What we keep, and what we don't
Last updated 4 August 2026. Written in plain language β if anything here is unclear, ask and we'll fix the wording.
What we store
Only what the desktop needs to work:
- Your account β email address, and either a password (stored as a salted scrypt hash, never in readable form) or a Google account ID if you signed in with Google.
- Your profile β the name and description you or the Terminal write, and your avatar if you generate one.
- Your apps β each app's brief, its conversation with you, the window it draws, its journal and status.
- Your files β anything you upload to My Documents and anything your apps write there, plus the shared Library your agents read and write.
- Housekeeping β notifications, the activity log, credit balance and spending totals, your wallpaper, and the layout of your windows.
Before you make an account, your computer already exists β held to your browser by a single session cookie, with the AI switched off. If you never sign up, that data stays anonymous: an email address is the only identifying thing we ever ask for.
Who else touches it
We use a small number of outside services, and only for the job named:
- OpenRouter (routing to the AI models) β receives the text your agents work with: their instructions, your conversations, and whatever content they are processing on your behalf. This is what makes an agent able to think; there is no way to run the product without it.
- Exa β receives search queries when an agent searches the web. It sees the query, not your identity.
- Resend β sends verification and system emails. Sees your email address.
- Stripe β handles payment when you top up credit. Card details go straight to Stripe; we never see or store them.
- Google β only if you choose to sign in with Google, and only to confirm who you are (your name, email and account ID). We ask for nothing else.
- Apple / Google push services β deliver notifications to your device if you enable them. They carry the notification text.
What we can promise, and what we can't. We don't train anything on your data, we don't sell or rent it, and we share it with nobody beyond the services listed above. We have no analytics, no tracking pixels and no third-party scripts of any kind.
We can't make that promise for the whole chain. The AI model provider we currently use β chosen because its pricing is what makes the free credit go a long way β retains the text sent to it and may use it to improve their models. So assume that anything your agents read or write could be kept by that provider. A good rule: if you wouldn't paste it into a chatbot, don't point an agent at it. That includes the mail an email app reads for you.
We'd rather say this plainly than bury it in a subclause. Routing to a provider that keeps nothing costs meaningfully more per run; if you'd want that as an option, say so on the BBS β it's useful to know whether people would pay for it.
What is public
Two things, and only when you choose them:
- BBS posts β visible to everyone on the system, with your profile name, avatar and computer number.
- Published apps β when you publish an app to the App Store, you share its recipe: name, icon, description and window design. You review and edit that text before it goes out. Your data, conversations, files and connected accounts are never part of it, and installing someone's app never gives them anything of yours.
Everything else is private to your computer.
Connected accounts
If you connect a mailbox, Telegram or Slack, those credentials are stored on our server and are never shown to any AI model β the agents get the messages, never the keys.
There is a hard boundary in the code, not just in instructions: agents cannot send anything. Email access is strictly read-only β reading a message never even marks it as read. Messages your agents prepare are saved as drafts for you to send, unless you explicitly switch a channel to automatic. Disconnect any of it at any time in My Computer β Connections; the credentials are deleted when you do.
Cookies
One cookie keeps you signed in (mc_session), plus a short-lived one during Google sign-in. That's the lot β no advertising or analytics cookies, because we have no advertising or analytics. Your window positions are remembered in your own browser's local storage and never reach us.
Where it lives, and for how long
Everything is stored on a server in Germany (Hetzner, Falkenstein). We keep your data for as long as your computer exists. Delete it and it's gone from the database and the disk immediately β we do not keep a shadow copy, and there is no recycle bin. Ordinary backups may hold a copy briefly before rotating out.
Your controls
- Clear chat histories β wipes every conversation with the Terminal and your apps, keeping the apps themselves. (My Computer β Privacy)
- Format C:\ β deletes the entire computer: account, apps, chats, documents, Library, connections, credentials. No undo, no recovery.
- Disconnect any mailbox or messaging channel, or disable push, at any time.
- Take your files β everything in My Documents downloads with one click.
If you're in the EU or UK, the rights you have under the GDPR β access, correction, deletion, portability, objection β are exercised by those buttons, and by writing to us for anything they don't cover.
Changes and contact
If this policy changes in a way that affects what happens to your data, we'll say so on the desktop rather than quietly editing this page.
Questions, requests, or something here that doesn't match what you observe: privacy@mycomputer.cloud.
What is this place? Β· mycomputer.cloud