Privacy and data

Privacy Policy

Last updated: July 2026

Assistela is a personal assistant for Mac and iPhone. It is designed so the main workspace data stays local on your devices, while the remote server is used only where an account, optional Managed AI or message delivery between devices is needed.

Local-first base

History, memory, files and assistant settings are stored primarily on your Mac, or inside the iOS app.

Encrypted device connection

Messages, attachments and requests between iPhone and Mac are encrypted so the delivery server cannot read their contents.

Controlled AI processing

Managed AI selects suitable models, while the server stores mainly operational usage data.

Operator and data controller

The operator of the Assistela app and service and the data controller is Giga Media Business, spol. s r.o., U valu 862/2, Ruzyně, 161 00 Prague 6, Czech Republic, Company ID: 26898756, VAT-ID: CZ26898756.

For general support, contact support@assistela.com. For privacy questions or requests related to server-stored Assistela data, contact privacy@assistela.com.

Local data

Assistela stores its main workspace data locally on your Mac. This can include conversation history, assistant memory, summaries, settings, approvals, local databases, files, attachments and application logs.

The iOS app stores its own local chat history, attachments, app settings, pairing state and optional shared-location text.

Sensitive keys and access credentials are stored in macOS Keychain or in the local Assistela database depending on the selected mode. On iPhone, the pairing token and encryption key are stored in iOS Keychain and are available after the device is first unlocked.

Assistela account

If you use an Assistela account, we store data needed for sign-in, optional Managed AI credit management and service operation. This includes your email, password hash, account status, connected devices, credit balance and basic usage summaries.

Session tokens and pairing tokens are stored on the server as hashes. Assistela does not directly process payment card data; payments and the customer billing portal are handled by Stripe.

Managed AI

If you use Assistela Managed AI, our service selects a suitable AI model according to configured rules and forwards the request to it.

Assistela does not store the full Managed AI conversation content in the database. We store operational data needed for limits, billing and cost verification: request ID, AI service and model, input type, token counts, cost, status and technical metadata.

The request content is sent to the selected AI service so the model can answer. If you use your own API keys or AI service, processing is also governed by that service's terms.

For image requests, Assistela may temporarily prepare an image in the format required by a particular AI service. These temporary files are deleted after the request completes.

iPhone and Mac connection

The iOS app communicates with the Mac app through the Assistela delivery service. During normal use, the service transfers encrypted data between paired devices and does not act as a permanent conversation archive.

Text, attachments and requests between devices are encrypted with ChaCha20-Poly1305 during normal pairing. The encryption key is created during pairing and stored only on the paired devices.

The delivery service processes only technical data needed to sign in the device and deliver data, such as an access-token hash, device identity, time, data type and size, or delivery status. It cannot read message or attachment contents sent through the encrypted connection.

If a device is temporarily unavailable, pending encrypted data remains in the sending app's local storage; the delivery server does not persist its contents. The app may retain it locally only as long as needed to retry delivery, for no more than 7 days, while some request types expire sooner. After delivery is confirmed, the corresponding records are cleaned up according to the app lifecycle. Pairing codes expire after 10 minutes and inactive server records are cleaned up over time.

Notifications

We use Apple Push Notification service for iPhone push notifications. The server sends a generic notification such as a new message or approval request.

When a reply preview is available, it is sent in encrypted form and decrypted only on the device using the pairing key stored in Keychain.

Form protection, analytics and cookies

The website, portal and administration may use technical cookies and similar technologies needed for sign-in, language, security, billing, abuse protection and service operation.

We use Cloudflare Turnstile on sign-in, registration and administrator forms. It helps distinguish normal users from automated abuse, and Cloudflare may process technical signals about the request, browser, device or network connection.

In the future, we may use Google Analytics or similar analytics on the website and portal to measure traffic, website performance and feature usage. Analytics will not use your message contents for advertising profiling. If consent is legally required, we will provide the appropriate choice.

User location

Location sharing is optional. After you grant permission, the iOS app can obtain approximate location through Apple CoreLocation and convert it locally through Apple geocoding into text such as street, city, postal code or country.

Assistela does not send readable GPS coordinates to the delivery service. Text location is synchronized to the Mac app through the encrypted connection, so the delivery service cannot read its value.

On Mac, location is stored as text in local preferences. It is added to the assistant request only when location sharing is enabled. If a reply is then generated through an AI model, this text location may be part of the request sent to the selected AI service.

Telegram and other integrations

If you enable Telegram, email, calendar, reminders, contacts, browser, Home Assistant or other integrations, Assistela can work with data from those services according to your settings and the permissions you grant in the system or service.

The server service for Telegram temporarily retains incoming messages and attachments until the Mac fetches them or their retention period expires. Email, calendar, reminders and similar sources are included in replies according to app settings and the selected AI model's capacity.

Demo mode

The iOS demo mode uses sample data and local demo replies. Demo replies are not generated by an AI model and demo messages are not sent to the normal queue for other devices.

No advertising profiling of content

Assistela is not built around advertising tracking of content. We do not use message content for advertising profiles and Assistela does not train its own AI models on user content.

Security

Network communication uses HTTPS. API keys for AI services stored in server administration are encrypted with AES-256-GCM. Local security also depends on the security of your device, operating system, Keychain and third-party accounts.

Your control and contact

In the app, you can manage connected accounts, devices, assistant memory, stored files, history, location and other settings. Signing out or removing a device revokes its access to the account or remote connection.

If you have a privacy question or want to request removal of an account or server-stored Assistela data, contact privacy@assistela.com. For general support, contact support@assistela.com.