service through Composio or another connector, Ducoro forwards the tool call you authorize and returns its result to the active Space. The connected service and connector provider process that data under their own terms.
When the Built-in Agent uses Web Search, Ducoro sends the search query to Brave Search and returns the selected titles, links, and snippets. When it uses Web Fetch, Ducoro sends the target URL to Tavily and returns extracted page content. The Gateway keeps content-free audit metadata for these calls but does not copy the query, target URL, results, or extracted content into its database or business logs. The tool request and result can remain in the runtime-native session on your device as part of the local execution record.
Billing, communications, and technical information
- Membership status, Stripe customer and payment references, wallet lots and balances, refunds, model usage, discounts, and billing ledger entries. Stripe receives your full payment-card details directly.
- Transactional email delivery records, marketing or research consent history, bounce and complaint status, and suppression records used to honor delivery choices.
- Standard request and security metadata processed by our hosting and network providers, including IP address, browser or client information, timestamps, and request status.
3. How we use information
- Provide accounts, authentication, device pairing, encrypted relay, and support.
- Run the agents, AI requests, and connector actions you initiate.
- Provide web search and web content extraction requested by the Built-in Agent.
- Operate memberships, wallet credits, metered Built-in Agent usage, and refunds.
- Receive and investigate problem reports you or an agent submit.
- Send transactional messages and the optional research or product communications you select.
- Measure aggregate product adoption, availability, performance, and resource use from explicit content-free product facts.
- Protect the service, prevent fraud and abuse, diagnose failures, and keep audits.
- Comply with law and establish, exercise, or defend legal claims.
4. Legal bases in the UK and EEA
- Contract: accounts, authentication, paired-device relay, agent or connector requests, paid features, and support you ask us to provide.
- Consent: optional research invitations and product communications. You can withdraw that choice in Ducoro settings or through the unsubscribe mechanism in an email.
- Legitimate interests: securing the service, preventing fraud and abuse, measuring product operation, diagnosing failures, and improving reliability, balanced against your rights and expectations.
- Legal obligations and claims: tax, accounting, regulatory requests, and establishing, exercising, or defending legal rights.
Account identity, authentication, paired-device, and payment information is required when you use the corresponding account, remote-access, or paid feature. Without it, we cannot provide that feature. Onboarding survey answers, research invitations, product updates, problem reports, Google Sign-In, connectors, voice input, and paid AI features are optional; you can use the parts of Ducoro that do not depend on them.
5. Service providers and disclosures
| Provider or category | Purpose |
|---|---|
| Cloudflare | Site hosting, Gateway, network protection, database, and storage |
| Optional account sign-in | |
| Resend | Transactional email, contacts, and email preferences |
| Stripe | Memberships, wallet payments, billing portal, and refunds |
| OpenRouter and model providers | Built-in Agent routing and AI inference |
| Composio and connected services | Connector authorization and tool execution |
| Brave Search | Built-in Agent web search |
| Tavily | Built-in Agent web content extraction |
| PostHog Cloud EU | Product measurement and error monitoring |
| Apple, ModelScope, and Hugging Face | Optional on-device speech and model asset delivery |
| Your selected runtimes and AI providers | External agent and model execution |
We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards. We do not sell personal information, use it for targeted advertising, or enable cross-site behavioral tracking. Our PostHog integration sends only the explicit first-party product and error events described above.
6. Cookies and local preferences
Ducoro uses cookies required for sign-in, session security, OAuth flows, and request protection. The web and desktop interfaces use local storage for device-level preferences such as theme, language, notifications, and navigation state. These technologies support the service rather than advertising. Product measurement is sent through the Gateway and does not add a PostHog cookie or Session Replay. Until the local daemon acknowledges delivery, the interface may keep up to 20 sanitized error facts in session-only browser storage; the buffer is cleared after acknowledgement or when the browser session ends.
7. Retention and deletion
- Local Space and runtime data remains on your device until you remove it.
- Account, device, connector, and membership records are kept while needed to provide the service and resolve account or security issues.
- Billing, refund, fraud-prevention, and audit records may be kept for tax, accounting, dispute, and legal requirements.
- Email suppression records may be retained as needed to keep honoring an opt-out or a delivery complaint.
- Product measurement and error events are retained only while needed to operate, secure, diagnose, and improve the service, subject to our PostHog project retention and deletion controls.
- Problem reports are retained until the related Ducoro account is deleted, unless we remove them earlier because they are no longer needed for support, security, or product diagnosis.
- Connector, web-search, and web-fetch audit metadata is kept while needed for service operation, account support, abuse prevention, and auditability, and is deleted with the related cloud account subject to the exceptions below.
To request deletion of cloud account data, contact us using the address below. We may ask you to verify the account and may retain limited records where law or a legal claim requires it. Email suppression records can remain so that we continue honoring an opt-out or delivery complaint. D1 Time Travel, access logs, and provider backups age out under the relevant infrastructure provider’s retention schedule. Removing cloud account data does not automatically remove files stored on your own devices or data held independently by a service you connected.
8. International transfers and security
Providers may process data outside the United Kingdom or EEA. Where required, we use an approved transfer mechanism such as Standard Contractual Clauses and the UK Addendum or rely on another lawful safeguard. Contact us to request a copy of the relevant transfer safeguards. We use access controls, encryption in transit, encrypted device relay, hashed credentials, and operational controls appropriate to the information involved. No security method can guarantee absolute protection.
9. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, or object to processing; receive portable data; withdraw consent; and complain to a data protection authority. Send requests to [email protected] with the subject “Data Subject Request.” We may verify your identity before acting. You may also complain to the UK Information Commissioner’s Office or the data protection authority where you live.
10. Children and changes
Ducoro is intended for people aged 16 or older. We may update this Policy as the service changes. The current version will remain posted here with its effective date, and we will provide additional notice when a material change requires it.
11. Contact
Data controller: Dessix Ltd. (company number 16167530). Email: [email protected]. Registered office: 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom.
Dessix Ltd. · Company number: 16167530 · Registered office: 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom.
Questions about this statement can be sent to [email protected].