Last updated: 21 July 2026
Your data is yours. We don't sell it, we don't use it for advertising, and we don't use it to train AI models. The AI providers we route your requests through are bound by API terms that prohibit them from training on your data as well, and we never hand your data to other companies for their own use.
ClosedHand is an AI assistant that connects to your services, runs background agents on your behalf, and can optionally access your local computer. It works across chat platforms (WhatsApp, Telegram, Discord, Slack, LINE) and via the web at closedhand.ai. It is operated as a purpose-driven, independent project. We are not affiliated with any big tech company.
Account information: Your name and email address when you connect via Google or Microsoft. This is used to identify your account and nothing else.
Service connections: When you connect services like Gmail, Google Calendar, Slack, Shopify, or others, we store the authentication tokens needed to access those services on your behalf. These tokens allow ClosedHand to read and act on your data only when you ask, or when you have enabled proactive features like Pulse.
Conversation history: Your messages with ClosedHand are stored so the assistant can maintain context across conversations. This history is encrypted at rest and in transit.
Context Brain: Things ClosedHand learns about you (preferences, key contacts, important dates, project notes) are stored in your personal Context Brain. You can view, edit, and delete any of this at any time from your dashboard.
Location data: If you share your location, it is stored to help with location-based requests. Location data is used only for the specific request and retained only to avoid asking you repeatedly.
Agent data: When you create agents or team projects, the task descriptions, results, and status are stored in your account. These are visible on your dashboard and deletable at any time.
When you connect a Google account, ClosedHand requests the minimum set of OAuth scopes needed for the features you use. Each scope grants a specific, limited capability:
userinfo.email & userinfo.profile — read your email address, name, and profile picture. Used solely to identify your ClosedHand account and display your name in the dashboard.
gmail.readonly — read your email content, headers, labels, and attachments. Used to let you triage, search, and summarise your inbox through chat, and to power semantic recall (e.g. finding the flight booking you asked about). Nothing is sent to third parties beyond the AI provider processing your request.
gmail.send — send emails on your behalf. Only used when you explicitly ask ClosedHand to send or reply, and every send requires your explicit confirmation before it goes out. ClosedHand cannot silently send email.
calendar — read and manage events across all your calendars. Used to answer scheduling questions, create and update events on your request, and cross-reference bookings from email (flights, appointments).
drive.readonly — read files and metadata in your Google Drive. Used when you ask ClosedHand to find, open, or reference specific files. ClosedHand does not scan or index your entire Drive without your instruction.
drive.file — create and manage files that ClosedHand itself uploads (e.g. attachments saved from email into a "ClosedHand Attachments" folder). This scope grants access only to files the app creates, not to any of your existing files.
We do not request scopes for permanent deletion, sending on behalf without consent, or bulk export of your Drive. If you disconnect Google from your dashboard, the tokens are deleted from our systems and Google is instructed to revoke the grant.
Google API Limited Use disclosure: ClosedHand's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the user-facing features described in this policy; it is not transferred to third parties except as necessary to provide those features (AI processing under zero-retention or time-limited terms as described below), to comply with law, or as part of a merger or acquisition with prior notice; it is never used for advertising; and it is never used to train generalised AI or machine-learning models. Humans do not read your Google data except with your explicit permission, when required for security or legal reasons, or when aggregated and anonymised for internal operations.
If you install the ClosedHand Bridge app on your Mac (a Windows app is coming), ClosedHand can access your local files, terminal, and applications. This is entirely optional and requires explicit setup on your part.
What Bridge can access: Files and folders you have given permission to, terminal/shell commands, Calendar, Reminders, Contacts, Notes, and screen content. Each category has its own permission toggle that you control.
How it works: Bridge connects your computer to ClosedHand via a secure WebSocket connection. Data flows directly between your machine and our servers. We do not store your local files on our servers. File contents are read in real-time when requested and are not persisted beyond the immediate processing of your request.
You are in control: You can disconnect Bridge at any time. You can toggle individual permissions (Calendar, Files, Terminal, etc.) on or off from your dashboard. When Bridge is not running, ClosedHand has zero access to your computer.
Every user gets their own dedicated cloud computer for running code, processing data, and browsing the web. It is fully isolated: no other user can ever access it. It is persistent by design: files you or ClosedHand place in its workspace, and website logins made in its browser, remain stored on its private volume until you delete them. Deleting your account destroys the machine and its volume entirely.
You can extend ClosedHand by installing skills (instruction files) and MCP connections (external tool servers). All skills and MCP connections are scanned for security risks before activation. MCP servers are third-party services that you choose to connect. Their own privacy policies apply to data they process.
We don't track your browsing outside of ClosedHand, collect analytics or behavioural data, or build advertising profiles. Your data is never shared with third parties for any commercial purpose, and it is never used to train AI models.
Your data is used for exactly one purpose: to make ClosedHand useful to you. When you ask ClosedHand to check your email, it reads your email. When you ask about your calendar, it looks at your calendar. When you enable Pulse, ClosedHand periodically checks your connected services to alert you about things that need your attention. When you run a team project, ClosedHand coordinates multiple agents on your behalf and stores the results.
Chat and reasoning run on xAI's API. Background indexing and summarisation of your connected data (for search and recall) run on DeepInfra. Neither provider uses data sent through their API to train AI models: xAI retains API data for up to 30 days for abuse monitoring and then deletes it, and DeepInfra operates zero-retention inference. ClosedHand automatically selects the appropriate model for each request.
If you connect your own API key (Anthropic, OpenAI, or Google), your messages are processed by that provider under their own API terms. Note that Google's free API tier may use submitted data for product improvement; paid tiers do not.
All data is encrypted in transit (TLS) and at rest.
OAuth tokens (Google, Microsoft, Slack, and every other connected service) are encrypted at the application layer with AES-256-GCM before being written to our database, using per-record random initialisation vectors and authenticated encryption. The encryption key is held in an environment variable on our servers, is never committed to source code, and is separate from the database itself, so a database dump alone cannot reveal your tokens. Rotation of the encryption key is supported without any user action.
Bridge connections use secure WebSocket with token-based authentication. Destructive actions (sending emails, deleting events, running shell commands) require your explicit confirmation before execution.
You are always in control of what ClosedHand can access. There are two independent ways to revoke:
From your ClosedHand dashboard: Go to the Integrations tab, click the connected service, and click "Disconnect". This deletes the stored tokens from our systems immediately.
Directly from the third-party provider: You can also revoke ClosedHand's access from the service itself. For Google: visit myaccount.google.com/permissions, find ClosedHand, and remove access. For Microsoft: visit account.live.com/consent/Manage. For other services, use their standard account settings. Revoking at the provider immediately invalidates any tokens we hold.
To delete your entire ClosedHand account and all associated data, go to Settings and click "Delete all my data". This is irreversible.
You can view everything ClosedHand holds about you at any time from your dashboard, and wipe all your data at any moment from Settings. Deleted data is removed from our systems.
ClosedHand connects to third-party services (Google, Microsoft, Slack, Shopify, Meta, GitHub, and others) using their official APIs and OAuth flows. When you connect a service, you authorise ClosedHand through that service's own consent screen. You can revoke access at any time from your dashboard or from the third-party service directly.
You have the right to access all data we hold about you. You have the right to delete all your data at any time. You have the right to disconnect any service at any time. You have the right to export your data. If you are in the UK or EU, you have additional rights under GDPR, and we respect all of them.
If we make meaningful changes to this policy, we will notify you through ClosedHand directly. We will never quietly weaken your privacy protections.
If you have questions about your privacy or your data, send a message to ClosedHand using /feedback, or email [email protected].