Privacy Policy
Calyx ("we", "us") is a desktop workspace for notes, tasks and projects where AI agents work alongside you. This policy covers the calyxapp.co website and the Calyx app, and explains what data we handle and why. The short version: your work lives on your device, we collect the minimum we need to run the beta, and we never sell your data or use it for advertising.
Website: early-access applications
When you request early access we collect what you submit — your email, name, optional handle, and your answers about how you work. We store this securely (Cloudflare, encrypted at rest) and use it only to run the beta programme and contact you about Calyx. Email sam@calyxapp.co anytime to see or delete what we hold. The site itself sets no advertising or analytics cookies.
The Calyx app: local-first
Your notes, tasks and files live in folders on your own computer. If you enable cloud sync, your vault is transferred encrypted in transit and stored in our cloud storage solely to provide sync and backup for your account.
Google user data
If you choose to connect your Google account, Calyx requests access to:
- Gmail (read) — to show recent and searched mail inside your workspace, and so agents you invoke can help triage messages, summarise threads and draft replies.
- Google Calendar — to show your schedule and let agents you invoke help plan around it.
How that data is handled:
- Messages and events are fetched on demand and delivered to your device and your session. We do not build server-side copies of your mailbox or calendar.
- OAuth tokens are held by our credential broker (Nango) solely to make these requests on your behalf; agent processes receive only short-lived, narrowly-scoped tokens.
- When you explicitly ask an AI agent to work with a message or event, that content is processed by the AI model provider powering that agent (e.g. Anthropic or OpenAI) to fulfil your request — and for nothing else.
- We do not sell Google user data, use it for advertising, or use it to train generalised AI or machine-learning models.
- No human reads your Google data except with your explicit consent, where necessary for security or abuse investigation, or where required by law.
Limited Use disclosure: Calyx's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google from Calyx at any time (Settings → Integrations), and revoke Calyx's access directly at myaccount.google.com/permissions. Disconnecting deletes the associated tokens.
Retention & deletion
Connection tokens are deleted when you disconnect an integration or delete your account. Early-access application data is kept while the beta programme runs and deleted on request. To exercise any of this, email sam@calyxapp.co.
Changes
If this policy changes materially we will update this page and note the new effective date above.
Contact
Questions about this policy or your data: sam@calyxapp.co.