Privacy Policy

Effective Date: May 1, 2026

Dessix Ltd. (“Dessix,” “we,” “our,” or “us”) respects your privacy. This Policy explains how information moves through Dessix’s local-first Space runtime, cloud account services, device relay, connectors, and optional paid AI services.

1. Scope and who controls your data

This Policy applies to dessix.ai, the Dessix desktop application and CLI, the Dessix Gateway, and related services. Dessix Ltd. is the controller of personal data held for Dessix accounts, billing, communications, and service operation. A third-party AI, connector, or account provider may act as a separate controller under its own terms when you choose to use that provider.

2. Information we process

Account and profile information

  • Your email address, display name, profile text, avatar reference, sign-in methods, and email verification state.
  • Onboarding information you submit, such as your role, intended use, how you found Dessix, contact channels, and separate choices for research invitations and product updates.
  • Authentication and security records, including password hashes, short-lived action token hashes, sign-in method events, and rate-limit records. Plaintext passwords and one-time action tokens are not stored.

Local Space and agent data

Spaces, timelines, agent memory, local folders, credentials, and runtime-native sessions are stored on the device running your Dessix daemon. They remain under your control in local files until you edit or delete them. Dessix may read and send the portions you direct an agent to use when performing a request.

Device and relay information

When you pair a device, we keep its Dessix device identifier, name, platform, hostname, last-seen time, revocation state, and public encryption key. Browser-to-device traffic uses an end-to-end encrypted relay. The Gateway routes encrypted frames and maintains connection metadata; the private key needed to open those frames remains on your device.

AI requests, connectors, and files

When you run an external runtime such as Claude Code, Codex, or Pi Agent, the runtime and AI provider you selected receive the prompts, file excerpts, tool inputs, and outputs needed to perform the run. When you use the Built-in Agent, the Dessix Gateway forwards request content to our AI routing and model providers and streams the response back. We retain billing and operational metadata for that request, such as model, token counts, cost, status, and time; the Gateway billing ledger does not store prompt or response bodies.

If you connect an external service through Composio or another connector, Dessix forwards the tool call you authorize and returns its result to the active Space. The connected service and connector provider process that data under their own terms.

Billing, communications, and technical information

  • Membership status, Stripe customer and payment references, wallet lots and balances, refunds, model usage, discounts, and billing ledger entries. Stripe receives your full payment-card details directly.
  • Transactional email delivery records, marketing or research consent history, bounce and complaint status, and suppression records used to honor delivery choices.
  • Standard request and security metadata processed by our hosting and network providers, including IP address, browser or client information, timestamps, and request status.

3. How we use information

  • Provide accounts, authentication, device pairing, encrypted relay, and support.
  • Run the agents, AI requests, and connector actions you initiate.
  • Operate memberships, wallet credits, metered Built-in Agent usage, and refunds.
  • Send transactional messages and the optional research or product communications you select.
  • Protect the service, prevent fraud and abuse, diagnose failures, and keep audits.
  • Comply with law and establish, exercise, or defend legal claims.

4. Legal bases in the UK and EEA

  • Contract: accounts, authentication, paired-device relay, agent or connector requests, paid features, and support you ask us to provide.
  • Consent: optional research invitations and product communications. You can withdraw that choice in Dessix settings or through the unsubscribe mechanism in an email.
  • Legitimate interests: securing the service, preventing fraud and abuse, diagnosing failures, and improving reliability, balanced against your rights and expectations.
  • Legal obligations and claims: tax, accounting, regulatory requests, and establishing, exercising, or defending legal rights.

5. Service providers and disclosures

Provider or categoryPurpose
CloudflareSite hosting, Gateway, network protection, database, and storage
GoogleOptional account sign-in
ResendTransactional email, contacts, and email preferences
StripeMemberships, wallet payments, billing portal, and refunds
OpenRouter and model providersBuilt-in Agent routing and AI inference
Composio and connected servicesConnector authorization and tool execution
Your selected runtimes and AI providersExternal agent and model execution

We may also disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards. We do not sell personal information or use it for targeted advertising. As of the Effective Date, dessix.ai does not run behavioral advertising or product-analytics trackers.

6. Cookies and local preferences

Dessix uses cookies required for sign-in, session security, OAuth flows, and request protection. The web and desktop interfaces use local storage for device-level preferences such as theme, language, notifications, and navigation state. These technologies support the service rather than advertising.

7. Retention and deletion

  • Local Space and runtime data remains on your device until you remove it.
  • Account, device, connector, and membership records are kept while needed to provide the service and resolve account or security issues.
  • Billing, refund, fraud-prevention, and audit records may be kept for tax, accounting, dispute, and legal requirements.
  • Email suppression records may be retained as needed to keep honoring an opt-out or a delivery complaint.

To request deletion of cloud account data, contact us using the address below. We may ask you to verify the account and may retain limited records where law or a legal claim requires it. Removing cloud account data does not automatically remove files stored on your own devices.

8. International transfers and security

Providers may process data outside the United Kingdom or EEA. Where required, we use an approved transfer mechanism such as Standard Contractual Clauses and the UK Addendum or rely on another lawful safeguard. We use access controls, encryption in transit, encrypted device relay, hashed credentials, and operational controls appropriate to the information involved. No security method can guarantee absolute protection.

9. Your rights

Depending on where you live, you may have rights to access, correct, erase, restrict, or object to processing; receive portable data; withdraw consent; and complain to a data protection authority. Send requests to [email protected] with the subject “Data Subject Request.” We may verify your identity before acting.

10. Children and changes

Dessix is intended for people aged 16 or older. We may update this Policy as the service changes. The current version will remain posted here with its effective date, and we will provide additional notice when a material change requires it.

11. Contact

Data controller: Dessix Ltd. (company number 16167530). Email: [email protected]. Registered office: 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom.

DESSIX LTD · Company number: 16167530 · Registered office: 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom.

Questions about this statement can be sent to [email protected].