Privacy Policy
Effective July 31, 2026
This policy describes how ISPO Labs, Inc. (“ISPO,” “we,” “us”) handles information when you use the ISPO desktop application and the optional services available through it. The short version: ISPO is a local-first application. Your projects, files, and credentials live on your computer. We collect information only where a feature genuinely requires it, and we do not sell personal information or use it for advertising.
Data that stays on your device
The ISPO app stores the following locally on your computer. It is not transmitted to our servers:
- Your projects, project files, and app data.
- Permission grants and access decisions you make in the app.
- Credentials for connected services (for example Google account refresh tokens), encrypted at rest using your operating system’s secure storage.
- API keys you supply for third-party AI providers (“bring-your-own-key”). These are sent only to the provider you configured, never to us.
- Chat and agent session history.
Data we process for cloud features
If you sign in to ISPO Cloud, we process the minimum needed to operate each feature:
- Account. Your email address and name, managed through our authentication provider (WorkOS).
- Billing. Subscription and payment processing is handled by Stripe. We do not store your card details; we receive subscription status and usage totals for metering.
- Metered AI relay. When you use ISPO Cloud inference instead of your own API key, requests are relayed to the model provider and we record usage metadata (such as token counts) for billing. We do not retain your prompt or completion content.
- Sync and hosted runs. Data you explicitly enable for sync, and prompts you schedule for hosted agent runs, are stored to provide those features.
- Community chat and support. Messages you post to community channels and reports you submit to support are stored to provide those services.
- Software updates. Update checks hit our download servers and produce standard server logs (IP address, version, timestamp), retained briefly for operations.
Google user data
ISPO offers an optional Google Calendar connection. If you connect a Google account, the app requests access to your calendar list, calendar events, and free/busy information, plus your basic profile (email and name) to label the connected account.
- Calendar data is fetched on demand and displayed only inside your own apps, on your device. ISPO maintains no server-side copy, mirror, or background sync of your calendar data.
- Your Google refresh token is stored only on your device, encrypted with your operating system’s secure storage. Access tokens are held in memory.
- Individual apps you run inside ISPO can read or change calendar data only after you explicitly grant them access, per account and per operation, and you can revoke those grants at any time.
- We do not sell Google user data, use it for advertising, share it with third parties, or use it to train AI or machine-learning models.
ISPO’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect a Google account at any time in ISPO’s Settings, which deletes the stored token, or revoke ISPO’s access from your Google Account permissions page.
Telegram
If you enable the optional Telegram integration, messages, agent summaries, and remote commands travel through Telegram’s cloud service between your device and your Telegram account. Telegram’s own privacy policy applies to that transport.
Third-party AI providers
When ISPO sends prompts to an AI model — whether through your own API key or the ISPO Cloud relay — the content is processed by the provider you selected under that provider’s terms. ISPO does not choose providers for you and does not send your data to any provider you have not configured.
What we don’t do
- No sale of personal information.
- No advertising and no third-party ad trackers.
- No third-party analytics SDKs in the desktop app.
Retention and deletion
Local data remains yours and is deleted when you delete it. Cloud data is retained while your account is active. You can request deletion of your cloud account and associated data by contacting us at the address below; we delete it within 30 days except where retention is required for billing records or legal obligations.
Security
Credentials are encrypted at rest with operating-system secure storage. Traffic between the app and our services, and between the app and connected providers, uses TLS. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
Children
ISPO is not directed to children under 13, and we do not knowingly collect personal information from them.
Changes
We may update this policy as the product evolves. We will post changes on this page and update the effective date; material changes will be called out in the app or by email.
Contact
ISPO Labs, Inc. — team@ispo.ai