Data & privacy

Version 2026-09-19-draft · current version

What we collect

What you type at sign-up (name, email, country, phone), your picture if you add one, your conversations (including any photos you send in them), the canvases the assistant draws, the settings you choose, and records of which plugins you enabled and what they were asked to do.

Where it lives

In this preview everything above is stored on your device, in the app's own database. Sign-up details are not verified or sent anywhere yet. If a future version syncs to a server, we will ask first.

The assistant

Your messages, and the context the app adds to them (the current section, the tools available), are sent to the assistant provider configured for the build. The scripted assistant sends nothing. The Claude provider sends them to a proxy you run, and from there to Anthropic under their terms.

Photos

The camera's picture stays on your device until you keep it with Use this. Then a smaller copy (about 1100 pixels on its longest side, as a compressed JPEG, without location or other embedded details) is kept in the conversation on your device, and is sent to the assistant only with an instruction from you: what you say or type about it, or the purpose of the button that opened the camera. A photo you ask the assistant to take (with the camera open on your screen) goes to it straight away. A kept photo you don't ask about stays on your device, above the message box, until you ask or drop it. From there it goes the way your messages do: through the proxy to Anthropic, under their terms. Only the most recent photo in a conversation is sent again with later messages; earlier ones are only mentioned. QR codes are read on your device and are never sent.

Your photo gallery

Photos you keep, and ones the assistant takes at your request, are kept in the gallery on your device (Settings → Photos) until you delete them. Deleting a photo removes it from the gallery and from the conversations it was sent in; copies you saved to your phone's Photos stay there. The assistant can see the list (when and how each was taken, its size) at any time, and looks at a photo — sending a smaller copy to Anthropic — when you ask it about one. The first time it looks, it keeps a short written description of what it saw with the photo (shown in the preview); after that the description is sent instead of the photo. It cannot delete photos.

Voice

In voice mode, what you say is sent to Deepgram to turn it into text, and replies are sent to Deepgram to be read aloud, under their terms. The text then goes to the assistant like anything you type. Deepgram is reached through the same proxy, which keeps the key; the app never holds it.

Transcripts

When you ask the assistant to transcribe, what the microphone hears is sent to Deepgram to turn it into text, as in voice mode, and written into the chat; none of it is sent to the assistant while it runs. The transcript is then kept on your device (Settings → Photos → Transcripts) until you delete it, and becomes part of the conversation: the whole text when short, or its start when long, which the assistant can read in full when you ask about it. On the free tier and in the demo a transcription stops after two minutes.

Plugins

When a plugin is live, the data needed for a request goes to that service. Mock plugins never leave your machine. Credentials are never stored in the app or shown to the assistant.

Connected accounts

Some plugins work with your own account on another service, which you connect in Settings → Plugins: by pasting a key you made there, or by signing in on that service's own page. The key or token is kept encrypted on RendR's server, never on your device, and follows you to every device you sign in on. Every call RendR makes with it — which plugin, what it asked, whether you or the assistant asked, and how it went, but never what was sent or what came back — is logged for you, and you can read the log in Settings → Plugins → Activity; it is kept 90 days. Disconnect it and we ask the service to revoke our access and delete the key or token; where a service cannot be asked, we tell you so you can revoke it there. Switching a plugin off only stops it being used on that device: the connection stays, on every device, until you disconnect it. Demo personas cannot connect accounts.

Your controls

Settings → Plugins sets what each plugin may do and where it appears. Settings → Profile → Your data has two buttons. Export my data gives you one zip file: a readable JSON of everything the app keeps on this device (your profile, canvases and their versions, the records they keep, conversations, transcripts, usage, plugin settings and every other setting), what the RendR server holds about your account (the account, credits, promotional credits, your invite code, your shared canvases, your connected accounts — which service, which account, what was granted, when, never a key or token — and your activity log), and your pictures as files. Delete my data wipes everything on this device at once and signs you out; your account on the server is deleted 30 days later, and signing in again before then lets you keep it. After those 30 days the account record, its credits, promotional credits, invite code, referral, shared canvases, connected accounts (each revoked at its service first), activity log and your email on any feedback you sent are removed, and your id is replaced in our audit log; counts that never named you (how much each model was used on a day) remain. Start over only returns you to the first screen and keeps your data.

Web sessions

When a live plugin's site opens on the Browser page, its sign-in cookies are stored by the device's web view, shared across the sites the app opens, until you sign out on the site. The assistant opens pages only from a curated list and cannot see a page unless you switch on 'Assistant may read pages' for that plugin — and then it can only read, never act.

Children

RendR is not for anyone under 16.

Contact

Questions about your data: privacy@rendr.app (placeholder).