Scope
This policy covers the official NativeAgent applications distributed by the project. NativeAgent is a personal agent for macOS with an optional iPhone and iPad companion. The Mac owns the agent runtime; the mobile app connects to that Mac through the user's private Apple account and is not a separate hosted agent.
Modified or third-party builds may behave differently and are governed by their publisher's policy.
What the project operator collects
The official apps do not include developer-operated advertising, analytics, behavioral profiling, or cross-app tracking. Installing or using NativeAgent does not send the project operator a copy of conversations, memories, files, credentials, tool results, or usage telemetry.
NativeAgent keeps local diagnostics, receipts, and bounded runtime measurements on the user's own devices. They are not automatically uploaded to the project operator. If a user voluntarily sends a support report, the operator receives only the information the user chooses to include and uses it to respond.
Data processed on your devices
Depending on the features you enable, NativeAgent may store or process:
- conversations, attachments, generated content, and session summaries;
- persona settings, memories, skills, preferences, and relationship context;
- tool inputs and outputs, approvals, receipts, tasks, and diagnostics;
- provider and connector configuration, credentials, and pairing material;
- files and work products you ask NativeAgent to read or create; and
- notification-delivery and device-sync state.
The Mac stores its canonical runtime data locally. Sensitive credentials use Apple Keychain where implemented or owner-only local files. Mobile pairing material is kept in protected app storage and the Apple account's private sync plane.
AI providers, connectors, and websites
NativeAgent does not provide a hosted model service. When you connect and use an AI provider, the Mac sends that provider the content needed for the request. That can include conversation text, relevant context, attachments, and bounded tool results. The provider processes that data under its own terms and privacy policy.
Optional email, calendar, messaging, source-control, document, search, social, and other connectors work the same way: data needed for the operation is exchanged with the service you chose. Those services are independent data controllers. Websites NativeAgent opens or retrieves may receive ordinary network information such as an IP address and user agent.
iCloud, CloudKit, and notifications
When Mac/iPhone continuity is enabled, signed messages, compact snapshots, pairing state, action receipts, and related records move through Apple iCloud or the app's CloudKit private database. They are associated with the user's Apple account and governed by Apple's terms and privacy policy. NativeAgent does not use a public CloudKit database for personal agent data.
Apple Push Notification service may process a device token and bounded notification payload so the phone or tablet can be notified of activity. Notification previews may reveal content according to the user's lock-screen settings.
Permissions
NativeAgent asks for protected access only when a corresponding feature needs it. On mobile this can include microphone, speech recognition, selected photos, and notifications. On Mac, optional integrations can request Calendar, Reminders, Contacts, Mail, Messages, Notes, Music, Accessibility, Screen Recording, or Automation. Apple controls these prompts, and users can review or revoke access in system settings.
Tracking, advertising, and sale
NativeAgent does not use advertising identifiers, track users across other companies' apps or websites, or sell personal information.
Retention and deletion
Local data remains until the user removes it, a configured retention rule expires it, or a bounded subsystem consolidates it. Removing local data does not erase independently created provider logs, external records, exported files, backups, or previously delivered messages.
Users can disconnect the mobile companion from its Settings, then delete the app to remove its local container. Mac data can be removed by quitting NativeAgent, uninstalling the app, and deleting unwanted NativeAgent Application Support and workspace files. Apple-account sync data, backups, and provider-side records must be removed through those services. Keep any wanted backup before deletion.
Security, children, and changes
NativeAgent uses signed device messages, local trust and approval boundaries, and Apple platform protections, but no software can guarantee absolute security. Broad Mac permissions and autonomous tool access increase risk.
NativeAgent is a general productivity tool and is not directed to children.
Material policy changes will be published here with a new effective date.
Contact
For a privacy or security matter, send a private report through the project's security advisory form . Do not include credentials, pairing keys, private prompts, or personal files in a public issue.
