Palmtop Privacy Policy
Effective date: July 15, 2026
Palmtop is a developer workspace for local projects, agent chats, files, tools, and an in-app browser. This policy applies to the Palmtop mobile app distributed through Google Play and the Apple App Store, except where a platform-specific section says otherwise. Palmtop is developed and published by Roman Savin. Privacy questions can be sent to [email protected].
Data handled on the device
- Prompts and chat context: prompts, assistant responses, conversation history, summaries, custom instructions, model choices, task state, and agent events.
- Projects, files, and photos: app-created project files, artifacts, files from a folder selected through Android's system picker, files explicitly attached from a project, and photos explicitly selected through the system picker. Selected folders and photos are copied into app storage for the requested workflow.
- Tool input and output: commands, file contents, patches, logs, test/build output, and other results produced by tools used during an agent task.
- Debug browser data: visited URLs, page titles and text, DOM/HTML snapshots, console messages, screenshots, cookies, and website local/session storage used to maintain and operate a chat-specific browser session.
- Provider and authentication data: selected provider, endpoint and model settings, API keys, provider account metadata, and authorization tokens used to connect a provider account.
- Local diagnostics: app/runtime events, errors, permission and environment state, job state, browser URLs, and frame-timing measurements. Diagnostic lines can contain details about a task but are stored locally.
- Installation and update status. A random app-installation identifier, device model, Android version and SDK, processor architecture, Palmtop build and distribution channel, runtime version, installed Desk and Notebook versions, and the time of the latest status report. Website builds also report update attempt and release identifiers, download and installation-request stages, and short error categories. A later status report indicates which version is running. These reports do not include Android ID, advertising ID, device serial number, chats, project files, raw error messages or credentials. A shortened one-way network-address hash is used only to limit abusive reports.
- User-initiated AI content reports: the one assistant response selected by the user, a required report reason, an optional comment, an opaque response identifier and engine label, and minimal Palmtop version/build metadata. Palmtop does not automatically attach the user's prompts, the rest of the chat, project files, photos, tool output, browser contents, or credentials.
When data leaves the device
A provider-backed agent task sends data needed for that task to the provider selected by the user. Depending on the task, this can include the prompt, recent chat context or a context summary, custom instructions, explicitly attached project-file contents, selected photos, and tool results. If the agent uses file or browser tools, returned file content, page text/HTML, screenshots, URLs, console output, or website storage accessible to that tool can become part of the provider conversation. Palmtop does not send all device files, photos, or browser sessions automatically.
Provider credentials are used for authentication with the selected service; they are not intentionally inserted into the text of a prompt. The current provider catalog includes Palmtop Cloud Free, Codex / ChatGPT account access, OpenRouter, Alibaba Token Plan, OpenAI API, Anthropic, Gemini, DeepSeek, xAI, Mistral, Groq, Together AI, Cerebras, Vercel AI Gateway, and user-configured compatible endpoints. Only the provider and model selected for a run receive that run's provider request. Those services process data under their own terms and privacy policies.
Websites opened in the in-app browser receive normal web requests and any data the user enters or the agent submits to the site. Android's system speech-recognition service processes voice dictation when the user invokes that feature; Palmtop receives the resulting text and does not request the Android microphone permission. Data is also transferred to another app when the user explicitly exports or shares content through the operating system.
On Android, Palmtop sends the installation and update status listed above to the Palmtop service so compatible agent updates can be delivered and their adoption can be diagnosed. A shortened one-way network-address hash is used only to limit abusive report creation; the raw address is not stored in the installation record.
A completed AI answer includes an in-app report action. A report is sent to the Palmtop developer moderation service only after the user selects a reason, reviews the transfer disclosure, and taps Submit. The selected AI answer, reason, optional comment, and minimal app/version metadata are used to investigate the report and improve content filtering and moderation. Reports are not sent to the selected model provider as part of this flow. A shortened one-way network-address hash is used to limit report abuse; the raw network address is not stored in the report record.
Purposes
- Provide agent responses and preserve chat context.
- Read, edit, build, test, synchronize, export, and share user-directed project work.
- Operate user-requested file, shell, package, and browser tools.
- Authenticate with and route requests to a selected AI provider or compatible endpoint.
- Keep long-running tasks visible and diagnose app/runtime behavior locally.
- Track installed Palmtop, Alpine, Desk, and Notebook versions for compatibility and update delivery.
- Review user-initiated reports about offensive or unsafe AI responses and improve content moderation.
Analytics, advertising, and sale
The audited Android app source does not include an advertising or third-party analytics SDK, and the app's diagnostic logger does not automatically upload its log. Palmtop does not sell personal data or use it for advertising.
Storage, retention, and security
Projects, chat records, agent/tool events, settings, imported content, and diagnostics are stored in the app's private storage or in a folder the user explicitly selected for synchronization. Local project and chat data is retained until the user deletes the project or clears Palmtop's app data; uninstalling the app removes data in its app sandbox. Exported or synchronized copies are not removed when an in-app project is deleted. Selected-photo copies and temporary browser screenshots can remain in app storage or cache until that storage is cleared by the user, Android, or app removal.
The local diagnostic log rotates after it reaches its size limit and can be cleared from the Diagnostics screen. Provider API keys are encrypted with AES-GCM using a key held by Android Keystore on Android. Codex authorization material is kept in an app-private service profile. Remote network connections use encrypted HTTPS transport; only loopback addresses are allowed to use cleartext for on-device runtime and browser bridges.
Palmtop does not define or promise a retention period for data received by a selected AI provider, custom endpoint, website, speech-recognition service, or receiving app. Their retention and security practices are controlled by those services.
AI content reports are available only to authenticated Palmtop moderators and are deleted from the moderation service after at most 180 days. A moderator can resolve or dismiss a report earlier. Reports are not sold, used for advertising, or used to train a general-purpose model.
Deletion and user choices
Users choose the provider, project attachments, photos, folders, websites, and sharing targets used in a workflow. Notification access is optional; broad all-files access, SMS access, and package-install permission are not requested by the current Google Play app.
Users can delete a local project in Palmtop, clear the local diagnostic log, disconnect a provider to remove its saved API key/account metadata, clear Palmtop storage in Android Settings, delete Palmtop from iOS, or uninstall the app. Disconnecting Codex removes the connection shown in the app; clearing app storage or removing the app removes its app-private local authorization profile. Clearing local data does not delete data already sent to a provider, website, system speech service, synchronized folder, or another app. Provider-side deletion must be requested from the applicable provider or account owner; Palmtop cannot delete data held by a user-configured third-party or custom endpoint. See the data deletion instructions for details.
AI transparency and consent
Palmtop does not represent Codex, ChatGPT, OpenCode, or a user-configured AI provider as a Palmtop-owned model. Before the first request to each provider, the app shows a prominent disclosure naming that provider and the categories of data that can be sent. Data is sent only after the user presses the affirmative allow-and-send action. Cancelling keeps the draft and records no acknowledgement. Sensitive files, photos, browser content, contacts, calendar data, or other protected device data must not be sent to a provider without the applicable system permission and an explicit user choice for that workflow. Provider access can be disconnected in the app. Provider-side account and data deletion remains governed by that provider's controls and policy. Android cloud backup and device transfer are disabled for Palmtop app-private projects, chats, runtime files, and provider credentials.
Users can report offensive or unsafe AI output without leaving Palmtop. The report form identifies exactly what will be sent and requires an affirmative Submit action; closing the form is not treated as consent.
Open-source software
Palmtop includes and adapts open-source components. Their copyright notices, licenses, source links, and the distinction between upstream projects and Palmtop are listed in the open-source notices.
Children
Palmtop is intended for developers and technical users. It is not directed to children.
Developer contact
Developer: Roman Savin
Email: [email protected]
Data deletion: palmtop.ai/data-deletion.html