In short
The on-device core sends nothing. Local inference, your vault, your documents and the model timings used to pick a local model never leave the handset.
A cloud request leaves your country and reaches a third-party AI provider under that provider's retention policy. We attach no profile, no account history and no advertising identifier to it.
We hold almost nothing about you — a purchase record and, if you email us, your support correspondence. No analytics, no prompt logs, no usage reports.
Zero-egress mode blocks the mesh entirely, so a prompt has no route off the device. That is the strongest control we offer and it is one switch.
What never leaves your device
- On-device inference. When Gestu answers locally, that request is never transmitted. There is no uplink on that path.
- Your vault and its contents. Documents, notes, chat history and anything else stored locally are encrypted at rest with AES-GCM and sealed with keys held in the device's hardware keystore. Those keys are non-exportable — not by an attacker, and not by us.
- Model performance timings. The app measures how fast models run on your hardware in order to decide which is fit to serve. That measurement stays on the device. It is never transmitted, and no report containing it exists.
- Telemetry and analytics. There is none. Gestu contains no analytics SDK, no crash-reporting SDK and no advertising identifier.
- Your API keys for bring-your-own-provider use. Held in the local keystore and used only to call the provider you configured.
What leaves it, and only when you choose
Gestu's cloud mesh exists so that hard questions can reach frontier models. When a request is routed to the cloud:
- The content of that request — your prompt, and any context needed to answer it — is sent to the selected third-party provider.
- It may cross national borders, because the providers in the mesh operate data centres in several jurisdictions. We do not restrict routing by country.
- It is then held under that provider's retention and training policy, not ours. Some providers may retain requests for abuse monitoring or service improvement; that is their policy and you should read it before sending anything sensitive. We name the providers in the app.
- We attach no profile, account history or advertising identifier to the request, and we do not retain a copy of its content on our own systems.
Zero-egress mode. Switch it on and the mesh is blocked: requests are forced onto the local path and there is no route off the device. Nothing in this section applies while it is on. Gestu states the consequence of the switch in both positions, because a control that only sounds reassuring when it is enabled is not a control.
What we actually hold
We deliberately keep this list short and specific:
- Purchase and entitlement records. That a subscription exists, its state, and a Google Play purchase token — needed to give you the service and to honour refunds. We do not receive your card number: Google Play handles payment and we never see payment instruments.
- Support correspondence. If you email us, we hold your address and the messages, so we can answer and keep a record of the fix.
- Token accounting for the cloud allowance. A count of cloud tokens consumed against your monthly allowance (see Terms). This is a number, not a record of what you asked.
We do not hold your prompts, your documents, your chat history, your location, your contacts, or a profile built from your behaviour.
Third-party providers
The cloud mesh routes to third-party AI providers, named in the app. When you use a cloud route you are also subject to those providers' terms and privacy policies, and their handling of a request is outside our control. This is the single most important limitation in this policy and it is why zero-egress mode exists.
Our website and app also load fonts and animation code from third-party content delivery networks. Those requests expose your IP address to the CDN in the ordinary way any web page does.
Payments
Subscriptions are sold and billed through Google Play Billing. Google processes the payment, handles renewals and cancellations, and is the merchant of record for the transaction. Their handling of your payment data is governed by Google's privacy policy. We receive only the entitlement and a purchase token, which we use to verify that your subscription is active.
Your choices and rights
Because we hold so little, most privacy rights are satisfied by the design rather than by a request form. Still, you can:
- Access or correct the account and purchase record we hold.
- Delete your data. Local data is deleted by uninstalling or clearing app storage — we cannot recover it, because we never had it. Account and purchase records are deleted on request, subject to records we must keep for tax and accounting law.
- Withdraw consent by not using cloud routes, or by enabling zero-egress mode.
- Ask us anything about this policy and get a straight answer.
Gestu is operated by a Canadian corporation and handles personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. You may contact us with a privacy question or complaint using the details below. If you are not satisfied with our response you may contact the Office of the Privacy Commissioner of Canada.
Cross-border transfer notice (PIPEDA). When you use a cloud route, personal information in that request is transferred to and processed in jurisdictions outside Canada, including the United States, and is subject to the laws of those jurisdictions. You can avoid this entirely by keeping work on the local core or enabling zero-egress mode.
Security
Local data is encrypted with AES-GCM at rest, with keys sealed in the device's hardware keystore and non-exportable. Vault integrity is verifiable on the device. Cloud requests are transmitted over TLS to the selected provider.
No system is perfect. We will not claim otherwise. If we ever become aware of a breach affecting personal information we hold, we will notify affected users and the relevant regulator as required by law.
Children
Gestu is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top and, for material changes, say so in the app before the change takes effect. We will not quietly widen what we collect.
Contact
⚠ REPLACE BEFORE PUBLISHING
- Legal entity
- [REGISTERED COMPANY NAME]
- Jurisdiction
- [PROVINCE], Canada
- Privacy contact
- [privacy@yourdomain]
- Support
- [support@yourdomain] · Mon–Thu, 10:00–19:00
- Mailing address
- [BUSINESS ADDRESS]
These fields are placeholders in the site source. A privacy policy must identify the organisation that is accountable for the information — fill them in before this page is public.