Privacy Policy
Last updated: 8 July 2026
CMD + J is a macOS writing assistant. You press a shortcut in any app, sketch a rough note, and CMD + J drafts a reply in your own voice — grounded in the conversation you are already looking at. This policy explains what data the app touches, where it is processed, what is stored, and the choices you have. We built CMD + J to be local-first: it reads a conversation only while you are actively replying to it, and only the minimum needed to draft that reply leaves your Mac.
The service is operated by Milsztein Ventures UG (haftungsbeschränkt), trading as aurio (the "operator", "we", "us"), which is the data controller for the purposes of the EU General Data Protection Regulation (GDPR). Full operator details are in our Imprint. Contact: accounts@aurio.ai.
1. Data CMD + J accesses
CMD + J only accesses a source after you explicitly connect it, and it uses read-only access:
-
Connected messaging & email (Slack, Gmail, Microsoft Teams, Outlook).
When you ask CMD + J to draft a reply, it reads the conversation you are replying to
so the draft fits the thread. To learn how you write, it also reads a sample of
your own recently sent messages from the sources you connect. Google (Gmail) access
uses the read-only
gmail.readonlyscope; Slack access uses read-only history and directory scopes (channels/groups/im/mpim:history,users:read,search:read). CMD + J never sends, deletes, or alters your messages. - On-screen content (optional). If you grant macOS Screen Recording, CMD + J can capture a still image of the window you are in as a fallback context source (for apps without a connected integration). This image is used only to draft the current reply and is not stored.
- Accessibility. CMD + J uses the macOS Accessibility API to read the text field you are in and to insert the finished draft at your cursor. This happens on your Mac.
- Account. To sign in you provide your email address; we send a one-time code to verify it. We use the email to create your account and manage fair-use limits.
- Diagnostics. The app records limited, non-content usage signals (e.g. response latency, which integration was used, error codes). These contain no message content.
2. How your data is processed
Reading and matching context happens on your Mac. To generate a draft — and to build your voice profile from your sent messages — the relevant conversation context and your rough note are sent to Anthropic (the maker of Claude) through aurio's relay service, which returns the drafted text. This is the only step in which message context leaves your device, and it happens each time you ask for a draft.
Under Anthropic's commercial API terms, the inputs and outputs sent to the Claude API are not used to train Anthropic's models. aurio's relay acts as a stateless proxy: it forwards your request to Anthropic and returns the result, and does not store the content of your conversations or drafts.
Legal bases (GDPR Art. 6(1)). We process this data to perform the service you requested (Art. 6(1)(b)) and, for diagnostics and abuse prevention, on the basis of our legitimate interest in keeping the service reliable and secure (Art. 6(1)(f)). Connecting an integration is your consent (Art. 6(1)(a)); you can withdraw it at any time by disconnecting.
3. What is stored, and where
- Access tokens for the sources you connect are stored in the macOS Keychain on your Mac. They are not uploaded to aurio.
- Your voice profile and a local corpus of your own sent messages (used to match your style) are stored on your Mac, encrypted at rest. They are not uploaded to aurio.
- The conversation you are replying to is read in the moment, used for that draft, and not persisted by the app or the relay.
- Your account email and non-content usage counters are stored by aurio to run your account.
4. Who we share data with
We do not sell your data and do not share it for advertising. We rely on a small set of processors:
- Anthropic — processes the prompt content needed to generate your drafts (Claude API); does not train on it.
- Vercel — hosts aurio's relay and this website.
- Slack, Google, Microsoft — the platforms you choose to connect are the sources of the context you ask us to read.
Because Anthropic and Vercel are based in the United States, connecting to them involves an international data transfer, carried out under the EU Standard Contractual Clauses.
Google user data — Limited Use
CMD + J's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained from Gmail is used only to provide the in-app reply-drafting feature at your request; is not transferred to others except as necessary to provide that feature, to comply with applicable law, or as part of a merger; is not used for advertising; is not used to develop, improve, or train generalized AI/ML models; and is not read by humans unless you give consent, it is necessary for security or to comply with law, or the data is aggregated and anonymized.
5. Retention
Conversation context is not retained after your draft is produced. Your local voice profile and message corpus stay on your Mac until you clear them (Settings → clear learning data) or delete the app. Access tokens remain in your Keychain until you disconnect the integration. Your account email is kept until you ask us to delete your account.
6. Your choices & rights
- Disconnect any integration at any time in Settings — this revokes CMD + J's access token for that source.
- Clear learning data to erase the locally stored corpus and voice profile.
- Sign out, or email us to delete your account and associated email.
- You can revoke app access directly at your provider: Google, your Slack workspace's app settings, or Microsoft's My Apps.
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. To exercise any of these, email accounts@aurio.ai. You may also lodge a complaint with your local data-protection supervisory authority.
7. Security
Access tokens live in the macOS Keychain; your local corpus and voice profile are encrypted at rest; and all network traffic to the relay and to Anthropic is encrypted in transit (TLS). No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your data.
8. Children
CMD + J is not directed to children and is not intended for anyone under 16.
9. Changes to this policy
If we change how we handle data, we will update this page and revise the "last updated" date above. Material changes will be communicated in the app or by email where appropriate.
10. Contact
Questions about this policy or your data: accounts@aurio.ai. Full operator details are in our Imprint.