Privacy Policy
Effective June 16, 2026
Our approach to privacy
Gbuild is built local-first. Wherever it is practical, your information stays on your own device, under your control. We collect as little as we can, we are clear about what we collect, and we never sell your personal information. This page explains, in plain language, what we handle and why.
This policy covers the Gbuild desktop app and the gbuild.app website. By using Gbuild, you agree to the practices described here.
What Gbuild never does
- We never sell your personal information.
- We never use your content to train our own models.
- We use no third-party analytics or ad trackers.
- We never access your device data without your explicit permission.
- No dark patterns or manufactured urgency.
Information you give us
Account information.
When you create an account or join the waitlist, we collect basic details such as your name and email address. You can sign in with Google, GitHub, Apple, or email — we use Supabase as our authentication provider and receive only the profile information you approve during sign-in. We never see or store your password for those services.
Conversations with G, your assistant.
When you talk or type to G, we process the content of those requests so Gbuild can respond and act on your behalf. This includes text you type and, where you use voice, the audio of what you say (see "Voice and audio" below for details).
Content you create.
Gbuild includes a creative studio for recording and editing video, generating images and video with AI, and building brand materials. The media you create and the prompts you use to generate it are handled as described in "How AI requests are handled" below.
Voice and audio
Gbuild is voice-first — you can talk to G using push-to-talk (the default) or, if you choose, always-on wake-word listening. Here is how audio is handled:
On-device speech-to-text and text-to-speech.
Gbuild includes fully on-device voice: speech-to-text (based on Whisper) and text-to-speech (based on Kokoro) that run directly on your Mac. When these are active, your audio stays on your device and is not sent to any server. Dictation and the composer default to the local speech-to-text model.
Interactive voice assistant (cloud by default).
The interactive sidebar voice assistant — where G speaks back to you in real time — defaults to streaming audio to OpenAI (Realtime API) for processing. When this mode is active, your voice audio is transmitted securely to that cloud provider. You can see which mode is active in the voice interface.
Offline / privacy mode.
There is a one-tap offline mode (and a cost-cap fallback) that forces all voice processing fully on-device — no audio leaves your Mac. You can enable this at any time in Settings.
Voice transcripts.
Voice transcripts are stored locally on your device and passed through redaction filters to remove sensitive content.
Information from your device, with your permission
Gbuild can work with information already on your Mac — but only with your explicit permission, one capability at a time. Your Mac will show its own permission prompt before Gbuild can access each type of information, and you can review or withdraw any permission at any time in macOS System Settings > Privacy & Security.
The device capabilities Gbuild may request access to include:
- Calendar — view your events so G can help you plan and schedule
- Contacts — look up people so G can help you reach the right person
- Reminders — view and manage your to-do items
- Notes — search and read your Apple Notes
- Mail — search your email to surface relevant messages
- Messages — read your iMessage and SMS conversations, and send messages on your behalf when you ask
- Photos — browse your photo library (metadata such as dates and locations)
- Spotlight / Files — search files on your Mac and watch folders you designate for changes
- Camera — for studio recording features
- Screen Recording — capture portions of your screen when you ask
- Location — for maps and location-aware features
- Automation (Apple Events) — control other apps on your behalf (for example, opening a file in a specific application)
- Login Items — let Gbuild start automatically when you log in
Gbuild never reaches this information without your explicit grant. Features that can act on your behalf — such as sending a message or running an automation — require your confirmation before they proceed. Agent-initiated actions that change your data are off by default and require you to approve them.
Connected services
Gbuild can connect to outside services — such as Notion, GitHub, Google, Asana, and many others (see the full list) — so G can work with your information across the tools you already use. Gbuild connects to these services only when you choose to, through each service's own secure sign-in (OAuth). We never see or store your password for any connected service.
With your permission, Gbuild accesses the data needed to do what you ask — for example, reading your Asana tasks, searching your Notion pages, or viewing your GitHub repositories. Actions that change your data (creating, updating, or deleting something in a connected service) are confirmed with you before they happen.
Access tokens for connected services are stored in your Mac's Keychain, not in plain files. You can disconnect any service at any time from Gbuild's settings; doing so removes the stored connection. The same principles apply to every service you connect: least access, clear purpose, and your control.
How AI requests are handled
On-device intelligence.
Several of Gbuild's capabilities run directly on your Mac using local AI models — including speech-to-text, text-to-speech, intent classification, and where your hardware supports it, local chat and embeddings for your project memory. When processing happens on-device, your data does not leave your Mac.
Cloud AI processing.
For requests that need larger cloud models — such as complex conversations, image generation, or video generation — your request is sent securely through Gbuild's own proxy gateway to the AI model provider that fulfills it, and the response is returned to you. Because requests route through our proxy, your own API keys never leave the server — they are not sent to providers directly from your device. We send only what is needed to answer your request.
Local Only mode.
Gbuild includes a Local Only mode that prevents any data from being sent to cloud AI providers. When enabled, all inference runs on-device, and captured conversations follow a strict on-device path. This is ideal for sensitive work or offline use.
Our commitment.
We do not use the content of your requests or your personal data to train our own AI models. Major cloud AI providers we work with (such as Anthropic and OpenAI) do not train on API data by default under their own published terms.
Second Brain: conversation capture
Gbuild can optionally capture and index your AI conversations — from Gbuild's own chat, from browser-based AI tools you use inside Gbuild (such as Claude or ChatGPT), and from conversation exports you import — to build a searchable personal knowledge base (your "Second Brain"). This feature is off by default for every source, and you must explicitly enable it per source in Settings.
Captured conversations are stored locally on your device. Before anything is stored, the content passes through multiple layers of secret redaction to remove credentials, API keys, and other sensitive patterns. The captured content feeds your local project memory and search — it is not sent to any external service for this purpose.
Studio recordings with guests (LiveKit)
Multi-guest studio recordings use LiveKit to carry participants' audio and video in real time. This is active only during a recording session you explicitly start with invited guests, and guest recording segments are staged to our cloud storage. Outside such sessions, no audio or video flows through LiveKit.
Built-in browser activity
When you use Gbuild's built-in browser, it keeps a local log of the page addresses and titles you visit inside it. This log is stored on your device and is never uploaded. Sensitive sites — including banking, password managers, government portals, and health services — are automatically excluded from the log.
Maps and location
Where you use Gbuild's maps features, your search queries and (with your permission) your location are sent to mapping service providers (such as Mapbox and Google Places) to return results. We do not store a history of your physical locations on our servers.
Obsidian sync
If you connect an Obsidian vault, Gbuild synchronizes project documentation bidirectionally with your vault's filesystem. This stays on your device — Gbuild reads and writes files in your local vault folder and does not send your Obsidian content to any external service.
Scheduled tasks and agents
Gbuild can run tasks on a schedule or through AI agents that work in the background. These tasks operate within the same permissions and data access you have already granted. Agents act on your behalf, and consequential actions require your approval. Background-task outputs stay on your device unless the task itself involves sending information externally (for example, posting to a connected service you have authorized).
How we use your information
We use the information described above to:
- provide, operate, and improve Gbuild and its features;
- carry out the tasks and requests you ask G to perform;
- keep Gbuild secure, reliable, and free of abuse;
- communicate with you about your account, updates, and support;
- meet legal and safety obligations.
We do not sell your personal information, and we do not use the private content of your work for advertising.
Diagnostics and crash reporting
Diagnostics are opt-in. In the shipped product, crash reporting and performance telemetry are off by default — they are shared only if you choose to turn them on, and you can change your choice at any time in Settings.
Internal or pre-release test builds may use different defaults (for example, diagnostics enabled for debugging). This policy describes the publicly shipped product.
If you opt in, we collect: a random install identifier (a UUID — not your name, email, or hardware serial number), crash and performance information, your hardware tier (so we can optimize for the machines people actually use), and process-health signals. All of this passes through secret-redaction filters before it leaves your device. We never collect file contents, conversations, API keys, or personal identifiers through diagnostics. We never use diagnostic data for selling or advertising.
Either way, we work to keep diagnostics free of the content of your work and your credentials: diagnostic data passes through redaction filters designed to strip sensitive details — including API keys, tokens, passwords, and personal content — before anything leaves your device.
How we store and protect your information
Local-first storage.
Your projects, conversations, memory, API keys, and settings live on your Mac. Project memory, captured conversations, and local AI model data are stored in your Mac's local filesystem and are not uploaded. Gbuild reaches the cloud only for: sign-in (Supabase, authentication only — no user content is written there), AI features you route to cloud providers, and optional diagnostics.
Secrets and credentials.
API keys, access tokens, and other credentials are encrypted at rest using Electron safeStorage (macOS platform encryption), with the macOS Keychain as a backstop — never stored in plain files. Gbuild also includes an on-device Vault that identifies and segregates sensitive files (financial, identity, and medical documents) so they are never accidentally commingled with ordinary project data.
No third-party analytics or tracking.
Gbuild uses no third-party analytics or tracking SDKs — no Google Analytics, no Mixpanel, no Amplitude, no Segment, no Sentry, and no ad trackers. The only telemetry is the opt-in diagnostics described above, sent to our own infrastructure.
Redaction.
Logs and diagnostics pass through dedicated redaction modules (both in the app and in the background service) designed to remove sensitive details before anything is stored or transmitted.
Security measures.
No system is perfectly secure, but we use reasonable technical and organizational measures to protect your information — including encrypted connections, per-feature permission gating, and defense-in-depth redaction — and we work to improve them over time.
How we share information
We share information only in these limited ways:
- AI model providers — when a request needs cloud processing, the content of that request is sent to the provider that fulfills it. We do not share more than what is needed, and we choose providers with appropriate data protections.
- Service providers who help us run Gbuild (such as cloud hosting, authentication, and content delivery), under agreements that limit their use of your information to providing those services.
- Services you connect — to do what you ask (for example, creating a task in Asana or updating a page in Notion).
- Mapping providers — search queries and location data when you use maps features.
- LiveKit — audio and video during multi-guest studio recording sessions you start.
- Legal and safety reasons — when we are required by law, or when we need to protect people from serious harm (such as reporting apparent child exploitation to the authorities as required by law).
We never sell your personal information.
Keeping and deleting your information
You stay in control. You can disconnect a service, clear your local data, or delete your account at any time.
- When you disconnect a connected service, the stored connection token is removed from your Keychain.
- When you disable a conversation-capture source, no new content is captured from it. Previously captured content stays on your device until you delete it.
- When you delete your account, we remove your personal information from our servers, except where we must retain some of it to meet legal obligations.
Local diagnostic and log data on your device is automatically pruned (roughly 7 to 30 days depending on the type). Server-side crash and diagnostic data is automatically deleted after 90 days.
Most of your data lives on your own device. Uninstalling Gbuild or deleting its local data removes that information from your Mac.
Your rights
Depending on where you live, you may have rights under laws such as the European Union's General Data Protection Regulation (GDPR), the UK GDPR, California's Consumer Privacy Act (CCPA), and similar laws. These rights may include the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- request deletion of your information;
- export your information in a portable format;
- object to or restrict certain uses of your information;
- withdraw consent you have previously given.
To exercise any of these rights, email [email protected] and we will respond as the law requires. We will not penalize you for exercising your rights.
International data transfers
Gbuild is developed in the United States, and some of our service providers (including cloud hosting and AI model providers) operate internationally. If your information is transferred outside your home country, we take steps to ensure it receives appropriate protection consistent with applicable data-protection laws.
Children's privacy
Gbuild is not directed to children, and we do not knowingly collect personal information from children under the age required by law in your region (under 13 in the United States, under 16 in many parts of Europe). If you believe a child has provided us information, please contact us at [email protected] and we will remove it promptly.
Changes to this policy
We may update this policy as Gbuild grows. When we make material changes, we will update the effective date above and, where appropriate, let you know in the app or by email. We encourage you to review this page periodically.
Contact us
For privacy questions or to make a data-rights request, email [email protected].
For legal notices, email [email protected].
For general support, email [email protected].