Privacy & security
Not a policy. An architecture.
ShogunAI sees your work all day. That only works if privacy is enforced by structure — where data lives, what never gets written, and what can never leave without you knowing.
What never gets stored — and what is
Audio is never stored
ShogunAI never writes meeting audio to disk — not as a file, not as a temp buffer. What persists is the transcript and where it came from. There is no code path that saves a recording.
These aren't settings. There is no code path that writes them.
Recordings are never made
There is no screen-recording feature and no video capture path. Nothing to disable, because it was never built.
These aren't settings. There is no code path that writes them.
Screens are stored only on your rules
Visual recall is off by default. Turned on, it reads your focused window with on-device OCR and keeps a compressed frame when text capture comes back empty or thin — fewer than 100 characters, or 400 while a meeting is being transcribed — when the window is a canvas-style app such as a design board or a browser document editor, and, during a meeting, when the window is a presentation or a shared screen. Excluded apps, terminals and password managers among them, are never captured. Frames stay encrypted on this Mac for the finite period you choose (presets 1–7 days plus custom, default 3 days); expiry always runs and cannot be disabled. Browse and delete them one by one in the timeline; turning Visual recall off wipes its frames immediately. Frames never leave this Mac. The text read from them joins your memory like any other captured text.
Every stored screen is encrypted, expiring, local — and yours to browse or delete.
One device. Every exit named.
Everything ShogunAI remembers lives in an encrypted database on your Mac. What leaves is the piece a task needs, sent only to the destinations named on this page, and each of those exits is recorded in an on-device traceability log you can read. The log keeps digests and flags, never the content itself. Anonymous product analytics and update checks carry none of your content and are not in the log.
Captured text is redacted before it is written, then stored in an encrypted database whose key lives in the macOS Keychain. Search and memory run locally. The diagram shows the five main flows off the device, each logged: agent requests to the AI provider you chose; service-funded AI work to Anthropic, with background tasks passing through the ShogunAI gateway; live meeting and dictation audio to Deepgram on your own key; dictated text to Groq if you add a key for optional formatting; and Gmail through Composio if you explicitly opted in. Audio files, screen frames, the search index, and your keys and tokens never leave.
Stored encrypted. Keyed to this Mac.
- The local database is encrypted; its key lives in the macOS Keychain.
- Secrets — AI provider keys, OAuth tokens — are stored only in the Keychain. Never in files, the database, or logs. Settings shows only the last 4 characters.
- Logs and telemetry never contain captured content, and the logging boundary force-masks emails, full URLs, and key-shaped strings.
- There is no ShogunAI cloud vault. Your memory has no server-side copy.
Every exit, in full
These are the services that receive data from your Mac: what goes, where, and why — and how to keep each one off. Every one of them is recorded in the traceability log.
Chat, actions and drafts — your AI provider
When you ask for something, the prompt and the context it needs go to the AI provider you chose: an assistant plan you already pay for, run through its official command-line tool on your Mac, or your own API key. Nothing is sent until you ask. Live meeting summaries and Quick Translate, once you turn them on or use them, go to the same provider on the same plan or key; live meeting translations sent over the network need your own API key.
Service-funded AI work — Anthropic
The nightly organisation, the Morning Brief, daily summaries, meeting recaps and mail sorting run on ShogunAI’s own AI capacity. Their working fragments go through the ShogunAI gateway in Tokyo, Japan, which forwards them to Anthropic and keeps only usage counts, request identifiers and digests — never the content.
Meeting notes and dictation — Deepgram
Transcription runs on your own Deepgram key, which you paste in Settings and which is stored in the macOS Keychain — ShogunAI holds no shared account of its own. While a meeting is transcribed, or while you hold the dictation shortcut, audio streams to Deepgram for live transcription only, with model-training use disabled. ShogunAI never writes the waveform to disk; what remains is the text. The UI shows when it is active, and without a key no audio is sent.
Dictation formatting — Groq (optional)
If you add your own Groq key, the text of a dictation is sent to Groq to clean it up before it is inserted. Without that key, nothing is sent for formatting.
Gmail — via Composio
Reading, drafting, and sending route through third-party infrastructure (Composio). Connecting requires explicit consent to three disclosures: third-party routing, the data types involved, and revocability at any time. Without consent, nothing syncs and nothing sends. Even read traffic is recorded in the traceability log.
Smaller paths, also logged: reads from other services you connect, only when you or an action you started asks for them; public web pages you paste into chat, off until you turn it on; and license checks and support reports you choose to send, to ShogunAI. Two kinds of traffic carry none of your content and are not in the log: anonymous feature-count analytics (on by default, one switch turns them off) and update checks.
Your data trains nothing
ShogunAI has no model of its own to train. The AI providers in the default configuration don’t train on your data either: Anthropic’s API does not use inputs or outputs for training by default, and meeting transcription is sent with training use disabled. Anthropic retains API data for about 30 days for abuse monitoring — we state it because it’s true, and because we can’t shorten it.
Your controls
Pause & exclude
Stop capture any time, from the notch or Settings. You can also name apps and websites that are never captured at all — the exclusion is applied before anything is written.
Delete
The last hour, the last 24 hours, or everything. Physical deletion — rows are removed, not flagged — done locally in seconds.
Choose
The AI that reasons for you runs on your own subscription or your own key. You decide the provider.
Inspect
Every outbound send except anonymous analytics and update checks appears in the traceability log; every stored screen appears in the timeline. Both readable on-device.
Nothing is sent on your behalf
Actions that leave your device — sending, posting, creating events — always stop for your explicit confirmation. Email additionally stops at a draft until you decide otherwise. The same gates apply when an AI reaches ShogunAI through its API.
The honest limits
- Chunks already sent to an AI provider follow that vendor’s retention policy (about 30 days at Anthropic, for abuse monitoring). Where a vendor has no deletion API, we cannot delete for you.
- Summaries derived from multiple events can echo deleted sources until the next nightly re-derivation.
- Anonymous usage statistics — feature counts only, never captured content, personal data, or keys — are sent by default. One toggle turns them off, in onboarding or Settings.
Frequently asked questions
What does ShogunAI actually capture?
By default, text — read through macOS Accessibility from the window you’re working in — plus metadata like app name, window title, and timestamps. With Visual recall on, it also keeps still frames when that text is missing or thin (fewer than 100 characters, or 400 during a transcribed meeting), for canvas-style apps such as design boards, and for presentations and shared screens during a meeting. Excluded apps are never captured. Every frame is encrypted, expires on your schedule, and stays on this Mac.
Does ShogunAI record my meetings?
No recording is ever saved. During a meeting, audio is streamed for live transcription only, with training use disabled, and the waveform is never written to disk. What remains afterwards is the transcript. Transcription uses your own Deepgram key, kept in the macOS Keychain; without it, nothing is transcribed and no audio is sent.
Where is my data stored?
In an encrypted database on your Mac. The key lives in the macOS Keychain. There is no ShogunAI cloud copy of your memory.
What leaves my device?
Agent requests, live meeting summaries and translations to the AI provider you chose; service-funded AI work (nightly organisation, the Morning Brief, meeting recaps) to Anthropic; live meeting and dictation audio to Deepgram on your own key; dictated text to Groq if you add a key for formatting; and Gmail through Composio if you explicitly opted in. Smaller paths: reads from services you connect, web pages you paste into chat when that is on, and license checks. All of these are recorded in an on-device traceability log you can read. Anonymous analytics and update checks carry none of your content and are not logged.
Is my data used to train AI models?
No. ShogunAI has no model to train, and default-configuration providers don’t train on your data either. Anthropic retains API data about 30 days for abuse monitoring — stated because it’s true.
Can ShogunAI send an email without me?
No. Outbound actions always stop for your explicit confirmation, and email additionally stops at a draft until you turn draft-stop off. The same gates apply to AI-initiated calls through the API.
How do I delete my data?
From Settings: the last hour, the last 24 hours, or everything. Deletion is physical — rows are removed, not flagged — and runs locally in seconds. Stored screens also expire automatically, can be deleted one by one from the timeline, and all of them are wiped the moment you turn Visual recall off.
Read the full policies
This page describes the design. Operation of the service is governed by the Privacy Policy and Terms of Service.
Questions: info@shogunaios.com
Services that process data
Stripe processes payments, subscriptions and tax. Cloudflare hosts the website and forwards email sent to our address. Fly.io hosts the AI gateway in Tokyo, Japan: it forwards the working fragments for background AI tasks (nightly organisation, the Morning Brief, daily summaries, meeting recaps and mail sorting) to Anthropic and does not store their content, only the usage counts, request identifiers and digests used to enforce plan limits. Supabase stores website, billing and support records. PostHog provides anonymous usage analytics (see Analytics choices). Resend delivers transactional mail and support email notifications. Anthropic processes the working fragments sent for service-funded AI tasks: nightly organisation, the Morning Brief, daily summaries, meeting recaps and mail sorting. Deepgram processes live meeting audio for transcription with your own key and model-improvement opt-out enabled; SHOGUN does not save audio files. Optional speech formatting sends dictation text to Groq using your key. Composio processes Gmail inbox reads, drafts and sends only after your three-part consent. Agent prompts and the relevant context go to the AI provider you choose, using your own subscription (through its official CLI) or API key. Live meeting summaries and Quick Translate go there the same way; live meeting translations go there with your own API key only. These services receive the data needed for their respective functions.
Analytics choices
Desktop feature-count analytics uses PostHog and is on by default. Turn it off during onboarding or in Settings → Privacy & Security; both controls update the same preference. Captured text, personal work content and keys are excluded. Website PostHog analytics is separate and off until you choose Allow. Use Analytics preferences to withdraw website consent. Website session replay and automatic text capture are disabled.
Saved screens and local deletion
Visual recall is off by default. If enabled, screenshots stay in the encrypted local memory database for 1–7 days or a custom period up to 3,650 days; the default is 3 days. Automatic age deletion stays on. At 2 GiB, new frames stop instead of deleting unexpired frames to make space. Screens are not uploaded. You can view and delete local frames and memory in Settings. Uninstalling the app alone does not delete Application Support data. Revoking Gmail consent stops subsequent sync and sending; remove its key separately in Settings if desired. Previously saved messages remain until you delete local memory.
Every model you use starts from zero. Give it your week.
Connect once, keep one private memory on your Mac, and let ShogunAI finish the work from there.
Joining the early-access waitlist is completely free.
macOS · 7-day full trial · your memory stays on your device.
