Palmtop Privacy Policy

Effective date: July 15, 2026

Palmtop is a developer workspace for local projects, agent chats, files, tools, and an in-app browser. This policy applies to the Palmtop mobile app distributed through Google Play and the Apple App Store, except where a platform-specific section says otherwise. Palmtop is developed and published by Roman Savin. Privacy questions can be sent to [email protected].

Data handled on the device

When data leaves the device

A provider-backed agent task sends data needed for that task to the provider selected by the user. Depending on the task, this can include the prompt, recent chat context or a context summary, custom instructions, explicitly attached project-file contents, selected photos, and tool results. If the agent uses file or browser tools, returned file content, page text/HTML, screenshots, URLs, console output, or website storage accessible to that tool can become part of the provider conversation. Palmtop does not send all device files, photos, or browser sessions automatically.

Provider credentials are used for authentication with the selected service; they are not intentionally inserted into the text of a prompt. The current provider catalog includes Palmtop Cloud Free, Codex / ChatGPT account access, OpenRouter, Alibaba Token Plan, OpenAI API, Anthropic, Gemini, DeepSeek, xAI, Mistral, Groq, Together AI, Cerebras, Vercel AI Gateway, and user-configured compatible endpoints. Only the provider and model selected for a run receive that run's provider request. Those services process data under their own terms and privacy policies.

Websites opened in the in-app browser receive normal web requests and any data the user enters or the agent submits to the site. Android's system speech-recognition service processes voice dictation when the user invokes that feature; Palmtop receives the resulting text and does not request the Android microphone permission. Data is also transferred to another app when the user explicitly exports or shares content through the operating system.

On Android, Palmtop sends the installation and update status listed above to the Palmtop service so compatible agent updates can be delivered and their adoption can be diagnosed. A shortened one-way network-address hash is used only to limit abusive report creation; the raw address is not stored in the installation record.

A completed AI answer includes an in-app report action. A report is sent to the Palmtop developer moderation service only after the user selects a reason, reviews the transfer disclosure, and taps Submit. The selected AI answer, reason, optional comment, and minimal app/version metadata are used to investigate the report and improve content filtering and moderation. Reports are not sent to the selected model provider as part of this flow. A shortened one-way network-address hash is used to limit report abuse; the raw network address is not stored in the report record.

Purposes

Analytics, advertising, and sale

The audited Android app source does not include an advertising or third-party analytics SDK, and the app's diagnostic logger does not automatically upload its log. Palmtop does not sell personal data or use it for advertising.

Storage, retention, and security

Projects, chat records, agent/tool events, settings, imported content, and diagnostics are stored in the app's private storage or in a folder the user explicitly selected for synchronization. Local project and chat data is retained until the user deletes the project or clears Palmtop's app data; uninstalling the app removes data in its app sandbox. Exported or synchronized copies are not removed when an in-app project is deleted. Selected-photo copies and temporary browser screenshots can remain in app storage or cache until that storage is cleared by the user, Android, or app removal.

The local diagnostic log rotates after it reaches its size limit and can be cleared from the Diagnostics screen. Provider API keys are encrypted with AES-GCM using a key held by Android Keystore on Android. Codex authorization material is kept in an app-private service profile. Remote network connections use encrypted HTTPS transport; only loopback addresses are allowed to use cleartext for on-device runtime and browser bridges.

Palmtop does not define or promise a retention period for data received by a selected AI provider, custom endpoint, website, speech-recognition service, or receiving app. Their retention and security practices are controlled by those services.

AI content reports are available only to authenticated Palmtop moderators and are deleted from the moderation service after at most 180 days. A moderator can resolve or dismiss a report earlier. Reports are not sold, used for advertising, or used to train a general-purpose model.

Deletion and user choices

Users choose the provider, project attachments, photos, folders, websites, and sharing targets used in a workflow. Notification access is optional; broad all-files access, SMS access, and package-install permission are not requested by the current Google Play app.

Users can delete a local project in Palmtop, clear the local diagnostic log, disconnect a provider to remove its saved API key/account metadata, clear Palmtop storage in Android Settings, delete Palmtop from iOS, or uninstall the app. Disconnecting Codex removes the connection shown in the app; clearing app storage or removing the app removes its app-private local authorization profile. Clearing local data does not delete data already sent to a provider, website, system speech service, synchronized folder, or another app. Provider-side deletion must be requested from the applicable provider or account owner; Palmtop cannot delete data held by a user-configured third-party or custom endpoint. See the data deletion instructions for details.

AI transparency and consent

Palmtop does not represent Codex, ChatGPT, OpenCode, or a user-configured AI provider as a Palmtop-owned model. Before the first request to each provider, the app shows a prominent disclosure naming that provider and the categories of data that can be sent. Data is sent only after the user presses the affirmative allow-and-send action. Cancelling keeps the draft and records no acknowledgement. Sensitive files, photos, browser content, contacts, calendar data, or other protected device data must not be sent to a provider without the applicable system permission and an explicit user choice for that workflow. Provider access can be disconnected in the app. Provider-side account and data deletion remains governed by that provider's controls and policy. Android cloud backup and device transfer are disabled for Palmtop app-private projects, chats, runtime files, and provider credentials.

Users can report offensive or unsafe AI output without leaving Palmtop. The report form identifies exactly what will be sent and requires an affirmative Submit action; closing the form is not treated as consent.

Open-source software

Palmtop includes and adapts open-source components. Their copyright notices, licenses, source links, and the distinction between upstream projects and Palmtop are listed in the open-source notices.

Children

Palmtop is intended for developers and technical users. It is not directed to children.

Developer contact

Developer: Roman Savin
Email: [email protected]
Data deletion: palmtop.ai/data-deletion.html