Back to Toone

Privacy Policy

Updated: August 10, 2026

Toone is built around local organization files and working context. This policy distinguishes that local product data from information you choose to submit through the website, waitlist, contact form, or account service.

Local Product Data

Toone does not receive your local organization files or working context merely because you use the desktop app. That includes:

Information You Submit

We receive information you deliberately provide when you create or sign in to an account, join the early-access waitlist, or send a contact request. Depending on the action, this can include your name, email, company, message, and authentication data. Waitlist entries are sent to the Toone backend, contact requests are delivered to the team's communications system, and account data is processed by the Toone account service. We use this information to provide the requested service, respond to you, protect the service, and administer early access.

Website analytics events do not include form text, names, email addresses, passwords, authentication tokens, or account identifiers.

Anonymous Usage Analytics

The Toone desktop app sends anonymous usage telemetry (feature usage events such as "an organization was created" — never conversation content, file contents, prompts, or anything that identifies you) to our own self-hosted, privacy-focused analytics (Umami). Events are tied to a random per-install identifier, not to your name or email. You can turn this off at any time in Settings.

This website uses the same self-hosted, cookieless analytics to count visits and clicks. It sets no cookies, does not track you across sites, and does not share data with any third party.

Local-First Architecture

All conversations, files, and project data remain on your device. Toone does not upload that local working context to its account, website, or analytics services. Account data, waitlist requests, contact requests, and optional relay connections are handled separately as described in this policy.

Third-Party AI Providers

Toone connects to AI providers (such as Anthropic or OpenAI) by letting you connect your own Anthropic or OpenAI account. Authentication is handled through your terminal using each provider's CLI. When you send a message, it is transmitted directly from your device to the provider's API. Toone does not proxy, log, or retain these requests. Please refer to your chosen provider's privacy policy for how they handle your data:

Mobile Companion App

The Toone mobile app connects to a running Toone Desktop instance over a direct local-network WebSocket or the optional Toone cloud relay. The cloud-relay transport uses TLS plus application-level end-to-end encryption, so the relay forwards encrypted application frames rather than readable conversation or project content. AI execution and project access remain on the Mac.

Crash Reports & Diagnostics

Toone does not include any crash reporting or diagnostic SDKs. If you choose to report an issue via GitHub, any information you share is voluntary and governed by GitHub's privacy policy.

Updates

Desktop releases are distributed through GitHub Releases. The app may check for new versions by querying the GitHub API, which is subject to GitHub's privacy policy. No personal data is transmitted during this check.

Changes to This Policy

If we make material changes to this policy, we will update the effective date at the top of this page and note the changes in our release notes.


Contact

If you have questions about this policy, open an issue on our GitHub repository or reach out to the maintainers directly.

Toone is published by Hexagonal.io.