Legal

Privacy Policy

Last updated: 8 July 2026

CMD + J is a macOS writing assistant. You press a shortcut in any app, sketch a rough note, and CMD + J drafts a reply in your own voice — grounded in the conversation you are already looking at. This policy explains what data the app touches, where it is processed, what is stored, and the choices you have. We built CMD + J to be local-first: it reads a conversation only while you are actively replying to it, and only the minimum needed to draft that reply leaves your Mac.

The service is operated by Milsztein Ventures UG (haftungsbeschränkt), trading as aurio (the "operator", "we", "us"), which is the data controller for the purposes of the EU General Data Protection Regulation (GDPR). Full operator details are in our Imprint. Contact: accounts@aurio.ai.

1. Data CMD + J accesses

CMD + J only accesses a source after you explicitly connect it, and it uses read-only access:

2. How your data is processed

Reading and matching context happens on your Mac. To generate a draft — and to build your voice profile from your sent messages — the relevant conversation context and your rough note are sent to Anthropic (the maker of Claude) through aurio's relay service, which returns the drafted text. This is the only step in which message context leaves your device, and it happens each time you ask for a draft.

Under Anthropic's commercial API terms, the inputs and outputs sent to the Claude API are not used to train Anthropic's models. aurio's relay acts as a stateless proxy: it forwards your request to Anthropic and returns the result, and does not store the content of your conversations or drafts.

Legal bases (GDPR Art. 6(1)). We process this data to perform the service you requested (Art. 6(1)(b)) and, for diagnostics and abuse prevention, on the basis of our legitimate interest in keeping the service reliable and secure (Art. 6(1)(f)). Connecting an integration is your consent (Art. 6(1)(a)); you can withdraw it at any time by disconnecting.

3. What is stored, and where

4. Who we share data with

We do not sell your data and do not share it for advertising. We rely on a small set of processors:

Because Anthropic and Vercel are based in the United States, connecting to them involves an international data transfer, carried out under the EU Standard Contractual Clauses.

Google user data — Limited Use

CMD + J's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained from Gmail is used only to provide the in-app reply-drafting feature at your request; is not transferred to others except as necessary to provide that feature, to comply with applicable law, or as part of a merger; is not used for advertising; is not used to develop, improve, or train generalized AI/ML models; and is not read by humans unless you give consent, it is necessary for security or to comply with law, or the data is aggregated and anonymized.

5. Retention

Conversation context is not retained after your draft is produced. Your local voice profile and message corpus stay on your Mac until you clear them (Settings → clear learning data) or delete the app. Access tokens remain in your Keychain until you disconnect the integration. Your account email is kept until you ask us to delete your account.

6. Your choices & rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. To exercise any of these, email accounts@aurio.ai. You may also lodge a complaint with your local data-protection supervisory authority.

7. Security

Access tokens live in the macOS Keychain; your local corpus and voice profile are encrypted at rest; and all network traffic to the relay and to Anthropic is encrypted in transit (TLS). No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your data.

8. Children

CMD + J is not directed to children and is not intended for anyone under 16.

9. Changes to this policy

If we change how we handle data, we will update this page and revise the "last updated" date above. Material changes will be communicated in the app or by email where appropriate.

10. Contact

Questions about this policy or your data: accounts@aurio.ai. Full operator details are in our Imprint.