Privacy-First Architecture

Privacy Policy

Last updated: September 15, 2026 • Effective Date: September 15, 2026

Key Highlights at a Glance

Self-Hosted & Local Storage

Your chat records, semantic facts, and account profile are stored locally in your instance database under your server control.

No Sale of Personal Data

We never sell, rent, monetize, or broker your personal information or conversation history to third parties or advertising networks.

Full User Control

You can view, export, or permanently delete your conversations, extracted memories, locations, and account data at any time.

1. Introduction & Overview

Welcome to PAA Agent ("Personal Artificial Assistant Agent", "we", "us", or "our"). This Privacy Policy explains how we collect, use, store, and safeguard your information when you access or use the PAA Agent web application, APIs, and associated services.

PAA Agent is architected with a privacy-first approach. Designed as a self-hosted or enterprise-hosted personal AI platform, the application provides you with granular transparency and direct administrative control over your data, conversations, and automated workflows.

2. Information We Collect

Depending on how you configure and interact with the service, we may collect and process:

  • Account Information: Your email address, username or display name, and securely hashed passwords (using cryptographic password hashing). If Google OAuth authentication is enabled by the administrator, we receive your verified Google email address, basic profile name, and profile picture avatar.
  • Conversations & Transcripts: User messages, chat queries, system prompt configurations, audio recordings (when using voice input for speech-to-text transcription), synthesized audio files, uploaded attachments, and agent-generated responses.
  • Memory & Knowledge Graphs: Semantic facts extracted from conversations (e.g., user preferences, stated interests, project details), reflective strategic insights, procedural routines, and episodic summaries.
  • System, Device & Usage Logs: IP address, browser type and version, operating system, network connection events, WebSocket connectivity, and application error logs.
  • Integration & Trigger Data: Webhook payloads, external trigger requests (alarms, price tracking alerts, reminders), API access keys, and configured third-party service tokens.

3. How We Use Your Information

Your data is processed strictly for providing and improving your assistant capabilities:

  • Facilitating real-time streaming conversations and executing agentic tools (calculators, web searches, sandboxed coding environments).
  • Providing contextual personalization across sessions through semantic fact retrieval and memory ranking.
  • Executing automated background jobs, such as conversation auto-summarization, vector embedding generation, and periodic idle-maintenance.
  • Delivering notifications, alarms, and alerts requested by you or received through authorized webhook integrations.
  • Enforcing multi-user security boundaries, access controls, and role-based permissions (user vs. administrator).

4. AI Models & Third-Party Providers

PAA Agent connects to Large Language Models (LLMs) to generate responses. Depending on the system configuration chosen by the instance administrator:

Local & Self-Hosted Models (Ollama / llama-server)

When configured with local models, prompts and context remain entirely within your local private infrastructure and are never transmitted over the internet to third-party AI companies.

External Cloud Providers (Anthropic, OpenAI, OpenRouter, MiniMax)

When using cloud provider endpoints, relevant conversation context, instructions, and user messages are sent via secure API calls. Cloud providers are governed by their respective business terms and privacy policies. Commercial enterprise APIs (e.g., Anthropic Claude API, OpenAI API) explicitly specify that customer API data is not utilized to train foundation models.

5. Memory Systems & Personalization

PAA Agent incorporates an autonomous multi-tier cognitive memory architecture:

  • Semantic Memory: Discovers facts regarding personal preferences, technical stacks, or project goals. Users can review, edit, or delete any discovered fact via the Memory control panel.
  • Reflective & Procedural Insights: Evaluates which tool execution chains succeed or fail, storing operational heuristics to improve assistant reliability over time.
  • Automatic Decay & Consolidation: Stale facts and unreinforced insights naturally decay in confidence or are consolidated, preventing outdated records from persisting indefinitely.

6. Geolocation & Device Data

PAA Agent includes an optional location service to furnish accurate local weather, timezone awareness, or geo-specific agent context.

Explicit Consent Required: Geolocation is never queried or transmitted without your explicit opt-in confirmation. You may grant or revoke location permissions at any moment in your browser or through the Settings → Location interface, and delete recorded location points immediately.

7. Data Storage, Security & Retention

We implement comprehensive technical and organizational safeguards:

  • Local Database Isolation: Conversation histories, user tables, and settings are stored in SQLite via Drizzle ORM on the hosting server filesystem.
  • Sandboxed Code Execution: When using development or coding agents (CoderAgent), code runs in isolated Docker containers with strict security constraints to prevent host system compromise.
  • Secure Communication: All transmissions between your client browser and the server are encrypted using Transport Layer Security (TLS/HTTPS).
  • Credential Protection: Passwords are cryptographically hashed; external API keys are stored server-side and never exposed to unauthenticated clients.

8. Your Rights & Data Portability

You have full autonomy over your data:

  • Export: You can export your conversations, memories, and profile data in standardized JSON formats at any time.
  • Deletion: You can delete individual messages, entire conversation threads, or wipe all conversation history via the Settings menu.
  • Correction: You can inspect and update your memories, preferences, and personal details directly.
  • Revocation: You can revoke device permissions (Web push notifications, audio microphone, geolocation) at any time.

9. Cookies & Authentication

PAA Agent uses minimal, strictly functional cookies essential for operating the platform securely:

  • paa_session: An encrypted HTTP-only session cookie that verifies your authenticated user session.
  • paa_accounts: A cookie managing linked multi-account switching capabilities.

We do not use advertising, tracking, or marketing cookies.

10. Changes & Contact Information

We may update this Privacy Policy from time to time. Any revisions will be reflected on this page with an updated effective date.

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data handling, please contact your instance administrator or reach out via your deployment's administrative channels.