Privacy & data

Is asambl private? How asambl handles your data and AI

The trust centre: where your data lives, exactly what crosses the network and when, who processes what, how long anything is kept, and how you leave. Every claim here restates the privacy policy in plain English.

Aleem O'BalogunBy Aleem O'BalogunUpdated 11 min read

The short answer

Your data stays with you: the primary copy lives on your computer as portable files. asambl is not local-only, because planning relies on cloud AI, so the honest label is a private cloud-AI planner. When AI is on, only that one request's prompt goes to asambl's managed AI on Azure and is not retained by asambl. Semantic search runs locally, and AI can be switched off.

Your data stays with you

asambl is a desktop app for macOS and Windows, and everything you put into it, your notes, priorities, plans, journal, reviews and outputs, is stored on your own machine as portable files you can read, back up, and move. The format is plain markdown, JSON, and CSV, so nothing is locked inside a database you cannot open. We do not have a copy of your data and we cannot read it.

That is the posture in one sentence, and the rest of this page is the detail: what crosses the network and when, who processes what, how long anything is kept, and how you leave. It is written to be checked, not to reassure: every claim restates the privacy policy, which remains the formal version, and the change log at the bottom records when anything here moves.

The map: what lives where

One table, the whole picture. The right-hand column is the one to read twice.

DataWhere it livesWhat ever leaves your device
Plans, notes, journal, reviewsYour computer, as plain filesNothing, except the small slice included in a prompt you trigger
Semantic search indexYour computer, built on-deviceNothing. Embeddings are generated and queried locally
An AI requestSent per request, never stored by asamblOne prompt: your question plus the slice of notes needed to answer it
Phone captures (Companion)Your phone, then your desktopEnd-to-end encrypted payloads only; the relay cannot read them and they auto-expire
CalendarYour Google Calendar, opt-inTwo-way sync with the one calendar you chose; revocable any time
Crash reportsOff by default; opt-in in SettingsScrubbed crash metadata only, if you turn it on
This website's analyticsPlausible, cookielessAggregate page counts; no cookies, no profiles, nothing tied to you
Where each kind of data lives, and what ever leaves

What happens when AI is on

asambl uses AI to draft your week from your priorities, your calendar, and your energy. To do that, it has to send something. Here is exactly what, and where it goes: when you use an AI feature, only the information needed for that specific request leaves your machine. That means your question plus the small slice of notes it takes to answer, not your files as a whole. It travels through asambl's proxy to the managed AI endpoint, hosted by Microsoft on the Azure OpenAI Service, and the response comes back the same way. There are no API keys to manage and no provider to choose.

Retention on that path, stated precisely: asambl does not retain prompts or completions beyond delivering the response, and we do not build profiles from them. Under Microsoft's standard configuration, prompts and outputs may be held by Microsoft for up to thirty days for abuse monitoring, accessible only to authorised personnel, and are not used to train OpenAI's or Microsoft's models.

What crosses, and what never does

Stays on your computer

  • Your plans, notes, journal and reviews, as plain files
  • The semantic search index, built and queried on your device
  • Everything else you have not put in a prompt
  • An AI request

    Your computerone prompt, for that request onlyManaged AI (Azure OpenAI, via our proxy)

    Not retained by asambl. Microsoft may hold prompts up to 30 days for abuse monitoring, then they are gone. Never used to train models.

  • A phone capture

    Your phoneend-to-end encrypted, unreadable in transitYour desktop, the only place that can read it

    The relay holds only unreadable payloads and delivery status, which auto-expire within days.

  • Calendar sync

    The one Google Calendar you choosetwo-way, opt-in, revocableYour week in asambl

    You grant it, you can disconnect it, and .ics export works without it.

The off switch, and what it leaves you

AI is on by default, and the switch to turn it off entirely is always available in the app. With AI off, the planner stops drafting, and the rest of asambl keeps working: your files, your calendar, your reviews, your captures. You plan the week by hand. What you lose is the automatic drafting, not the app, and nothing about the off state is degraded to nudge you back.

Semantic search deserves its own line, because it feels like the cloud and is not: search and matching run on your own device, with embeddings generated locally and the index stored locally. The part of asambl that finds the right note when you ask a vague question never touches a network.

The Companion path

The Companion opens in your phone's browser, on iPhone and Android, for capture on the go: notes, todos, reminders, voice, photos, a day and week glance, workout and meals logging. Captures are end-to-end encrypted on your phone and relayed to your linked desktop, and only your desktop can decrypt them. The relay in between holds payloads it cannot read, plus delivery status, and both auto-expire within days. Calendar reads on the phone are read-only and are not sent to us.

Who processes what

Naming the services plainly, because "we use trusted providers" is not information. At the time of writing: Cloudflare hosts this website and runs the proxy in front of AI requests, and briefly holds the Companion's unreadable payloads in transit. Microsoft processes AI requests on the Azure OpenAI Service. Resend delivers email you asked for. Plausible provides cookieless website analytics. Sentry receives scrubbed crash metadata, only if you opt in.

Three integrations are off unless you enable them, and each sends only the query it needs: Tavily receives your web-search text when you turn web search on; Microsoft Azure Maps receives a place name when location features are used; Ticketmaster receives your event-search text when event suggestions are generated. None of them sees your files. The privacy policy carries the formal list and is updated when sub-processors change.

Retention and deletion, in numbers

The short version of the policy's retention table: AI prompts and completions are not retained by asambl beyond delivering the response, with Microsoft's abuse-monitoring window at up to thirty days as above. Opt-in crash reports sit with Sentry on the standard ninety-day default. Website-side data follows its purpose: newsletter data goes within thirty days of unsubscribing, waitlist and beta records last as long as the programme unless you ask sooner. And you can ask: deletion requests are honoured, and the contact route is on the policy page.

The most important retention fact is structural rather than a number: your actual data, the plans and notes and journal, has no server copy to retain or delete. It is on your disk, under your account, and was never anywhere else.

Is asambl local-first? The honest answer

It helps to split two terms people use interchangeably. Local-first means the primary copy of your data lives on your device; by that definition asambl qualifies, because your files are the primary copy and they stay on your machine. Local-only, fully offline, no-cloud means the app never needs a network at all, and asambl is not that, because drafting a plan relies on cloud AI. It would be easy to blur the two, and some tools do; we would rather be accurate than flattering.

So the honest posture: local-first for your data, not local-only for the app. Your files stay on your computer, AI is request-scoped so one prompt travels rather than your whole life living on a company's servers, search runs locally, and AI has a real off switch. If you need a tool that never touches a network at all, the honest roundup names the genuinely local options and ranks them above asambl on that axis.

Leaving, and what you take

Because your data is stored on your machine as plain markdown, JSON, and CSV, leaving requires nothing from us: there is no server copy to request, and your files open in any text editor the day you stop using asambl. Calendar sync disconnects in one step and events export as standard .ics. An exit that needs no permission is the strongest privacy claim on this page, which is why it is the one we end on.

Change log

  • 2026-07-26: expanded into the trust centre: the data map, the flow diagram, named sub-processors, retention in numbers, and this change log
  • 2026-07-21: the local-first section tightened so the data claim and the app claim cannot be read as one
  • 2026-06-21: first published

Sources

checked 26 July 2026

This page is the plain-English reading of the formal privacy policy, which remains canonical; where the two could ever differ, the policy wins and this page gets fixed. Facts re-checked against the policy on the date shown.

  • The asambl privacy policy (asambl.app/privacy): data categories, retention table, sub-processor list, and your rights.
  • Microsoft, Azure OpenAI Service data handling: the abuse-monitoring window and the no-training commitment for service inputs and outputs.

Plan the week before it starts

A short prompt every Sunday to help you decide what next week is actually for, plus the occasional essay. No product pitch, unsubscribe any time.