Anydo Legal

Privacy Policy

This policy explains how we collect, use, store, share, and protect your information, along with the responsibilities you must bear when using Anydo securely.

Effective date:
2026-08-17
Version:
2026-08-17

Key Points

  • We will handle account, session, machine, file, sandbox, API calls, and billing-related data as required for providing services.
  • AI models and third-party services may process the Prompt, code snippets, context, or file content you actively submit.
  • Please avoid uploading unnecessary sensitive information, production credentials, private keys, Tokens, or restricted data.

1. Overview

This Privacy Policy explains how we collect, use, store, share, and protect your information. Anydo is a service for AI programming, remote agent control, terminals, sandboxes, and API agents; therefore, it may process your code, commands, files, sessions, machine information, and model invocation data.

We will do our best to protect your privacy, but you should also understand that AI agents, remote terminals, local machines, public tunnels, third-party models, self-hosted environments, and user-authorized commands carry inherent security risks.

Operator and Contact Information

Operating Entity
Genvas Technology Pty Limited
Chinese Name
即畫科技有限公司
Registered Address
Unit 29, 13/F, Fook Cheong Building, No. 63 Hoi Yuen Road, Kwun Tong, Hong Kong
Contact Email
info@anydo.io

2. Information We Collect

We may collect the following types of information based on the features you use:

  • Account information: email, nickname, profile picture, phone number, login status, role, permissions, team space, invitation relationships, authentication status.
  • Authentication and security information: IP address, device identifier, browser, system, language, login time, login history, failed attempts, API Key, CLI code, machine ID, Token metadata, security logs, risk control records, request ID.
  • AI agent conversation data: conversation title, project path, machine name, user messages, Prompt, AI response, tool invocation, permission request, approval result, model configuration, terminal output, command results, Git status, diff, file search results.
  • Files and attachments: uploading files, images, documents, object storage keys, preview URLs, file names, size, MIME types.
  • Local machine and remote control data: hostname, operating system, agent status, runner status, heartbeat, local port, preview port, tunnel status, and records of remote spawn/resume/abort operations.
  • Sandbox and computing resource data: sandbox ID, image, template, specifications, container/virtual machine status, CPU, memory, disk, network usage, terminal records, file operations, runtime logs, automatic shutdown, and billing statistics.
  • API proxy and model invocation data: model name, Token usage, costs, latency, error codes, invocation logs, upstream service information, and processing of request bodies and model context when necessary;
  • Payment and bill information: packages, orders, invoices, payment status, limits, usage, balance, and refund records. Complete bank card details are typically processed by the payment service provider; we do not store the full card number directly.
  • Communication Information: Information provided by you through email, customer service, feedback, work orders, communities, or other channels.
  • Voice and media data: microphone audio used for voice input or meeting transcription, transcripts, voice correction terms, and photos you take or files you choose to attach. Device biometric authentication such as Face ID is handled by your device; we do not receive your facial or fingerprint data.
  • Notification and purchase data: Web Push, APNs, or FCM subscription tokens, installation ID, platform, app version, notification preferences, store product and subscription status, transaction identifiers, and purchase tokens or receipts used to verify purchases.
  • Connected app data: connection name, provider account metadata, granted permissions, OAuth or API credentials, and the requests, results, or audit records needed to perform actions you authorize. The service may access third-party email, calendar, chat, document, source-control, or other content only when needed for the feature or action you request.

3. Cookies, Local Storage, and Similar Technologies

We may use cookies, localStorage, sessionStorage, IndexedDB, Service Worker cache, device IDs, or installation IDs. These are used for maintaining login status, language settings, themes, layouts, recent paths, drafts, terminal preferences, multi-tab synchronization, PWA/OTA updates, offline caching, security, risk control, and debugging.

The current product primarily utilizes necessary storage and preferred storage. If advertising, third-party tracking, or non-essential analysis are introduced in the future, we will provide additional prompts or consent mechanisms in accordance with applicable laws.

4. Sources of Information

We may obtain information from the following sources:

  • The information you provided voluntarily;
  • Information automatically generated when you use Web, PWA, CLI, API, agent, Hub, sandbox, or self-hosted components.
  • Information provided by your team members, space managers, or resource sharers.
  • Information returned by third-party certifications, payments, models, cloud services, object storage, email, SMS, and push services;
  • Information reported by the machine, sandbox, Hub, API forwarding service, or self-hosted service you are connecting to.

5. How We Use Information

We use this information for:

  • Create, log in, verify, and manage accounts;
  • Provide features such as agents, sessions, terminals, files, Git, previews, tunnels, documents, sharing, and notifications.
  • Synchronize the status of multiple devices, tabs, hubs, or team spaces.
  • Call AI models, API agents, third-party services, or model providers selected by users;
  • Provide sandbox, computing resources, resource monitoring, automatic shutdown, and resource recycling.
  • Processing bills, quotas, orders, payments, refunds, and usage statistics.
  • Send verification codes, notifications, security alerts, service messages, and customer service responses;
  • Debugging, troubleshooting, performance optimization, log analysis, and product improvement.
  • Preventing fraud, abuse, attacks, infringement, illegal activities, and security incidents.
  • Fulfill legal obligations, respond to legitimate requests, and protect the rights and safety of us, users, and third parties.
  • Process voice input, deliver notifications, verify store purchases, and connect to or perform actions in third-party applications at your request.

6. Legal Bases

Under applicable laws, the legal basis for processing personal information includes fulfilling contracts, legitimate interests, your consent, legal obligations, and protecting significant interests. For example, providing the agents and remote control features you request falls under contract fulfillment; security, anti-abuse measures, and troubleshooting are part of legitimate interests; and non-essential marketing or non-essential cookies may be based on your consent.

7. AI Models and Third-Party Processing

When you use AI features, your prompts, code snippets, file content, context, model configurations, and session data may be sent to third-party model/API service providers selected by or configured by the system for processing. The data retention, logging, training, and security policies of different service providers vary.

Please avoid entering unnecessary sensitive information, do not upload unauthorized third-party code or data, and do not input passwords, private keys, access tokens, production database credentials, or other confidential details. We will transmit data only to the minimum extent required by the service, but we have no control over the handling practices of third-party providers beyond what is promised.

Voice audio may be sent to the configured speech-recognition provider for transcription. Connected-app requests are sent to the provider you connect, and store purchase identifiers may be verified with Apple or Google. These transfers occur only when you use the relevant feature.

8. Information Sharing

We will not sell your personal information. We may share necessary information under the following circumstances:

  • Service providers: cloud services, object storage, email, SMS, payment, push notifications, logs, security monitoring, AI models, API gateways, etc.
  • Team and space members: If you join a team space or share resources, authorized members may view the sessions, files, documents, machines, tunnels, or permission information that you share.
  • You actively share: If you create public links, share links, file sharing, document sharing, preview links, or tunnels, individuals who hold the links or have access rights may be able to access the corresponding content.
  • Law and Safety: Disclosure required to comply with laws, court orders, regulatory requirements, law enforcement requests, or to prevent fraud, attacks, abuse, infringement, and security incidents.
  • Company transactions: In cases of mergers, acquisitions, financing, asset transfers, or restructuring, information may be transferred as part of the transaction. However, we require the recipient to continue protecting the data.

9. Data Retention

You can close your account in Settings > Security. You may also contact us to request deletion of applicable account data; information that must be retained for legal, billing, security, or dispute purposes will be kept only as necessary.

account informationWhile the account is active; after closure, sign-in credentials and push subscriptions are removed. Account records and some service data may remain where needed for billing, security, dispute handling, or legal obligations.
Conversation and MessagesSave before deletion; after deletion, it may remain temporarily in backups.
Files and attachmentsSave before user deletion; object storage copies are cleaned up based on lifecycle and backup policies.
terminal and logsReserve a reasonable period for debugging, security, auditing, billing, and anti-abuse purposes.
Billing and payment recordsRetained according to tax, financial, and compliance requirements.
Security LogsRetain a reasonable period for prevention of abuse, security audits, and compliance.
backupAutomatically overwrite or clean up based on the backup cycle.
Voice and mediaAnydo does not keep raw voice audio as long-term account content; speech providers may process it under their own policies. Transcripts and attachments are retained with the related session, document, or configured meeting-notes period.
Connected appsCredentials are retained while the connection remains active and removed from Anydo when you disconnect it. Limited action audit records may be retained for security and troubleshooting.
Store purchasesTransaction and subscription records are retained as needed to provide entitlements and meet accounting, fraud-prevention, and legal obligations.

10. Data Security Measures

We take reasonable technical and organizational measures to protect information, including:

  • HTTPS / TLS encrypted transmission;
  • Account authentication, Token verification, and refresh mechanism;
  • Permission control, spatial isolation, and the principle of least privilege.
  • Server-side key is isolated from client-side;
  • Database, object storage, and internal service access control;
  • Logging, monitoring, anomaly detection, and security response;
  • Security updates, vulnerability fixes, backup, and recovery mechanisms.
  • Restrict and audit internal access.

11. Your Security Responsibilities and Acknowledgment of Risk

No system can guarantee absolute security, especially with Anydo involving local command execution, remote terminals, AI tool calls, third-party models, public previews, tunnels, and self-hosting services. You are solely responsible for protecting your computer, server, browser, SSH, Git, cloud accounts, databases, code repositories, and third-party accounts.

Unless the incidents result from our intentional or gross negligence, they shall be borne by the user themselves. This includes intrusions, leaks, damages, extortion, data loss, or cost losses involving user devices, servers, self-hosting services, browser environments, third-party accounts, third-party models, public tunnels, weak passwords, key leaks, incorrect configurations, or unauthorized user actions.

  • Install the system and dependency security updates;
  • Do not submit tokens, API keys, SSH keys, or passwords to the code repository or to AI systems.
  • Examine the commands that the agent will execute;
  • Use yolo, bypassPermissions, automatic approval, public preview, and remote terminal with caution.
  • Properly configure the firewall, reverse proxy, DNS, TLS, sharing permissions, and team permissions.
  • Remove unused machines, Tokens, sharing links, and API Keys promptly.
  • Maintain independent backups for critical code, databases, and production environments.

12. Security Incidents

If we confirm that a security incident involving your personal information occurs, we will take reasonable measures in accordance with applicable laws, including investigation, mitigation, and repair, and notify affected users or regulatory authorities when required by law.

If a security incident occurs on your local machine, self-hosted hub, third-party cloud account, third-party model, public tunnel, weak password, key leakage, or misconfigured environment, you are responsible for investigating and addressing it; we can provide assistance within reasonable limits.

13. Your Rights

In accordance with applicable laws, you may have the right to access, correct, delete, export your personal information, limit or object to certain processing, withdraw consent, cancel your account, file a complaint or appeal. You can exercise these rights through product settings or by contacting us. We may need to verify your identity.

14. Supplemental Notice for California Users

If CCPA/CPRA applies, California users may have the right to know which categories of personal information we collect, use, and disclose, request access to, delete, or correct their personal information, choose not to sell or share their personal information, and not be discriminated against due to exercising their privacy rights. We currently do not sell personal information; if there is any “selling” or “sharing” under applicable law in the future, we will provide corresponding opt-out mechanisms.

15. Supplemental Notice for EEA/UK Users

If GDPR or UK GDPR applies, you may have the right to access, correct, delete, limit processing, carry over your data, object to processing, and file a complaint with regulatory authorities. We will strive to explain the purposes of data processing, categories of data, retention periods, and entities to which data is shared in a clear, understandable, and accessible manner.

16. Children's Privacy

This service is not intended for children under 13, and we do not intentionally collect personal information from such children. If higher age requirements are required in your area, you must comply with local regulations. If we discover the collection of child-specific personal information, we will take measures to delete or restrict it.

17. International Data Transfers

Your information may be processed or stored outside your country or region. We will implement reasonable protective measures in accordance with applicable laws.

18. Policy Updates and Contact

We may update this policy. Major changes will be announced via the website, internal notifications, or email reminders. Continuing to use the service after the update indicates that you acknowledge the updated policy.

If you have any questions regarding privacy, or wish to submit a request for access, correction, or deletion of your personal information, please contact us via the following methods.

Operator and Contact Information

Operating Entity
Genvas Technology Pty Limited
Chinese Name
即畫科技有限公司
Registered Address
Unit 29, 13/F, Fook Cheong Building, No. 63 Hoi Yuen Road, Kwun Tong, Hong Kong
Contact Email
info@anydo.io