Legal
Privacy Policy
Last updated 24 July 2026
This policy describes what the Sandhi desktop and mobile applications do with your information. It is written to be read, not to be skimmed past.
The short version
We do not run a service that holds your data. Sandhi has no account, sends no telemetry, and keeps your tasks, screens and files on your own devices. The only things that ever leave your machines are the ones you switch on yourself — a cloud AI model, if you choose one, and a relay you host.
1. Who we are
Sandhi is produced by Aitele Research ("we", "us"). You can reach us about anything in this policy at hello@aiteleresearch.com.
2. What we collect
From using the apps: nothing. The Sandhi desktop and mobile applications contain no analytics, tracking or crash-reporting services, and there is no account to create. We operate no server that receives your tasks, your prompts, your screenshots or a list of your devices, and none of that reaches us at any point.
If you buy a licence. Payment is processed by Paddle.com Market Ltd, who act as the merchant of record and are a separate data controller. They collect the information a sale requires — your email address, billing country and postcode, tax identifiers where applicable, and your payment details — and their own privacy notice governs it. We never receive or store your card or bank details.
What Paddle passes to us, and what we then hold, is:
- your email address, because a licence key has to be delivered somewhere;
- the plan you bought, the issue and expiry dates, and an internal licence id;
- your company name, if you provided one for an invoice.
We keep this as a record of issued licences so that we can reissue a key you have lost, honour a refund, and meet our own tax and accounting obligations. Your licence key itself contains the name or email it was issued to, which is why the app displays "Licensed to …" beside your plan.
If you write to us. The contact form sends us the name, email address and message you type, so that we can reply. Nothing else is taken from the page.
When you download. Our download links are counted. To count people rather than clicks without identifying anyone, each request is reduced to a keyed hash of the IP address and browser user-agent, using a random key that is replaced and discarded every day — after which the stored value cannot be linked back to any address by anyone, including us. Only the resulting counts are kept. No IP address is written to disk and no per-visitor record exists.
What we do not do. We do not build a profile, we do not sell or share personal data, and we do not combine what a purchase tells us with anything about how you use the product — because nothing about how you use it ever reaches us.
3. What stays on your devices
Everything the product needs to work is stored locally on the device it belongs to:
- The instructions you type or speak, and the results of those tasks.
- Screenshots the agent captures in order to see what it is doing.
- Your scheduled tasks, device names and preferences.
- Your device's encryption keys, and any API key you enter — held in your operating system's credential store (Windows Credential Manager, the Android Keystore) and never transmitted to us.
Uninstalling the applications removes this data with them.
4. What leaves your devices, and only if you choose it
Three things can send data off your machines. Each is your decision.
A cloud AI model. Sandhi can run a model locally, in which case nothing leaves. If you instead point it at a cloud provider using your own API key, then for each step of a task the screenshot and on-screen text it needs are sent directly to that provider, under your account with them and subject to their privacy policy — not ours. We are not a party to that exchange and never see it. If this matters to you, use a local model.
A relay, when your devices are apart. If your devices are not on the same network, they meet through a relay that you host and control. The relay forwards encrypted bytes and cannot read them: it holds none of your keys. Like any relay, it does unavoidably observe the two IP addresses connecting, the timing, and how many bytes pass. It observes nothing about the content.
An update check. The application can ask whether a newer version exists. That request carries no identifier of any kind — no account, no device ID, no cookie, and deliberately not your current version number. Every client sends an identical request and receives identical bytes, so the check cannot be used to distinguish or profile anyone. Serving any file over a network means the server momentarily sees the requesting IP address and the time; it learns nothing else.
5. Permissions the mobile app asks for
The Android application requests the permissions it needs to act as your agent, and uses them for nothing else:
- Accessibility service — to read the screen and tap on your behalf. This is how the agent operates apps. It does not send screen contents anywhere except as described in section 4.
- Screen capture — to see what is on screen while a task runs.
- Display over other apps — for the floating prompt bar and bubble.
- Camera — used once, to scan the pairing code.
- Microphone — only while you hold the button to speak.
Sandhi steps aside automatically in banking and payment applications.
6. Children
Sandhi is not directed at children under 13, and we do not knowingly collect information from them. Using the applications creates no record with us at all; the only personal data we hold comes from buying a licence or writing to us, both of which are adult transactions. If you believe a child has given us their details, write to us and we will delete them.
7. Your rights
Data-protection law gives you rights to access, correct, export and erase the personal data held about you.
For anything created by using Sandhi — your tasks, prompts, screenshots and device list — these rights are exercised on your own devices, because that is the only place the data exists. It is in your hands, and removing the applications removes it. The desktop's task history has a Clear history button for the same reason.
For the records a purchase creates — your email address, the plan and the dates — write to hello@aiteleresearch.com and we will tell you exactly what we hold, correct it, or delete it. Note that we may be required to retain invoice records for a period under tax law even after a deletion request, in which case we will say so and delete everything not covered by that obligation. For the payment details Paddle holds as merchant of record, address Paddle directly — they are a separate controller.
If you contacted us through the website, ask and we will delete the message and your address from our inbox.
8. Changes to this policy
If this policy changes we will update the date at the top and publish the revised version here. Material changes to what leaves your devices will be stated plainly rather than buried.