We use cookies to measure how the site is used and how our ads perform (Google Analytics, Microsoft Clarity). Privacy Policy

Skip to content
Automater
LiteProPricingFAQIntel
Upgrade to ProDownload

DRAFT — pending legal counsel review. This document is engineering-drafted placeholder copy for the Automater.AI launch (P1-2 of the production-readiness master plan). It must be reviewed and revised by qualified legal counsel before being relied upon as the binding Privacy Policy for production users.

Automater.AI — Privacy Policy

Effective date: 2026-05-05

This Privacy Policy describes how Automater.AI (“we”, “us”, “our”) collects, uses, and shares information about you when you use the Automater.AI desktop application, website, and related services (collectively, the “Service”).

1. Information We Collect

Account information

When you create an account, we collect your email address, a hashed password, your selected display name (if any), and your verification status. We collect timestamps for account creation, last login, and email verification.

Billing information

When you subscribe, Stripe processes your payment instrument. We receive from Stripe only the metadata we need to associate a subscription with your account: a Stripe customer ID, a Stripe subscription ID, subscription status, and the last four digits and brand of your card. We do not store your full payment card number, expiration date, or security code.

Usage statistics in the Automater applications (on by default, opt-out)

Automater Lite and Automater Desktop send us anonymous usage statistics so we can see which versions are in use, which features are used, and where the applications fail. Once every 15 minutes (and when the application closes) each installation uploads to our own servers (api.automater.ai):

  • a random installation identifier generated on the computer the first time the application runs. It is not derived from your hardware, account or network, it is never linked to your account or email, and it is replaced by a new random identifier whenever you turn usage statistics off and back on;
  • the application name and version, the operating system and its major version, the processor architecture, the display language, and whether the installation is free, signed in, or Live Pro;
  • daily counts of events from a fixed, published list — for example “app opened”, “dictation completed (local)”, “library search”, “upgrade button clicked”, “JavaScript error”, “unclean exit” — and, for a few timing events, a total duration so we can compute an average (start-up time, dictation latency);
  • which supported AI command-line tools are installed on the computer (names only, e.g. “codex”, “claude”).

Usage statistics never include the content of your sessions, prompts, transcripts, files, file paths, window titles, your machine name, user name, IP address, account identifier or email address. Our servers record the country of the request from the connection and discard the IP address. Event names that are not on the published list are discarded.

Usage statistics are on by default and can be turned off at any time: in Automater Lite under Settings → Diagnostics → “Share anonymous usage statistics and crash reports”, and in Automater Desktop under Settings → Telemetry (also offered during onboarding). Setting the environment variable DO_NOT_TRACK=1 disables them as well. We can also stop collection remotely for every installation. The application shows you your installation identifier (“support ID”) so that you can ask us to delete the statistics tied to it (Section 8).

We may additionally mirror daily aggregated usage statistics from our servers to Google Analytics 4 through its server-side Measurement Protocol so that application and website reporting can be viewed together. That mirror runs on our servers, not in the application; it carries the same counts and attributes described above under a one-way hashed installation identifier, and never the IP address, machine name, account or content. It is off until we enable it, and it is disabled when you turn usage statistics off.

The legacy web application at app.automater.ai uses PostHog product analytics only after you opt in through its cookie banner; the Lite and Desktop applications do not load PostHog or any other third-party analytics SDK.

Website analytics

Our public websites — automater.ai, classic.automater.ai, account.automater.ai and leaderboard.automater.ai — load Google Tag Manager, a tag container that in turn loads the analytics services below. These services run in the website only; the Automater desktop and Lite applications do not load them, and a website page displayed inside the Automater Lite browser card is not counted.

Google Analytics 4 (Google LLC / Google Ireland Ltd). We measure how the website is used: the pages you visit and the page you came from, the approximate location derived from your IP address (Google does not store the IP address itself (verify)), your device type, browser, operating system, language and screen size, and interactions such as clicks, scroll depth, outbound links, file downloads and video plays. We also send conversion events — for example that a sign-up was completed, that checkout was started, or that a purchase was completed and for which plan. These events never include your name, email address, password or payment details. Google Analytics identifies your browser with a random client identifier stored in a first-party cookie (_ga, _ga_*), which lets us count returning visitors and attribute a sign-up to an earlier visit.

Google Signals (advertising features). We have enabled Google Analytics’ advertising features. When you are signed in to a Google account that has Ads Personalization turned on, Google associates your visit with that account to give us aggregated demographic and interest reports, cross-device reporting, and remarketing audiences we may use to show Automater advertising on Google’s network. Google does this under its own privacy policy; we never receive the identity of an individual visitor from it. You can turn this off for your Google account at any time (see Section 8), and where consent is required it is only active after you accept analytics and advertising cookies in our consent banner.

Microsoft Clarity (Microsoft Corporation). We use Microsoft Clarity to record how visitors interact with our website: mouse movement, clicks, scrolling, page structure and navigation, replayed as anonymized session recordings and aggregated into heatmaps. Clarity masks text you type into form fields before it leaves your browser (confirm the masking level set in the Clarity project), and we do not run Clarity on pages where you enter payment details (verify: exclude /upgrade in the Clarity project or drop this sentence). Clarity uses first- and third-party cookies (_clck, _clsk, CLID, ANONCHK, MR, MUID, SM (verify)) to link the pages of one visit together. Microsoft processes this data under the Microsoft Privacy Statement and may also use it for its own fraud-detection and advertising purposes as described there.

Crash and error reports (legitimate interest)

We collect crash reports and error traces through Sentry from our servers, from the legacy web application, and from the Automater Lite and Automater Desktop applications. From the applications this means: application crashes (native crash dumps and, in Lite, Rust panics), unhandled JavaScript errors, the application version, operating system and architecture, and a short technical trace of what the program was doing. Crash reports are scrubbed before transmission: authentication tokens, password fields, session identifiers, URL paths containing a verification or reset token, your user name and machine name, and user-specific file paths are removed or replaced. Crash reporting is on by default under the legitimate-interest basis described in Section 3 below; you may turn it off at any time — in Lite with the same Settings → Diagnostics switch as usage statistics, in Desktop under Settings → Telemetry.

Logs

Our backend records server-side logs of API requests, including IP address, user-agent, timestamp, and the response status. Logs are retained for the period described in Section 6.

Automater AI Network (optional beta)

The following beta disclosure is a draft for counsel review before invited users are admitted. It describes the intended network contract; it does not announce general availability.

Joining links an authenticated account to a registered device and a private overlay address. We process device names, platform, public WireGuard keys, account and device identifiers, address assignments, enrollment and revocation events, latest handshake time, and aggregate bytes sent and received. This operational information is required to authorize and operate the network; it is separate from optional product analytics.

Traffic passes through an Automater-operated hub. WireGuard encryption terminates at that hub and is applied again for the next device. The hub can therefore see inner network addresses and traffic that is not separately encrypted by its application. SSH, SFTP and correctly configured HTTPS provide their own encryption. The overlay alone does not provide end-to-end encryption against the hub operator. The staff-only Cloud Code Drive has a separate rollout gate; its NFS traffic is also visible wherever it is not separately encrypted.

For bundled Windows and macOS connections, Automater Core manages the network independently of Desktop or Lite windows. Closing a window does not sign you out. Signing out stops the Core-owned local tunnel and requests removal of the device’s network authorization. Session invalidation also removes authorization. If the hub cannot receive the change, remote removal remains pending until it reconnects; a pending revocation is not confirmation that traffic has stopped. A hub outage interrupts connectivity, and loss of session validation can disconnect Core-owned tunnels.

Device private keys are generated locally and kept in Core’s operating system credential store for bundled clients. The privileged tunnel helper receives them in memory. Phone enrollment and staff imports use an import file or QR code containing that device’s private key: anyone who obtains it can use those credentials until they are revoked. The control plane stores encrypted preshared keys needed to configure the hub. Enrollment and desired-state payloads must not enter request logs, analytics or session recordings. Unsupported platforms cannot use the bundled tunnel; staff may use the separately identified official-client import mode during testing.

The beta retention contract is 30 days for network audit events, with latest operational counters kept on device records. Address-allocation tombstones and revision records needed to prevent address reuse and complete revocation are retained separately from audit events. Audit retention, payload exclusion and the signed-client behavior must pass the beta release checks before this disclosure is approved for invitees.

2. How We Use Information

We use the information we collect to:

  • create and authenticate your account, including delivering email verification links;
  • provide, maintain, and improve the Service;
  • process payments and renewals;
  • diagnose and fix bugs through crash and error reports;
  • understand product usage in aggregate — which versions are in use, which features are used, how often the applications fail (anonymous usage statistics; you may turn them off);
  • measure website traffic, understand which pages and campaigns lead to sign-ups and purchases, and improve the website (Google Analytics, Microsoft Clarity session recordings and heatmaps);
  • build audiences for and measure Automater advertising on Google’s network (Google Signals);
  • comply with legal obligations and enforce our Terms of Service;
  • send you transactional email related to your account or subscription (we do not use your email address for marketing without separate consent).

3. Legal Bases (GDPR)

For users in the European Economic Area, the United Kingdom, and Switzerland, we process personal data on the following legal bases:

  • Contract necessity (Article 6(1)(b)) — to create your account, authenticate you, deliver the Service you subscribed to, and bill you.
  • Legitimate interest (Article 6(1)(f); see Recital 47) — to collect crash and error reports through Sentry, and to collect the anonymous usage statistics described in Section 1 from the Automater applications. We have determined that keeping the Service stable and secure and understanding in aggregate how the applications are used is a legitimate interest that is not overridden by your fundamental rights, given the scrubbing measures, the random and user-resettable installation identifier, the fixed event list, the absence of any content or account linkage, and the one-click opt-out described in Section 1 (counsel to confirm the basis for usage statistics; the alternative is opt-in consent).
  • Consent (Article 6(1)(a); ePrivacy Article 5(3)) — to load product-analytics scripts through PostHog in the legacy web application, and to set analytics, session-recording and advertising cookies on our websites. The Lite and Desktop applications load no third-party analytics SDK at all. On the websites, visitors in the European Economic Area, the United Kingdom and Switzerland see a consent banner, and until they choose only Essential storage is used (Section 5).
  • Legal obligation (Article 6(1)(c)) — to retain records of payment, tax, and similar transactions where applicable law requires it.

4. Third-Party Sub-processors

We share personal data with the following named sub-processors, each of which is contractually obligated to use the data only for the purpose we specify and to safeguard it.

Sub-processor Purpose Legal basis Region
Stripe, Inc. Payment processing, subscription state Contract necessity United States
Resend or SMTP self-host Transactional email (verification, receipts) Contract necessity United States or self-hosted (TBD)
Sentry (Functional Software, Inc.) Crash and error reporting Legitimate interest United States
PostHog Inc. (Cloud EU) Product analytics Consent (opt-in) European Union
Google LLC / Google Ireland Ltd (Google Tag Manager, Google Analytics 4, Google Signals) Website analytics and advertising features; optional server-side mirror of daily aggregated, pseudonymous application usage statistics (Measurement Protocol) Consent where required by law (website); legitimate interest (application mirror) United States; EU visitor traffic first processed on EU servers (verify)
Microsoft Corporation (Microsoft Clarity) Website session recordings and heatmaps Consent where required by law United States

We do not sell your personal information to third parties under any definition of “sell” we are aware of. Under the California Consumer Privacy Act, allowing Google to use your browsing information for cross-context behavioral advertising (Google Signals) may be considered “sharing” (counsel to confirm). You can opt out via the “Do Not Sell or Share My Personal Information” link in the website footer or by enabling the Global Privacy Control signal in your browser, which we honor.

5. Cookies & Telemetry

On our websites (automater.ai, classic.automater.ai, account.automater.ai, leaderboard.automater.ai):

Category What Examples Duration Your control
Essential Signing in, remembering a referral code or the offer you arrived from, your theme and display preferences access_token, automater_ref, automater_hero_theme, automater-theme, automater_promo, automater_fomo session to 1 year always on
Analytics Google Analytics visitor identifier _ga, _ga_* up to 2 years consent banner (EEA/UK/CH) · Cookie settings · Section 8
Session recording Microsoft Clarity visit identifiers _clck, _clsk, CLID, ANONCHK, MR, MUID, SM (verify) 1 day to 13 months (verify) consent banner (EEA/UK/CH) · Cookie settings · Section 8
Advertising Google Signals (cookies set by Google on its own domains, e.g. doubleclick.net) — per Google consent banner (EEA/UK/CH) · Google Ads Settings

If you visit from the European Economic Area, the United Kingdom or Switzerland, we display a consent banner on your first visit. Until you make a choice, only Essential storage is used and Google Analytics runs without cookies; session recording and advertising features are off. Your choice is stored in the automater_consent cookie for 12 months (confirm) and applies to all of the websites above; change it at any time via “Cookie settings” in the footer. Elsewhere, these cookies are set when you load the page and you may opt out as described in Section 8. We honor the Global Privacy Control browser signal as a refusal of advertising cookies.

In the Automater applications, we distinguish three categories of client-side storage:

  • Essential. Required for the Service to function — for example, the cookie or local-storage entry that keeps you signed in. Always on; cannot be disabled.
  • Usage statistics. The anonymous daily counts described in Section 1, kept in the application’s local storage under a random installation identifier and uploaded to our servers. On by default; may be turned off at any time, which also deletes the locally buffered counts and, when turned back on, issues a new installation identifier.
  • Crash reports. Sentry’s crash-reporting integration. On by default on the legitimate-interest basis described in Section 3. May be turned off at any time.

You can change these choices at any time — in Automater Lite under Settings → Diagnostics (one switch covers usage statistics and crash reports), in Automater Desktop under Settings → Telemetry (separate switches for crash reports and usage statistics, also offered during onboarding). Setting DO_NOT_TRACK=1 in the environment turns both off. The applications never record session replays.

6. Data Retention

Data class Retention
Encrypted database backups 30 days, then deleted
Account record Until you delete the account, plus 30 days for backup expiry
AppEvents (audit / activity timeline) Indefinite (used for support, fraud-prevention, and product analysis)
Email verification tokens 24 hours; the token field is set to NULL when you verify or when the link expires
Password reset tokens 1 hour; same null-after-use behavior
Stripe billing records Per Stripe’s retention policy and our tax obligations (typically 7 years)
Server logs 30 days
Sentry crash reports 90 days (Sentry default), unless required for active investigation
Application usage statistics — daily event counts 400 days, then deleted nightly
Application usage statistics — installation record (random identifier, version, OS, plan, country, first/last seen) Kept while the identifier is in use; orphaned when you reset it (turn statistics off and on) or uninstall; deleted on request with your support ID
PostHog analytics events (legacy web app, if you opt in) Up to 7 years per PostHog default; configurable on request
Google Analytics event-level data 14 months (GA4 “Event data retention” setting (confirm)); aggregated reports are retained by Google without a time limit
Google Signals data Held by Google under its own policy; remarketing audiences expire per audience definition (default 30 days) (verify)
Microsoft Clarity session recordings 30 days (verify); heatmaps and aggregated metrics 13 months (verify)

You may request earlier deletion of your account and its associated records by emailing [email protected]; see Section 8.

7. International Transfers

Some of our sub-processors are located in the United States or transfer data outside your country of residence. Specifically:

  • PostHog Cloud EU — analytics data is stored in the European Union (Frankfurt). No outside-EU transfer occurs for this data class.
  • Sentry SaaS (US region) — crash and error reports are stored on Sentry’s US infrastructure. Where required, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.
  • Stripe (US) — payment data is processed in the United States under SCCs and PCI-DSS controls.
  • Google (US) — website analytics and Google Signals data is processed by Google LLC in the United States. Google LLC is certified under the EU-US Data Privacy Framework and we rely on Google’s Standard Contractual Clauses (Google Ads Data Processing Terms) (verify current certification).
  • Microsoft (US) — Clarity recordings are stored on Microsoft infrastructure in the United States under the EU-US Data Privacy Framework and Microsoft’s Standard Contractual Clauses (verify).

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • access the personal data we hold about you;
  • correct inaccurate personal data;
  • request deletion of your personal data (“right to be forgotten”);
  • restrict or object to processing;
  • request a machine-readable copy of your data (data portability);
  • withdraw consent at any time, where processing is based on consent (you may also do this for analytics directly through the cookie banner);
  • lodge a complaint with your local data-protection authority.

Opting out of website analytics

  • Use the consent banner (EEA/UK/CH) or “Cookie settings” in the website footer to refuse or withdraw analytics, session-recording and advertising cookies at any time.
  • Install Google’s opt-out browser add-on: https://tools.google.com/dlpage/gaoptout.
  • Turn off Ads Personalization for your Google account: https://adssettings.google.com. How Google uses data from sites that use its services: https://policies.google.com/technologies/partner-sites.
  • Microsoft Clarity: Microsoft Privacy Statement https://privacy.microsoft.com/privacystatement, Clarity terms https://clarity.microsoft.com/terms, Microsoft ad settings https://account.microsoft.com/privacy/ad-settings.
  • Enable Global Privacy Control in your browser; we treat it as a refusal of advertising cookies and of any “sharing” under the CCPA.

Opting out of application usage statistics and crash reports

  • Automater Lite: Settings → Diagnostics → “Share anonymous usage statistics and crash reports”. Turning it off stops uploads immediately and deletes the locally buffered counts.
  • Automater Desktop: Settings → Telemetry (“Opt out of telemetry”), or the individual crash-report and usage-statistics switches shown during onboarding.
  • Any platform: set the environment variable DO_NOT_TRACK=1 before starting the application.
  • To have the statistics already stored under your installation deleted, copy your support ID from the same settings screen and email it to [email protected]. Because the identifier is random and unlinked to your account, we cannot find your data without it.

If you are a California resident, you also have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect about you, the right to delete it, and the right to opt out of any “sale” or “share” of personal information (see Section 4 regarding Google Signals).

To exercise any of these rights, email [email protected] from the email address associated with your account. We aim to respond within 30 days. A self-serve data-rights portal is on our roadmap; until it ships, all requests are handled manually.

9. Children

The Service is not directed to children under 13 (or 16 in the European Economic Area), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please email [email protected] and we will delete it.

10. Security

We use industry-standard measures to protect personal data, including TLS in transit, encrypted database backups, scoped database credentials, and least-privilege access controls. No system is perfectly secure; we encourage you to use a strong, unique password and to enable any multi-factor-authentication options we offer.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Effective date” at the top of this document and, if the changes are material, we will provide reasonable advance notice (for example, by email or by an in-app notice). Your continued use of the Service after the effective date of the revised Privacy Policy constitutes acceptance of that Policy.

12. Contact

Questions about this Privacy Policy or how we handle your personal data? Email [email protected]. For all other questions, email [email protected].

Automater

The free tray app that remembers what your AI agents forget.

ProductsAutomater LitePro Account CardsPricingRoadmap
CommunityIntelNewsletterLeaderboardContact Us
AccountSign inMy accountDownload Lite freeUpgrade to Pro
© 2026 Automater AIBuilt for local control.
PrivacyTerms
Desktop builds

Automater Desktop installers

Automater Desktop is in beta. Windows is signed and published. macOS is a prerelease. Linux is not built yet.

Checking updates.automater.ai for the latest Desktop builds.

Windows
Desktop for WindowsChecking updates.automater.ai…—
macOS
Desktop for macOSChecking updates.automater.ai…—
Linux
Desktop for LinuxChecking updates.automater.ai…—

Looking for the free tray app?Download Lite free

Available Desktop releases

Automater DesktopAutomater Desktop (beta)