In short
- One only listens and looks at your screen while you are talking to it. It is not an always-on recorder.
- What you say, what is on your screen, and what your agents are showing are sent to AI providers to understand and act on your request. We do not keep a server-side archive of it.
- Product analytics never include the contents of your prompts, audio, screenshots, or terminal output. You can turn analytics off in the app.
- You can delete your account and everything associated with it by emailing support@getone.one.
Who we are
One (“One”, “we”, “us”) is a macOS application and companion services published at getone.one. The app lets you drive coding agents running on your Mac by speaking or typing to it. This policy covers the One macOS app, the One phone remote, the services behind them, and the getone.one website.
Questions or requests: support@getone.one.
What we collect
Account information
- Sign-in. When you sign in we receive your email address, display name, and avatar image from your sign-in provider. We use these to create your account, show who is signed in, and contact you about the service.
- Connected AI accounts. If you connect an AI provider account (such as ChatGPT) so that an agent can run on your plan, we keep an account identifier and plan tier for that account. We never see your password for that account, and the credentials stay on your Mac.
- Download signup. When you enter your email to download One we store that address and basic information about how you signed up, so we can send you release notes and product updates. You can unsubscribe at any time.
What One uses when you talk to it
Each time you speak or type a request, One works with:
- Your voice — the audio of the request you speak.
- Your screen — a capture of what you are looking at, so the model can see what you are pointing at.
- Your agents’ activity — what your coding agents are currently showing and recent context from their sessions on your Mac, so the model knows what each agent is doing.
- The exchange itself — the transcription of what you said, One’s response, and the instruction it passed to an agent.
This is what makes One work; there is no way to act on a spoken request without it. It is sent from your Mac to the AI providers we use to process the request. We do not build a server-side archive of your audio, screenshots, or terminal text.
Phone remote
When you pair a phone, One shares the names and status of your agents and short summaries of what they are working on, so you can pick one from your phone. Anything you type on the phone is relayed to your Mac. This state is held only while the remote is connected.
Product analytics
We collect usage events (such as completing onboarding or starting a request) together with app version, macOS version, and coarse device information, associated with your account. Analytics events never include prompt contents, transcripts, audio, screenshots, terminal output, file paths, or project names. You can opt out of analytics at any time in the app’s settings.
Crash and error reports
If the app crashes or hits an unexpected error, a report containing technical details about the failure, the app version, and the macOS version may be sent to us. We try to keep prompt contents out of these reports.
Where it goes
We rely on third-party service providers to run One. Each receives only what it needs for its role and is bound by its own terms and data-processing commitments. They fall into these categories:
- AI providers that process your voice, screen, agent context, and requests.
- Infrastructure providers that host our services, store account data, and relay traffic between your devices.
- Analytics and email providers that receive the analytics events and download-signup information described above.
Some of these providers are located in the United States. By using One you acknowledge that your data will be processed there. We rely on the providers’ standard contractual protections for international transfers.
How long we keep it
- Voice and screen captures are used for the request at hand and are not retained on our servers. Copies on your Mac are removed automatically shortly afterwards.
- Phone remote state is cleared when the remote disconnects.
- Sign-in sessions expire after a period of inactivity. Signing out ends them immediately.
- Account and download-signup information is kept until you delete your account or ask us to remove it.
- Analytics events are kept in aggregate for product analysis; identifiers are removed when you delete your account.
- Crash reports are kept for up to 12 months.
What stays on your Mac
Your conversation history with One, the working memory it builds up, summaries of your agent threads, your settings, and the credentials for connected accounts are stored locally on your Mac and are not uploaded to our servers. You can remove them at any time from within the app or by deleting the app’s data folder. One reads, but does not modify, the files your coding agents keep for themselves.
Your choices and rights
- Permissions. One only works with the macOS permissions you grant (Microphone, Screen Recording, Accessibility, Automation). You can revoke any of them in System Settings → Privacy & Security at any time.
- Analytics. Turn analytics off in the app’s settings.
- Sign out. Signing out ends your sessions and removes your credentials from your Mac.
- Delete your account and data. Email support@getone.one from the address you signed in with. We will delete your account, sessions, email signup, and analytics identifiers within 30 days and confirm by email.
- Access and correction. You can ask us for a copy of the account data we hold about you, or to correct it, at the same address.
If you are in the EU, UK, or another region with data-protection law, you may also have the right to object to or restrict certain processing, to data portability, and to lodge a complaint with your local supervisory authority. Our legal basis for processing is performance of the service you asked for, and our legitimate interest in keeping it secure and improving it.
Security
Traffic between the app, the website, and our services is encrypted in transit. Credentials are stored using the secure storage built into macOS. Access to our systems is limited to the people operating the service. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
Children
One is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
One is in beta and this policy will change as the product does. We will post the new version here with an updated effective date, and notify signed-in users in the app or by email when the changes are material.