Back to home

Privacy Policy

Last updated: February 20, 2026

Our Commitment to Your Privacy

Privacy is a fundamental right, not a feature. At AI Office, we design our product to collect only the data necessary to provide the service you expect, and nothing more. We believe you should always know what data we collect, why we collect it, and how long we keep it.

AI Office is built and operated by Kurcz Software GmbH, based in Stuttgart, Germany. As a German company, we are directly subject to the General Data Protection Regulation (GDPR) and hold ourselves to the highest standard of data protection.

Information We Collect

We organize the data we collect into clear categories, each with a specific legal basis under Article 6(1) of the GDPR.

Account Information

Legal basis: Contractual necessity

When you create an account, we store your name, email address, and profile image. This information is managed through our authentication provider, Clerk, and synced to our database so we can identify you across sessions and devices.

Your Content

Legal basis: Contractual necessity

This includes messages you send and receive in conversations with AI agents, files you upload, tasks you create, and the outputs your agents produce. We store this content to provide the core service of AI Office — deploying and interacting with AI agents.

Communication Data

Legal basis: Contractual necessity

When your AI agents send or receive emails, SMS messages, or voice calls, we store the message content, sender/recipient addresses, and delivery status. This data is necessary to provide agent communication features and maintain an audit trail.

Billing Information

Legal basis: Contractual necessity

We store your subscription plan, usage records, and Stripe customer identifiers. Payment methods, card numbers, and billing addresses are handled entirely by Stripe and never touch our servers.

Device Information

Legal basis: Legitimate interest

We collect a device identifier, operating system, browser type, and device form factor to support multi-device functionality and ensure the app works correctly on your device. On the desktop app, we also track which macOS permissions have been granted so agents can operate within your chosen scope.

Onboarding & Analytics

Legal basis: Legitimate interest

During onboarding, we collect session data including navigation history, branch choices, and step timings to improve the setup experience. We also track aggregate usage metrics like token consumption, task completion rates, and agent run counts to understand product performance.

Credentials

Legal basis: Contractual necessity

API keys for third-party AI providers are stored exclusively in your operating system's native keychain (macOS Keychain, Windows Credential Manager). Our database only stores masked references showing the first and last four characters. We never store plaintext API keys on our servers.

Notification Preferences

Legal basis: Consent

If you opt in to notifications, we store your push subscription tokens, phone number (for SMS notifications), voice call consent flag, and quiet hours preferences. You can withdraw consent and delete this data at any time from your notification settings.

How We Use Your Information

We use your information for the following purposes:

  • Provide the service — power AI agent conversations, execute tasks, send and receive communications, and manage your workspace
  • Process payments — manage subscriptions, track usage against plan limits, and handle billing through Stripe
  • Improve the product — analyze aggregate usage patterns to identify bugs, improve performance, and develop new features
  • Communicate with you — send transactional emails about your account, notify you of service changes, and deliver the notifications you have opted into
  • Comply with law — respond to legal requests and fulfill regulatory obligations

What We Never Do

Some things are non-negotiable. We will never:

  • Sell your personal data to anyone, for any reason
  • Use your content to serve you advertisements or target you with marketing from third parties
  • Train AI models on your data without your explicit, informed consent
  • Share your data with third parties for their own marketing purposes

Third-Party Services

We work with trusted third-party services to provide specific functionality. Here is exactly what each service sees.

ServicePurposeData sharedPrivacy policy
ClerkAuthenticationEmail, name, profile image, login activityclerk.com/legal/privacy
StripeBillingPayment methods, invoices, subscription statestripe.com/privacy
TwilioSMS & voicePhone numbers, message content, call metadatatwilio.com/legal/privacy
AgentMailAgent emailEmail addresses, message content, attachmentsagentmail.to/privacy
ElevenLabsVoice AIAgent config, voice call audio, transcriptselevenlabs.io/privacy-policy
Anthropic, OpenAI, Google, MistralLLM providersConversation context (messages, system prompts, tool calls)Each provider's respective privacy policy
Brave SearchWeb search toolSearch queries from agentsbrave.com/privacy
PostHog (EU Cloud)Product analyticsProduct analytics events, session data (consent-required). Hosted in Frankfurt, Germany (EU). See “Analytics & Consent” below.posthog.com/privacy
VercelHosting & analyticsPage views, performance metrics, IP addressvercel.com/legal/privacy-policy

Analytics & Consent

We use PostHog (hosted in Frankfurt, Germany on AWS eu-central-1) to understand how users interact with AI Office across web and desktop. All analytics require your explicit consent.

Consent-Based Analytics

Legal basis: Consent (Art. 6(1)(a) GDPR)

No analytics data is collected until you click “Accept” on our consent banner. When you grant analytics consent, we collect product usage events such as pageviews, feature interactions, and aggregate performance metrics. We honor the Do Not Track (DNT) browser setting. Your consent choice is stored locally and synced across devices for authenticated users.

Consent Categories

You can manage your preferences granularly through our consent banner:

  • Essential — always enabled, required for the app to function
  • Analytics — product usage events to help us improve AI Office
  • Marketing — campaign effectiveness measurement

You can change or withdraw your consent at any time. When you revoke analytics consent, we immediately stop all tracking and reset your session. On the desktop app, the banner refers to “tracking preferences” rather than cookies, since the native app does not use browser cookies.

Where Your Data Lives

Your data is stored on Convex, our real-time database provider, which operates servers in the United States. As a German company transferring data to the US, we rely on the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure your data receives adequate protection.

File attachments you upload are stored via Convex's built-in file storage system and served through signed, time-limited URLs.

Your Data on Your Device

Some data stays on your device and is never sent to our servers.

Browser localStorage

We use browser localStorage to store onboarding progress (expires after 24 hours), a stable device identifier, session identifiers, UI preferences like expert mode, flags indicating which API key providers have been configured, and your analytics consent preferences. No actual API keys or passwords are stored in localStorage.

OS Keychain (Desktop App)

When you use the AI Office desktop app, your API keys and OAuth tokens are stored in your operating system's native keychain — macOS Keychain or Windows Credential Manager. These credentials are encrypted at rest by your OS and never leave your device in plaintext. Our servers only store masked references (first and last four characters) for display purposes.

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access — request a copy of all personal data we hold about you
  • Rectification — correct any inaccurate or incomplete data
  • Erasure — request deletion of your personal data
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — limit how we process your data in certain circumstances
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — revoke consent at any time for consent-based processing, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at privacy@aioffice.so. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI).

Data Retention

We keep your personal data for as long as your account is active and you need the service. When you delete your account, we delete your personal data within 30 days. Some anonymized, aggregated analytics data may be retained indefinitely because it cannot be traced back to you.

Communication logs and agent inbox data are retained for the duration of your account to maintain audit trails. You can request deletion of specific conversations or communication records at any time.

Children's Privacy

AI Office is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@aioffice.so and we will promptly delete it.

Changes to This Policy

We may update this policy from time to time. For material changes, we will notify you by email before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

Contact Us

Kurcz Software GmbH
Stuttgart, Germany

For privacy-related inquiries: privacy@aioffice.so

For general support: hello@aioffice.so

Your privacy matters to us — genuinely

We're fully GDPR compliant and then some. If you opt in, we'll use anonymous usage data to make AI Office better for everyone. We will never sell your data. Period. And you can change your mind anytime in settings. Read our privacy policy