Privacy Policy
Effective Date: January 1, 2025
Last Updated: September 26, 2026
1. Introduction
Chishingo Ventures Ltd. ("we," "us," or "our") operates the Human-in-the-Loop (HITL) mobile application and related services. We are committed to protecting your privacy and handling your personal information with transparency and care.
This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have regarding your personal information. By using HITL, you agree to the collection and use of information in accordance with this policy.
Contact Us: For privacy-related questions or requests, email us at contact@hitlrelay.app
1.1 How HITL Works
HITL is an agentic mobile application where agents run on your phone. When an agent thinks or processes a task, the request goes to the AI model you use—Google Vertex AI by default, or your own API key via Bring Your Own Key (BYOK). Anything the agent reads from your device to answer your query or execute a task goes with that model request to the chosen provider.
1.2 Public Beta Notice
The HITL mobile application is currently in public beta. Features, device tools, and data flows may evolve as we iterate on the platform. When material changes occur, we update this policy and the "Last Updated" date above.
2. Information We Collect
We collect the following categories of information:
2.1 Information You Provide
- Account Information: Email address, name, and authentication credentials when you create an account
- Profile Information: Optional profile settings and preferences
- Content: Requests that remote agents (such as AI tools connected through MCP) send to you through our servers, and the approvals, responses, and attachments you send back to them. Your chats with agents in the app are stored on your device, not on our servers; to generate replies they are sent to the AI provider you use (see Section 1.1). Chat content reaches our servers only if you choose to send it: when you report an AI response (that response and your note), send us feedback, or turn on trace upload (see Section 5.4)
- Communication: Support requests, feedback (including any screenshot you attach), AI responses you report to us, and correspondence with us
2.2 Information Collected Automatically
- Device Information: Device type, operating system, app version, device identifiers
- Push Notification Token: Firebase Cloud Messaging (FCM) token for delivering notifications
- Usage Data: Features used, interactions, session duration, and timestamps
- Log Data: IP address (for security and analytics), error logs, crash reports
- Diagnostics: Performance metrics, error rates, and technical diagnostics
2.3 Location Information
Precise Geolocation (Geofencing & Location Triggers): When you explicitly grant location permissions, HITL accesses your precise device location (latitude and longitude coordinates) to monitor geofences and trigger automated agent workflows when you arrive at or depart from specified areas. On iOS, this includes When-In-Use and Always (background) location access. On Android, this includes foreground and background location permissions.
Processing & Model Requests: Geofence coordinates and trigger configurations are stored on your device for active triggers. When an agent tool accesses location data, those coordinates are included in the request sent to your selected AI provider. We do not store historical location movement logs or continuous tracking trails on our servers. Deleting a trigger in the app removes its location coordinates from your device; account deletion purges server-side records and account associations, while local on-device geofences and coordinates remain on your phone until you delete the app or clear application data in device settings.
Coarse Location: We also collect approximate location information derived from your IP address for security, regional compliance, and analytics.
2.4 Device Permissions & Data Flows
HITL agents can interact with various device features and APIs when you grant permission. Data from these sources is read on your phone only when an agent tool is invoked to fulfill a request. The table below details how each permission is handled:
| Category & Permissions | What Is Read | When Accessed | Where It Goes | Storage & Retention |
|---|---|---|---|---|
| Location & Geofences | Precise coordinates (latitude/longitude), geofence boundaries; coarse location from IP | During geofence monitoring or when an agent location tool is invoked | Evaluated on device; included in model request to chosen AI provider if a location tool runs | Coordinates stored on device for active triggers; no location trails stored on HITL servers |
| Health (Apple Health / Health Connect) | Requested health metrics (steps, sleep, heart rate, activity, workouts) via read-only access | Read on device only when an agent tool is invoked by you to answer a health query | Included in model request to your chosen AI provider | Not stored on HITL servers. Health data is never used for advertising and never sold |
| Contacts | Contact names, phone numbers, and email addresses | Read only when an agent tool is invoked to look up or reference a contact | Included in model request to your chosen AI provider | Not stored on HITL servers |
| Calendar & Reminders | Calendar event titles, dates, attendees, and reminder tasks | Read only when an agent tool is invoked to review or manage schedule | Included in model request to your chosen AI provider | Not stored on HITL servers |
| SMS, Calls & Email | Draft message text, recipient information, communication context | When you ask an agent to draft, summarize, or review messages | Included in model request to your chosen AI provider | Texts and emails are drafted on your phone and sent only by you. We do not store drafts on our servers |
| Photos, Camera & Microphone | Selected photos, camera frames for OCR/vision analysis, audio input for voice transcription | When you capture/select images or use live voice and scribe features | Sent to chosen AI provider (Vertex AI via Firebase AI Logic for voice/scribe) | Processed in real time; not permanently stored on HITL servers |
| Notifications from Other Apps (Android) | Notification text, sender, and source app via Android Notification Listener Service | Only when enabled by you to let agents evaluate incoming notifications for triggers | Included in model request to your chosen AI provider when evaluated | Not stored on HITL servers |
| Screen Content (Android Accessibility) | On-screen text and UI structure via Android Accessibility Service | Read only when you explicitly tap to analyse screen content | Sent to chosen AI provider for visual or textual analysis | Discarded immediately after analysis; never stored on HITL servers |
Health Data Protection Commitment
Health data accessed via Apple Health or Health Connect is never used for advertising and never sold. It reaches an AI provider only when you explicitly ask an agent to use it.
3. Data Categories (Apple App Store Disclosure)
The following data types are collected and may be linked to your identity:
- Contact Information: Email address, name
- Identifiers: User ID, device ID, Firebase UID
- Location: Precise location (latitude and longitude for geofencing and location-based agent triggers, collected only with explicit user permission) and coarse location (approximate location derived from IP address)
- Purchases: Purchase history, subscription status, and transaction identifiers managed via Apple In-App Purchase, Google Play Billing, and RevenueCat
- Usage Data: Product interaction, app interactions, feature usage
- Diagnostics: Crash data, performance data, error logs
- User Content: Remote-agent requests routed through our servers and the approvals, responses, and attachments you send in reply; AI responses you report and feedback you send us; and agent run traces, only if you turn on trace upload. Chats with in-app agents are stored on your device and are not stored on our servers
4. How We Use Your Information
We use the collected information for the following purposes:
- Provide Services: Run phone agents, deliver notifications, relay agent requests, synchronize configurations, and process approvals
- Authentication & Security: Verify your identity, prevent fraud, detect abuse, and protect against security threats
- Service Improvement: Analyze usage patterns, debug issues, improve features, and develop new functionality
- Communication: Send service updates, respond to support requests, and provide important notices
- Legal Compliance: Comply with legal obligations, enforce our terms, and respond to lawful requests
- Analytics: Understand how users interact with HITL to improve user experience (aggregated and pseudonymous)
5. Third-Party Services and Data Sharing
We use the following third-party service providers to operate HITL:
5.1 Infrastructure & Hosting
- Google Cloud Platform (GCP): Cloud infrastructure, database hosting, and API services
- Firebase (Google): Authentication, push notifications (FCM), and analytics
- GitHub: Feedback and AI-response reports you send us are copied, with your user ID, into issues in a private GitHub repository that our team uses to review and track them
5.2 Analytics & Monitoring
- Google Analytics & Firebase Analytics: Usage analytics, user engagement, and app interaction monitoring (aggregated and pseudonymous data)
- Firebase Crashlytics: Crash reporting, stack traces, and technical diagnostics to identify issues and improve stability
- Firebase Cloud Messaging (FCM): Push notification delivery and device token registration
5.3 Payments (if applicable)
- Apple App Store / Google Play: In-app purchases and subscriptions
- RevenueCat: Subscription management, entitlement mapping, and purchase analytics
Data Sharing Policy: We do not sell your personal information. Third-party service providers are contractually bound to protect your data and may only use it to provide services on our behalf.
5.4 AI Service Providers
Notice on AI Processing
When you use AI agents, voice features, or assistant tools, your prompts and any device data retrieved to fulfill the request are transmitted to the AI provider handling the inference. Providers process data under their own terms and privacy practices.
AI Providers Available in HITL:
- Google Vertex AI (via Firebase AI Logic): The default model provider for Companion, Builder, live voice, and scribe features. Model requests are governed by Google Cloud enterprise terms and data protections. For details on Google Cloud data commitments, see the Google Cloud Generative AI Data Governance documentation.
- OpenRouter: Utilized by our relay model proxy for select requests and available when selected by the user. Requests sent to OpenRouter are subject to OpenRouter's privacy policy and the terms of the underlying model endpoint.
- Bring Your Own Key (BYOK): You may configure your own API keys for providers including OpenAI, Anthropic, Google, OpenRouter, or custom OpenAI-compatible endpoints. In BYOK mode, calls route directly under your account credentials and are governed by your direct agreement with that provider.
- On-Device Models (experimental, Android only): On supported Android devices you can choose an experimental on-device model, which runs on your phone, so model requests are not sent to a cloud AI provider.
Your API keys and secrets
API keys you enter for AI model providers, and secrets you save for skills or connected services, are stored on your device in its secure storage (the iOS Keychain, or encrypted with a key held in the Android Keystore). They are not synced to HITL's servers or included in trace uploads. The app sends your AI provider keys directly from your device to that provider (for example OpenAI, Anthropic, Google or OpenRouter) or to the custom endpoint you configure, only to make the requests you ask for. A secret you set for a skill or tool is given only to that skill or tool to use, and third-party skills and services you enable are responsible for how they use it.
What AI Providers Receive:
- Your Prompts: Text and audio instructions you provide to agents
- Context & Tool Outputs: Device data read by agent tools (calendar entries, contact info, health metrics, photos, or location coordinates) to answer your query
- Agent Configurations: System prompts and tool definitions
Agent Run Traces:
Agent run traces (including your messages, the agent's instructions and replies, and tool execution steps) are uploaded to our servers only if you turn on "Upload traces to relay" on the app's Traces screen. It is off by default. When enabled, traces are associated with your agent and are deleted whenever the associated agent is deleted.
🔒 E2EE Scoped to Remote Relay Agents
Optional end-to-end encryption (E2EE) protects messages between your phone and remote MCP clients. When using cloud AI providers for in-app agents, prompt data must be sent in cleartext over HTTPS/TLS to the provider for processing.
5.5 Legal Disclosures
We may disclose your information if required by law, legal process, or to protect the rights, property, or safety of our users or the public.
6. End-to-End Encryption (Optional)
HITL offers optional end-to-end encryption (E2EE) for communications with remote agents via MCP:
- Message content is encrypted on your device and can only be decrypted by authorized client endpoints
- HITL servers cannot read or decrypt the contents of E2EE payload messages
- Routing metadata (timestamps, message sizes, delivery state) is processed to operate delivery
7. Data Retention
We retain information according to the following retention schedule:
- Remote-Agent Requests: Requests and responses exchanged with remote agents are kept on our servers for 7 days after they are answered or resolved, after which they are moved to an archive we keep for account recovery
- Agent Run Traces: Retained only if trace upload is enabled by the user; automatically deleted when the associated agent is deleted
- Crash & Diagnostic Data: Retained in Firebase Crashlytics according to standard retention periods (90 days)
- Feedback & Reports: Feedback and AI-response reports you send us, any screenshot you attach, and their copies as issues in our private GitHub repository have no fixed expiry. The copy in our database is kept until you delete your account; the GitHub copies and screenshots are kept until you ask us to remove them (see Section 10.2)
- Account Data: Retained while your account is active and for 90 days following account deletion
- Location Data: Geofence coordinates and trigger configurations are retained locally on your device for the duration of the configured trigger. Coordinates are deleted when the trigger is removed. We do not store historical location movement logs on our servers
- Usage & Analytics Data: Aggregated and pseudonymous usage statistics retained for up to 2 years
- Server Log Data: Retained for up to 90 days for infrastructure security and debugging
8. Data Security
We implement industry-standard security measures to protect your information:
- Data encryption in transit (TLS/HTTPS) and at rest
- Secure authentication using OAuth 2.1 and Firebase Authentication
- Access controls and authorization safeguards for backend services
- Regular security audits and infrastructure monitoring
- Cloud infrastructure hosted on Google Cloud Platform
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
9. Your Rights and Choices
You have the following rights regarding your personal information:
9.1 Access and Portability
You can request a copy of your personal data in a machine-readable format.
9.2 Correction
You can update or correct your account information through the app settings or by contacting us.
9.3 Deletion
You can request deletion of your account and personal data:
- In the app: Go to Settings → Account → Delete Account
- Email us at contact@hitlrelay.app with "Delete My Account" in the subject line
- Deletion requests are processed within 30 days
9.4 Opt-Out Rights
- Push Notifications: Disable notifications in device or app settings
- Trace Upload: Turn off "Upload traces to relay" on the app's Traces screen
- Analytics: Contact us to opt out of analytics data collection
9.5 Object or Restrict Processing
Where applicable by law, you can object to or request restriction of certain data processing activities.
10. Account Deletion
Users have the right to delete their account and associated personal data at any time.
10.1 How to Delete Your Account
You may initiate account deletion through either method:
- In-App: Navigate to Settings → Account → Delete Account
- Email: Send a request to contact@hitlrelay.app with the subject line "Account Deletion Request" from your registered email address
10.2 What Data Gets Deleted
When you delete your account, our backend service automatically removes:
- User Profile: Email, name, and Firebase authentication credentials
- Agents: Cloud-synced agent definitions and configurations
- Active Requests & Responses: Current and pending agent requests and attachments
- Devices & Tokens: FCM push notification tokens and registered device records
- API Keys & Usage: Issued API keys and usage statistics
- Schedules & Shares: Scheduled agent triggers and shared agent links
- Knowledge & Feedback: Custom knowledge entries, and the feedback and AI-response reports stored in our database
Archived Remote-Agent Requests: Account deletion purges active user records; however, records in the remote-agent request archive (stored for account recovery) are not purged automatically by the deletion endpoint. Archived records are removed upon written request to contact@hitlrelay.app within 30 days.
Feedback Copies & Screenshots: Account deletion does not automatically remove the copies of your feedback and AI-response reports kept as issues in our private GitHub repository, or screenshots you attached to feedback. These are removed upon written request to contact@hitlrelay.app within 30 days.
On-Device Data: Saved geofences on your phone, local agent definitions, chat history, and local database entries stored on your mobile device are removed by deleting the HITL application or clearing application data in device settings. If you use your device's own backup service (such as Google or iCloud backup), copies may also exist in those backups under that service's terms.
10.3 Deletion Timeline
- In-app account deletion executes immediately upon confirmation
- Email deletion requests are processed within 30 days of receipt
- Backup archives are purged in accordance with standard backup rotation cycles (up to 90 days)
11. California Privacy Rights (CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request disclosure of personal information collected, used, and shared
- Right to Delete: Request deletion of personal information, subject to statutory exceptions
- Right to Opt-Out: We do not sell your personal information
- Right to Non-Discrimination: Equal service regardless of exercising your privacy rights
To exercise CCPA rights, email contact@hitlrelay.app.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States and European Union. When transferring data internationally, we employ approved mechanisms such as Standard Contractual Clauses to safeguard your data.
13. Children's Privacy
HITL is not intended for children under the age of 13 (or the applicable digital consent age in your jurisdiction). We do not knowingly collect personal information from children. If you believe child data has been inadvertently collected, please contact contact@hitlrelay.app for immediate deletion.
14. App Tracking Transparency (Apple)
HITL does not track users across third-party apps or websites for advertising or advertising measurement purposes. We do not sell or share data with data brokers.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements, regulatory changes, or new features. When material changes occur, we update the "Last Updated" date and notify users through the app or website.
16. Contact Us
For questions or privacy requests regarding this Privacy Policy, please contact us:
This Privacy Policy complies with applicable data protection laws including GDPR (EU/UK), CCPA (California), and developer disclosure policies for the Apple App Store and Google Play Store.