Privacy Policy

How More AI handles your data. Desktop work is local-first; Chrome, sync, web, mobile and cloud features process the data needed for the features you choose.

Last updated September 27, 2026

This Privacy Policy explains what information More AI ("More AI", "we", "us", or "our") collects, how we use it, and the choices you have. It applies to our website at more-ai.net, the More AI desktop, web, and mobile applications, More AI for Chrome, optional cloud features, and any paid plan or credits made available to you (together, the "Service").

More AI is an independent software project, operated and published by its founder. Where you buy a paid plan, the seller is Paddle.com Market Limited, which acts as merchant of record and is identified in full on your receipt and invoice. You can reach us at the contacts in the "Contact us" section below.

The guiding principle of the Service is data minimisation. The More AI desktop app is local-first: conversations, code sessions, and project files have a local copy on your device. While you are signed out of the desktop app, supported work there does not sync to More AI. On a new installation, the individual sync categories are switched on and begin syncing supported data after you sign in; you can switch any category off in Settings. Server-side cloud execution is a separate control and remains off until you enable it. In a local desktop run with your own API key, model requests go directly from your device to the provider, subject to the telemetry disclosure below.

A quick summary

We have written the full detail below, but in short:

  • You can use the More AI desktop app locally without an account. An account is required for cross-device sync, web and mobile access, server-side cloud execution, paid plans, and credits.
  • In a local desktop run with your own API key, prompts and AI responses travel directly between your device and the provider you chose (for example Anthropic, OpenAI, or Google), and the key stays in your device’s secure storage. If you explicitly use server-side cloud execution, you may store a provider key with us so our systems can run that work on your behalf.
  • More AI for Chrome can run without the desktop app. In that mode, you sign in, provide a key for a supported provider or a compatible endpoint, and choose a model. Your key is encrypted in our account vault; browser task requests pass through our servers to the provider you selected. This is distinct from a local desktop run and does not depend on the desktop cloud-execution switch.
  • If you use credits or free pooled model access, you are using model access we provide. Those requests do pass through our servers on their way to the upstream provider. We pass them through — we do not store the prompts or the responses — but they are technically visible to our systems in transit, so treat them as you would any hosted AI service.
  • In the desktop app, conversations, code sessions, and project files have a local copy on your device. While you are signed out, supported work does not sync. After you sign in, the supported sync categories that are enabled in Settings upload the data they cover; those category switches start on in a new installation. Cloud execution is separate and stays off until you enable it.
  • Synced messages and, by default, synced Cowork files are stored in a form our systems can read. Cowork has a separate optional end-to-end-encryption setting; when you enable it, file contents are uploaded as ciphertext we cannot read, although file names and paths remain readable and web access may be limited.
  • We collect a description of the computer you run the app on (operating system, processor, graphics, memory, display, disk) so we can fix performance problems on real hardware. It describes the machine and does not identify it or you — no hostname, user name, MAC address, or serial number — and it is off entirely if you turn telemetry off.
  • Payments are handled by Paddle, which is the merchant of record and the seller you contract with. We never see or store your card details.
  • Curated product events and redacted error reports are designed not to include your content. Separate session replay can capture content already rendered in the desktop or web app, and a separate, default-on AI-observability setting can send full agent-run traces — including prompts, responses, reasoning, and tool inputs and results — for both BYOK and More AI model runs. Turn off AI Observability to stop future content traces, or turn off the master telemetry switch to stop both telemetry and replay.
  • We do not sell your personal data, and we do not use your content to train AI models.

Who we are (data controller)

For the personal data described in this policy, More AI is the data controller. More AI is an independent project run by its founder rather than a corporate group, and it is the single point of contact for everything in this policy — every request reaches a person who can act on it. If the Service is later transferred to a company formed or acquired to operate it, that company becomes the controller, and we will name it here.

Paddle.com Market Limited acts as the merchant of record for purchases and is an independent controller of the billing data it collects from you. See "Payments and billing" below.

For privacy questions or to exercise your rights, contact us at privacy@more-ai.net.

Information we collect

We collect only what a given feature needs. If you run the desktop app locally without an account, use your own API key, turn telemetry off, and do not use pooled or server-side features, you share no prompts, project content, or account data with us. Your device still contacts our release infrastructure when it checks for updates.

The sections that follow describe each category, when it applies, and how to avoid it.

Account information

If you create an account (optional for local desktop work; required for cross-device sync, web and mobile access, server-side cloud execution, paid plans, and credits), we process your email address, which we use for passwordless sign-in. We do not store passwords. When you request a sign-in code we generate a one-time 6-digit code (and a fallback link) that expires within about 15 minutes.

If you provide them, we also store your display name and avatar. When you sign in we create a session (a signed token valid for up to 30 days, which you can revoke by signing out), a record of the device you signed in from — its name, operating-system platform, and the app version — and your time zone, so scheduled features run at the right local time. We do not store your IP address or browser user-agent against your account; an IP address is used transiently only to apply rate limits and is not retained.

Your prompts and AI content — two different paths

How your prompts travel depends on whose model access you use, and the difference matters, so we describe both.

Your own API key in a local desktop run (bring your own key). When you use your own key locally, the model request — your prompts, attached files, and the provider's response — travels directly between your device and that provider rather than through our model proxy, and the key is stored encrypted on your device using your operating system's secure key storage. The provider processes that content under its own privacy policy and terms. Separately, if desktop telemetry and AI Observability are on, clipped copies of the run content can be sent to our analytics provider as described under Diagnostics.

Model access provided by More AI through credits or a free pool. When you use a model we provide rather than one of your own keys, your device sends the request to our servers, which forward it to the upstream provider under our credentials and stream the answer back. We do not write the pass-through request or response to our product database or use it to train models. It is nonetheless processed by our systems in transit, and the upstream provider we route to (see "How we share information") receives it. Diagnostic copies can also be sent to PostHog while AI Observability is on. To keep a BYOK prompt out of our systems, run it locally, turn off AI Observability (or all telemetry), and do not use sync, replay-enabled surfaces, or a server-side feature for that work.

For billing and abuse prevention we do record metadata about each pooled request: the time, the model, the number of input and output tokens, the computed price, and your user ID. That record contains no prompt or response text.

If you use an optional server-side ("cloud") execution feature, you may store a provider API key with us so we can make calls on your behalf. Such keys are encrypted at rest (AES-256-GCM). Because the Service must use them to reach the provider, they are technically readable by our systems; we use them only to operate the feature you enabled. To keep a key and its requests off our servers, use that key only in local desktop runs and leave cloud execution off.

More AI for Chrome

The Chrome extension has two paths. For standalone use, you sign in to your More AI account with an email code or approval from another signed-in device. The extension keeps a revocable account session in Chrome extension storage restricted to trusted extension contexts. When you connect an API key for a provider in the catalog or a custom OpenAI- or Anthropic-compatible HTTPS endpoint, the key is sent over HTTPS to your encrypted account vault. It is not stored in Chrome. We use that key to call the provider and model you select; the provider processes the request under its own terms and privacy policy.

When you ask the standalone browser agent to work on a page, it can read the URL, title, visible top-level page text and interactive controls of the tab you selected, and the tabs it opens for that task. It asks you before accessing each new site. Your instruction, the page information needed for the task, action results and model responses travel through our servers to and from your selected provider. Browser clicks, typing and scrolling happen in Chrome. The extension does not continuously collect your browsing history or read unrelated tabs for a standalone task.

Standalone Chrome chats and messages, including the provider and model used, sync to your More AI account and are stored in a form our systems can read; a reply that could not be synced immediately may remain in extension storage for retry. If you pair the extension with the desktop app, browser task data instead goes through the local desktop bridge and its permission controls. The desktop path uses the keys and model routing configured in the desktop app; its optional sync and diagnostics follow the desktop settings described in this policy.

Our use of information received from Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use browser data for the browser assistant you invoke and related security and reliability, not for personalized advertising or creditworthiness, and we do not sell it.

Two more features route through our servers when you use the versions we provide rather than your own credentials.

  • Dictation — if you use the built-in "More AI" speech-to-text provider, the audio you record is uploaded to our servers and forwarded to a transcription provider, which returns the text. We do not store the audio or the transcript; both exist only for the duration of the request. If you configure your own transcription provider instead, the audio goes directly there.
  • Web search — if you use the in-app web search on our pooled access, your search query is sent to our servers and on to the configured search provider. We do not retain the query; we record only that a search happened, for rate limiting and billing.

Information about your device and hardware

The desktop app reports a description of the computer it runs on. Knowing what hardware people actually use is what lets us tell a real performance regression from a slow machine, decide which graphics paths are worth supporting, and reproduce a bug on something like the affected system. This report is part of diagnostics: it is governed by the same consent as all other telemetry, and if you turn telemetry off in Settings → Privacy it is never sent.

The report describes the machine. It is deliberately built so that it cannot identify the machine or you: it contains no hostname, no user or account name, no MAC or network address, no disk, board, or device serial number, no licence key, and no IP address. Values are coarse (memory is rounded to a sensible step, disk space to whole gigabytes) for the same reason. Where a device model identifier is available it is the product model — the same string every unit of that model reports — never a serial.

It is sent when it changes, not on every launch: the app keeps a fingerprint of the values and sends a fresh report only when something differs or the previous one is about 30 days old. The report contains:

  • Operating system — name and version, kernel or build number, processor architecture, the system interface language, your time zone, and whether the app is running under ARM translation (such as Rosetta).
  • Processor — model name, vendor, number of logical cores, and clock speed.
  • Memory — total installed RAM, rounded.
  • Graphics — vendor, model, driver version, how many GPUs are present, the device model identifier where the system publishes one, and whether hardware acceleration, WebGL, WebGPU, and hardware video decoding are available.
  • Display — how many screens are attached, the primary display's resolution in physical pixels, its scale factor, refresh rate and colour depth, and whether a built-in panel is present.
  • Power and storage — whether the computer is currently running on battery, and the total and free space on the volume that holds the app's data (so we can warn you before a full disk breaks something).
  • Software versions — the Electron, Chrome, and Node versions the app is built on, and whether this is a packaged release or a development build.

Diagnostics: telemetry, analytics, and error reports

We use two different diagnostic channels. Ordinary product telemetry records usage metadata and redacted errors; AI Observability records content-level agent traces. Both are on by default after desktop setup. You can turn off AI Observability on its own, or turn off "Send anonymous usage data" in Settings → Privacy to stop both channels. The web app uses similar analytics and session replay as described below. We do not intentionally send API-key values through either channel.

  • Install pings — a randomly generated device identifier, your platform, and the app version. Analytics may be associated with your user ID while you are signed in, and session identifiers can connect events within the same visit or app session.
  • Product events — the names of actions taken in the app (for example "app launched" or "settings opened") and a small set of non-content properties such as which mode or model was selected. If you are signed in, these may be associated with your user ID.
  • Device and hardware description — as set out in the section above.
  • Error reports — when the app hits an error, it sends a report whose message and stack trace are redacted on your device before sending, to remove file paths, keys, email addresses, and similar identifiers.
  • We use PostHog (a product-analytics provider) to process this data, including session replay in the desktop app, on our website, and in the web app. Form text is masked while you type. In the desktop and web apps, however, messages, responses, and tool output already rendered in the interface, as well as recorded console output, can appear in a replay. The marketing website has no conversation interface and does not record console logs.
  • AI Observability — for agent runs, including local runs with your own API key, we can record a trace containing the model and provider, token counts, cost, latency and status, plus clipped copies of the prompt, response and reasoning and each tool call’s arguments, result and error state. This content-level setting is on by default and is separate from ordinary product events. Turning AI Observability off stops future content traces; turning the master telemetry setting off stops both content traces and ordinary telemetry.

Payments and billing

Paid plans and credits are sold through Paddle.com Market Limited, which acts as the merchant of record — the seller you contract with and the party that takes the payment. Paddle collects and processes your payment details, billing name and address, country, and any tax identifier directly, as an independent controller under its own privacy policy and buyer terms. We never receive, see, or store your card number or bank details.

What we store on our side is the record of what you are entitled to and what you have used: your plan, the subscription and transaction identifiers Paddle gives us, the status and renewal date of your subscription, the amounts and currency of your payments, your credit balance and the ledger of how it was spent, and the metered usage those charges are based on.

We keep the records that tax and accounting law requires us to keep for as long as it requires — typically several years — even if you delete your account. See "How long we keep information".

Synced data (optional and configurable)

A More AI account is optional for local desktop use. On a new installation, supported sync categories are switched on and begin syncing their data after you sign in. You can turn each category off per device in Settings. Server-side cloud execution is controlled separately and remains off until you enable it.

  • Chat sync uploads your conversations (titles, messages, model and provider names, timestamps) to our servers so you can read them on other devices and in the web app. Synced chat content is stored in a form we can read (it is not end-to-end encrypted), so that the web app can display it. Please do not sync content you need to keep confidential from us.
  • Cowork sync uploads your project files. By default, synced file contents are not end-to-end encrypted and can be read by our systems and compatible web clients. If you turn on the separate Cowork end-to-end-encryption setting, file contents are encrypted on your device before upload and we store only ciphertext we cannot read; file names and paths remain readable metadata, and access from web or mobile clients may be unavailable or limited unless they have the required key.
  • Settings sync copies your preferences (theme, language, chat options, and the configuration — not the secrets — of your connectors) so a new device starts where the last one left off.
  • Locally stored API keys are not copied by settings sync. A key you separately provide for cloud execution is handled under the server-side key terms above. Supported conversations, Code work, routines, memory, and profile data may upload the state and results needed for each sync category that is enabled.

Linked devices and remote control

If you pair a phone or browser with a desktop to send it commands, each device generates its own cryptographic key pair. The private key never leaves the device that made it; we store only the public keys, the device identifiers, and a label you can recognise. Commands are signed by the sending device and verified by the receiving one, so the trust is in the signature rather than in anything we hold. You can unpair a device at any time.

Problem reports and surveys (optional)

If you choose to send a problem report, the app packages information you can review and toggle first — a description you write, a summary of your settings (with secrets removed), device and version details, and, only if you opt in, recent application logs (redacted) and selected project or repository files. We store the report so we can investigate the issue.

If you respond to an in-app survey, we store your answers and, only if you choose to provide it, a contact email.

Cookies and local storage

Our website and web app use browser storage to keep you signed in and remember preferences such as language and theme; the marketing website also sets an essential first-party cookie for the selected language, and our analytics provider may set cookies. On the marketing website, analytics starts when a page loads. Session replay starts only if you explicitly allow it in the notice; you can change either choice there or at any time through "Privacy choices" in the footer. The desktop and web apps expose their analytics controls in Settings → Privacy. Paddle sets its own cookies on its checkout, which runs on Paddle's domain. The desktop app stores its data in your operating system's application-data folder rather than in browser cookies. For full detail and your choices, see our Cookie Policy.

How we use information

We use the information above to:

  • Provide and operate the Service — sign you in, run cloud features you enable or model access available through the free pool or credits, sync your data across devices, and display it in the web and mobile apps.
  • Take payment and manage your plan — process purchases and renewals through our payment provider, meter your usage, apply your entitlements, and keep the accounting and tax records the law requires.
  • Maintain security and prevent abuse — apply rate limits, detect and block misuse, fraud, and payment abuse, and protect our infrastructure.
  • Diagnose problems and improve the product — understand which features are used, fix errors and crashes, and tune performance against the hardware people actually run.
  • Communicate with you — send sign-in codes and, where relevant, billing, service, or security notices.
  • Comply with legal obligations.

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to provide an account, a paid plan, sync, web and mobile access, and cloud execution you ask for, and to take the payment for them.
  • Legitimate interests — to keep the Service secure, prevent abuse and payment fraud, and improve the product through limited metadata diagnostics including the hardware description. You can object to analytics by turning telemetry off.
  • Consent — where required, for non-essential cookies and analytics, for AI-observability content capture, and for optional surveys. You may withdraw consent at any time.
  • Legal obligation — to keep tax, accounting, and transaction records, and where we must otherwise process data to comply with the law.

How we share information (sub-processors)

We do not sell your personal data and we do not share it for advertising. We use a small number of service providers ("sub-processors") to operate the Service, each acting on our instructions:

  • Cloudflare — hosting and infrastructure (compute, database, key-value and object storage, content delivery, and sending sign-in emails). Our data is stored on Cloudflare's global network.
  • Paddle.com Market Limited — merchant of record, payment processing, tax calculation and remittance, invoicing, and refunds. Paddle acts as an independent controller for the billing data it collects from you.
  • PostHog — product analytics, error tracking, and AI observability. Processed in the United States.
  • Model and infrastructure providers behind our own model access — when you use credits or free pooled access rather than your own key, we route the request to an upstream provider (currently OpenRouter, and Groq for dictation), which processes it under its own terms in order to return the answer.
  • Web-search providers — if you use the in-app web search, your query is sent to the configured search provider.
  • AI providers you choose (for example Anthropic, OpenAI, Google, or a compatible endpoint you configure) — they receive the prompts you send them directly, under your own key and their terms. They are not our sub-processors; you select and control them.

International data transfers

Our infrastructure and payment providers operate globally, including in the United States and the United Kingdom. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent mechanism offered by the provider. If you are outside the country where our providers store data, your information may be processed there.

How long we keep information

We keep personal data only as long as needed for the purpose it was collected:

  • Account data — until you delete your account or ask us to delete it.
  • Synced chats — until you delete them or your account; you control them from the app.
  • Cowork files — kept while your account is active; on free use, files expire about 7 days after they were last touched.
  • Billing and tax records — for the period required by applicable tax and accounting law (typically 6 to 10 years, depending on the jurisdiction), even after you delete your account. This is a legal obligation and is not affected by a deletion request.
  • Usage and metering records — while they are needed to operate and reconcile your plan, then aggregated.
  • Sign-in codes — about 15 minutes; device pairing requests — about 10 minutes.
  • Pass-through prompts and responses on our own model access are not written to the product database; dictation audio and search queries likewise exist in those request paths only for the request. If the same content is included in an AI-observability trace, tool span, or session replay, that diagnostic copy follows the diagnostics retention statement below.
  • Diagnostic events, AI-observability traces, session replays, error reports, and problem reports — retained for as long as they remain useful for security and product improvement, then deleted or aggregated. Turning a setting off stops future capture; it does not itself delete records already received, so contact us to exercise an applicable deletion right.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. You can update your name and avatar in the app, and turn diagnostics off in Settings. To make any other request, email privacy@more-ai.net; we will respond within the time the law requires. You also have the right to complain to your local data-protection authority.

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not use your personal data for profiling of that kind.

Where a request concerns data held by Paddle as merchant of record — for example your billing address or payment method — we will point you to Paddle, since we do not hold it.

Regional disclosures

Some jurisdictions require specific statements. Those that apply to us are set out here.

  • EEA and UK — you have the rights described above under the GDPR and UK GDPR, including the right to lodge a complaint with your supervisory authority. Requests and complaints reach us fastest at privacy@more-ai.net, which is our contact point for all data-protection matters. Where we are required to appoint a representative under Article 27 of the GDPR, we will do so and name it here.
  • California — under the CCPA/CPRA you have the right to know what we collect, to delete it, to correct it, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined, and we do not process it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights.
  • Switzerland and Brazil — the rights described above are available to you on an equivalent basis under the Swiss FADP and the Brazilian LGPD respectively.
  • Mainland China — the Service is not directed to users in mainland China. We have not appointed a local representative and we do not carry out the cross-border transfer formalities that the Personal Information Protection Law requires of an operator targeting that market. Our Chinese-language documents are provided for Chinese speakers generally, not as an offer of service in mainland China.
  • Russia — the Service is not directed to users in the Russian Federation. We do not store or process personal data on servers located in Russia and therefore do not meet the localization requirements of Federal Law No. 152-FZ. Our Russian-language documents are provided for Russian speakers generally, not as an offer of service in Russia.
  • If you access the Service from a jurisdiction we do not target, you do so on your own initiative and are responsible for compliance with local law.

Security

We protect data with encryption in transit (HTTPS/TLS) and with the security features of our infrastructure provider, including DDoS protection and a web application firewall. API keys are encrypted on your device, Cowork file contents are end-to-end encrypted when you enable that separate setting, stored cloud-execution keys are encrypted at rest, and the credentials behind our own model access never leave our servers.

No system is perfectly secure. As noted above, chat content you choose to sync is stored in a form we can read, and requests on our own model access pass through our infrastructure — so apply your own judgement about what you send and what you sync.

Children

The Service is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country, if higher) to create an account or buy a plan. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date at the top and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

Contact us

For privacy questions or to exercise your rights, email privacy@more-ai.net. For billing and refunds, email billing@more-ai.net. For other legal matters, email legal@more-ai.net.

Back to home