Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how we handle personal data across the asambl website, desktop application, phone companion, subscriptions, the optional asambl account, newsletter, and product updates. It also covers records from the beta waitlist and beta tester programme, which closed in August 2026.
Summary (Plain English)
- Your planning vault stays on your device. We do not have access to it.
- When AI is on, only the prompt for that specific request goes to our managed AI endpoint. AI can be switched off entirely.
- We collect the minimum information needed to manage your emails from us, your licence, and records from the closed beta programme.
- If you subscribe, Stripe takes the payment and your licence key is linked to the email address you paid with. We never see your card details.
- An asambl account is optional. The desktop app works fully without one; it is used to pair the iPhone app and to delete your account from inside the app.
- We do not sell your data or use it for targeted advertising.
- You can unsubscribe or ask us to delete your data at any time.
- asambl is intended for users aged 18 or older.
Who we are
Asambl Technologies Ltd, trading as asambl, is the data controller for personal data processed through the website and desktop application. The registered address is:
71–75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom
Company number: 17066085
ICO registration number: ZC102886
For privacy questions or data requests, contact: [email protected]
asambl and the EU AI Act
asambl is the provider of an AI system under EU Regulation 2024/1689 (the EU AI Act). asambl is a general-purpose productivity assistant that falls outside the high-risk categories in Annex III of the regulation. As an AI system that people interact with, it is subject to the transparency obligations of Article 50, described below.
Two transparency obligations under Article 50 apply to us. The first, Article 50(1), is to inform you when you are interacting with an AI system. We do this in two places: in this Privacy Policy, and in the asambl desktop application itself, where AI features are clearly labelled and the AI on/off control is always available.
The second, Article 50(2), is to mark AI-generated content in a machine-readable way. When the desktop application writes an AI-generated draft to a file in your vault, that file carries anai_generated: true flag in its frontmatter. Output the application produces from a fixed template, without AI, is not marked, because it is not AI-generated. Content you write yourself is never marked.
Microsoft is the provider of the underlying general-purpose AI model (Azure OpenAI Service). Documentation and training-data summaries for the underlying model are published by Microsoft and OpenAI under their own AI Act obligations.
What we collect
Beta-era records (programme closed August 2026)
If you joined the beta waitlist or beta tester programme while it ran, we collected:
- your email address
- your platform preference, such as macOS or Windows
- your main area of interest, such as health, money, relationships, joy, or growth
- whether you wanted to take part as a beta tester
Newsletter
When you subscribe to the newsletter, we collect your email address.
We may also use basic email engagement information, such as opens and link clicks, to understand what content is useful. We do not track your browsing behaviour across the web.
Feedback and support
If you submit the feedback form at asambl.app/feedback, send a note from inside the desktop app, or email support, we collect the message you write and, if you choose to provide them, your email address, which part of asambl your message concerns, and any app version or operating system details you include. A note sent from inside the app carries the line you typed, which screen it came from, the app version and your operating system, and nothing else: no activation key, no account details, no plan content. If you attach a screenshot, we store it with your message and keep it for as long as needed to investigate and respond, unless you ask for deletion earlier. We use this information only to investigate the issue and reply. To protect the form against abuse, we also store a truncated, hashed version of your IP address; the raw address is never stored.
Desktop application
asambl is designed around a clear three-tier separation of where data lives.
- Local data. Your planning data, notes, preferences, and outputs are stored on your device under your operating system’s user data directory, and are never transmitted to us. This data is stored unencrypted on disk and protected by your operating system login. We recommend enabling full-disk encryption (FileVault on macOS, BitLocker on Windows) so your data stays protected if your device is lost or stolen.
- Local embeddings and semantic search. Embeddings are generated on your device with an on-device model (Xenova/all-MiniLM-L6-v2) and stored locally in SQLite with sqlite-vec. The semantic index never leaves the device.
- Request-level prompts. When AI is on, only the prompt assembled for that specific request (which may include curated snippets retrieved from your vault) is sent to our managed AI endpoint via a Cloudflare Worker proxy. The full vault is not sent in one go.
The app identifies itself to our AI proxy with a trial or licence key stored on your device. Prompts are not stored against that key; request counts and the usage signals described below are. Keys, subscriptions, and the optional asambl account are described next.
Trial keys, licences, and payments
- Free trial. When you start the trial, the app asks our proxy for a trial key and sends a random identifier for your installation so the same machine is not issued a fresh trial repeatedly. To limit abuse, the number of trial starts per network address per day is capped; the address is held only for that daily count and is cleared within two days.
- Subscriptions. Payment is taken by Stripe on Stripe’s own checkout page. There Stripe collects your name, email address, billing country, and card details under its own privacy policy; card numbers go to Stripe only and asambl never receives or stores them. Stripe sends us the email address you paid with and your Stripe customer and subscription identifiers. We store these with your licence key on our infrastructure (Cloudflare) so the key can be issued to you, renewed, and switched off when a subscription ends, and we email the key to that address. Your licence is therefore linked to your email address. The desktop app shows a masked form of it under Settings › Account so you can recognise which licence is active; the full address is not returned to the app. Invoices and receipts come from Stripe and are available from the subscription portal.
Optional asambl account
You can sign in to an asambl account from Settings › Account on the desktop and from the iPhone app. Sign-in is optional: the desktop works fully without it, and a signed-out iPhone app keeps working in standalone mode. The account is provided by Microsoft Entra External ID and holds your email address and, if you sign in with Apple and choose to share it, your name. You can sign up with an email address and password or with Sign in with Apple; Apple lets you hide your email address, in which case we receive the relay address Apple issues. The account is used only to say who you are: it gates pairing the iPhone app with your laptop and it lets you delete your account from inside the app. It never holds the keys that encrypt data between your devices, and nothing on the account side can read that data. Sign-in tokens are stored in your operating system’s keychain. Account records are hosted by Microsoft in Europe.
Optional integrations
- Google Calendar. If you choose to connect Google Calendar, asambl exchanges OAuth tokens and calendar API requests with your Google account. It reads your events to plan around them and, only if you allow write access, creates the calendar blocks you approve. Calendar data is stored on your device only, is never used for advertising, and is never sold or shared. asambl’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. When you ask the phone companion a question, or when the desktop drafts a week, the titles and times of your calendar events for that window are included in the request to asambl’s managed AI and are not stored by it. This use follows the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect at any time.
- Calendar companion. If you use the companion at calendar.asambl.app (on your iPhone or in a mobile browser), you pair it with your laptop using a one-time code. In the iPhone app, signing in to your asambl account comes before pairing; in a mobile browser you enter the code directly and there is no sign-in. Either way the pairing code, not the account, is what lets your two devices read each other’s data. Your day and week arrive as an end-to-end encrypted document your laptop publishes, which the relay stores as unreadable ciphertext and only your paired phone can decrypt. Notes you capture are end-to-end encrypted on your device and can only be read by asambl on your laptop. They pass through a relay that stores only unreadable ciphertext, which auto-expires after seven days. To tell you whether your laptop has received a capture, the relay also briefly stores per-capture delivery status: the capture’s random identifier, whether it was delivered or dropped, and a timestamp. No note content is included, and this status auto-expires after seven days. The companion is off until you enable it on your laptop.
- Training log sync. If you log a training session on the companion, that session syncs two ways between your phone and your laptop. The sync is end-to-end encrypted with an authenticated box: only your phone and your laptop can read it, the relay stores only unreadable ciphertext that auto-expires, and the relay can never read the contents. To do this, the companion stores an encryption key in this browser (in IndexedDB) on your device. The key never leaves your browser.
- Push notifications. If you allow notifications in the iPhone app, the phone registers its Apple push token with Microsoft Azure Notification Hubs, tagged with the random identifier from pairing. When your laptop publishes an update, our relay sends a content-free wake-up (“Your plan updated.”), at most one every ten minutes. No plan, note, or calendar content is ever included: the relay cannot read it.
- Receipt and product scans. If you use the scan button in the desktop app (Finance and Relationships) or the receipt scan in the phone companion, that one photo is sent through our proxy to Microsoft’s Azure AI Document Intelligence (receipts) or Azure AI Vision (product photos) to read the text and numbers out of it. The photo is processed for that request only: neither we nor the relay store or log it, and only the extracted fields come back. On the phone, that result then travels to your laptop end-to-end encrypted like every other capture. The companion asks before the first scan; the desktop button can be hidden in Settings › Privacy.
- Ask on the phone. If you ask the companion a question about your plan, the phone assembles the context for that question from the plan it already holds and sends the question, that context, and up to three earlier turns of the same conversation to our managed AI endpoint (Azure OpenAI) through the relay. The answer is read-only: it cannot change anything. The relay does not log the question or the context and keeps nothing beyond delivering the answer, apart from a per-day count used for rate limiting.
- Web search. If you enable web search inside asambl, your search query is sent to Tavily Inc. to fetch results. Off unless configured.
- Crash reporting. If you turn on crash reporting in Settings › Data, scrubbed crash and error metadata is sent to Sentry. Off by default.
- Usage signals. The desktop app counts milestones (setup finished, a weekly plan committed or reviewed, a pattern card shown) and sends them to our infrastructure as counts and week numbers tied to your activation key. No note content, plan text, priorities, or calendar details are ever included. On by default; turn it off any time in Settings.
- Auto-updates. The desktop app checks GitHub for new releases roughly every four hours. These checks necessarily expose your IP address and the asambl version you are running. They can be disabled by blocking outbound network access for the app.
Cookies and analytics
The website does not use cookies.
We use Plausible Analytics, which is cookieless and privacy-friendly. It provides aggregated website analytics without creating individual user profiles, and we do not use Google Analytics.
How AI processing works
When AI features are enabled inside asambl, the prompt for that request is sent to our managed AI endpoint, which is built on Microsoft’s Azure OpenAI Service. We do not build user profiles from your prompts and we do not retain prompts or completions on our own infrastructure beyond what is needed to deliver the response.
Microsoft processes prompts under the standard Azure OpenAI Service terms. Microsoft does not use Azure OpenAI inputs to train OpenAI’s foundation models or Microsoft’s own models. Under Microsoft’s standard configuration, prompts and outputs may be retained by Microsoft for up to thirty days for abuse monitoring and accessed only by authorised Microsoft personnel where required to investigate suspected misuse. We are working with Microsoft to confirm and, where possible, reduce this retention, and we will update this policy as that configuration is finalised.
You can switch AI off at any time from the application’s settings. With AI off, no prompts are sent.
asambl outputs are advisory drafts. We do not use AI to make decisions that produce legal or similarly significant effects on you within the meaning of Article 22 of the UK and EU GDPR.
We design asambl’s AI features to be understandable: a clear AI on/off control, per-feature labels, and plain-language descriptions of what each feature sends to our managed AI.
Data Protection Impact Assessment
We are completing a Data Protection Impact Assessment for asambl’s AI-driven features, in line with Article 35 of the UK and EU GDPR and the European Data Protection Board’s Opinion 28/2024 on AI models. A summary will be made available to regulators on request.
Why we process your data
We process personal data to:
- manage newsletter and product-update emails
- send the newsletter
- send product updates, including major releases and changes that affect you
- tailor communications where you have provided optional preferences, such as platform information
- honour commitments made to beta members, such as keeping beta keys free
- investigate and respond to feedback and support requests
- issue, renew, and deactivate trial keys and licences, deliver licence keys by email, and take subscription payments through Stripe
- operate the optional asambl account and in-app account deletion
- send content-free push wake-ups to a paired iPhone
- operate and secure the asambl desktop application and proxy
Legal basis
Where UK GDPR or EU GDPR applies, we rely on the following legal bases:
- Performance of a contract. Operating the desktop application, processing AI requests when you have enabled AI features, taking payment and issuing licences when you subscribe, operating trials, and operating the asambl account when you choose to sign in.
- Consent. Newsletter sign-ups, feedback and support messages you choose to send us, opt-in crash reporting, and optional integrations such as Google Calendar.
- Legitimate interests. Operating and securing the service, abuse monitoring on our AI proxy, protecting against fraud, and understanding where the product loses people via usage-signal milestone counts (opt-out any time in Settings).
- Explicit consent (special-category data). The health, fitness, and relationship information you choose to enter is special-category data under Article 9 of the UK and EU GDPR. We process it only on the basis of your explicit consent, which you give through a dedicated checkbox before using the planning features. asambl cannot generate plans without it, and you can withdraw it at any time (see below).
You can withdraw consent at any time by using the unsubscribe link in an email, disabling the relevant integration in the app, or contacting us directly. Withdrawing explicit consent to special-category processing means asambl can no longer generate plans from that information; your existing data on your device is unaffected and remains yours to keep or delete.
How we use email
Newsletter
The newsletter may include:
- educational content about intentional planning and living
- updates on how asambl is evolving
- ideas related to building a more thoughtful life system
It is usually sent weekly or fortnightly.
Every newsletter email includes an unsubscribe link, and we do not add you to unrelated mailing lists.
Product updates
We may also send emails about:
- your trial or subscription
- new life areas or features
- major changes to the product or these policies
You may receive both newsletter emails and product updates, and you can unsubscribe from either at any time.
Data retention
We keep personal data only for as long as needed.
- Beta-era waitlist and preference data: the programme closed in August 2026; records are deleted within 90 days of closure except where needed to honour beta commitments (such as keeping beta keys free) or where you have since subscribed to product updates, and always sooner on request
- Newsletter data: until you unsubscribe, then deleted within 30 days
- Feedback and support messages: for as long as needed to investigate and respond, unless you ask for deletion earlier
- AI prompts and completions: not retained on our infrastructure beyond what is required to deliver the response. Retention by Microsoft on the Azure OpenAI Service is described above.
- Licence records (email address, Stripe customer and subscription identifiers, licence key): kept while the licence is active and for as long as needed after it is deactivated to resolve billing questions and disputes, then deleted; sooner on request where the law allows.
- Billing records (invoices, and the amounts and dates of payments): kept for six years from the end of the company financial year they relate to, which is what UK tax law requires of us. These are held by Stripe and in our accounting records; they cannot be deleted on request within that period.
- Trial start counts: the per-network-address daily count is cleared within two days.
- asambl account: until you delete it from Settings › Account in the iPhone app, or ask us to.
- Push registration: until you unpair or delete your account. A registration left behind receives nothing, because your laptop no longer publishes to it.
- Receipt and product photos: not stored anywhere by us; processed for that one request and discarded. Only the extracted text and fields are kept, on your own devices.
- Ask questions on the phone: the question and its context are not stored or logged on our infrastructure beyond delivering the answer; a per-day count for rate limiting is cleared within two days.
- Crash reports: retained by Sentry on our behalf for the standard ninety-day default unless we configure otherwise.
- Usage signals: milestone counts tied to your activation key, retained for up to 12 months, unless you ask for deletion earlier. Turning the setting off stops further collection immediately.
We may also clean up inactive entries from time to time, for example where there has been no engagement for 12 months, and we will give notice before doing so.
Sub-processors
We use service providers to help operate the website, the desktop application, the AI proxy, and email communications. At the time of writing, those include:
- Cloudflare: website hosting, DNS, CDN, the Worker proxy that fronts our AI requests, storage of newsletter and feedback submissions, licence records, trial keys, usage-signal counts, and the companion relay that briefly holds unreadable ciphertext and delivery status while a capture reaches your laptop.
- Stripe, Inc.: takes subscription payments on its own checkout page and sends us the email address you paid with and your customer and subscription identifiers. Card details stay with Stripe.
- Microsoft (Entra External ID): hosts the optional asambl account (email address, and name if you share it). Only if you sign in.
- Apple Inc.: Sign in with Apple, if you choose it when signing in to your asambl account; and the Apple Push Notification service, which delivers content-free wake-ups to the iPhone app if you allow notifications.
- Microsoft (Azure Notification Hubs): holds the iPhone app’s push token, tagged with the pairing identifier, and forwards content-free wake-ups. Only if you allow notifications.
- Resend: transactional and newsletter email delivery.
- Microsoft (Azure OpenAI Service): processes AI requests when you use AI features inside asambl, including Ask on the phone companion.
- Microsoft (Azure AI Document Intelligence and Azure AI Vision): reads the text and numbers out of a receipt or product photo when you use a scan. Processed for that request only; the photo is not retained. Only if you scan.
- Tavily Inc.: receives your web-search query when web search is enabled in asambl. Optional, off unless configured.
- Microsoft (Azure Maps): receives the place or location text you provide (such as your city, or a venue or event area) to return weather forecasts and nearby places when location-based planning features are used in asambl. Optional, off unless web search is enabled.
- Ticketmaster (Live Nation Entertainment, Inc.): receives your event-search text to return ticketed events when event suggestions are generated in asambl. Optional, off unless web search is enabled.
- Google LLC (Calendar API): receives OAuth tokens and calendar API requests when you connect Google Calendar. Optional, off unless connected by you.
- Sentry (Functional Software, Inc.): receives scrubbed crash and error metadata when crash reporting is enabled in Settings › Data. Off by default.
- GitHub, Inc.: auto-update checks necessarily expose your IP address and the asambl version you are running. Required for the application to receive security updates.
These providers process data only to provide their services to us. They are not authorised to sell your data or use it for their own marketing purposes. We will update this policy when our sub-processors change.
International transfers
Some of our providers may process data outside the UK or EU.
Where this happens, we rely on appropriate safeguards, such as standard contractual clauses or the UK International Data Transfer Agreement, where required.
Notice for EU residents
asambl is a UK-based service registered with the UK Information Commissioner’s Office (ICO registration ZC102886). We do not yet maintain a representative in the European Union under Article 27 of the EU GDPR; EU residents should consider this before signing up. We will update this policy when we appoint one.
Your rights
If UK GDPR or EU GDPR applies to you, you may have the right to:
- access your personal data
- correct inaccurate data
- ask us to delete your data
- withdraw consent at any time
- object to certain kinds of processing
- request a copy of your data in a structured format
- complain to the Information Commissioner's Office (ICO)
To exercise these rights, email: [email protected]
If you have an asambl account, you can also delete it yourself from Settings › Account in the iPhone app. That removes the account, unpairs every device, and clears relayed data; the plans and notes on your own devices are untouched.
We aim to respond within one calendar month. If a request is complex and we need more time, we will let you know within that first month.
Security
We take reasonable steps to protect personal data, including access controls, least-privilege access, secure hosting, and encrypted connections.
No system can be guaranteed 100% secure, but we work to reduce risk and protect the information we handle.
Children
asambl is intended for users aged 18 or older. We do not knowingly collect personal data from anyone under 18. If you believe a child has signed up, contact us at [email protected] and we will delete the relevant data.
Changes to this policy
We may update this Privacy Policy as the product and services evolve, including as further provisions of the EU AI Act take effect.
When we do, we will update the “Last updated” date above. If a change is significant, we will notify existing subscribers by email before it takes effect.
Changelog. 9 September 2026: added the Article 50(2) machine-readable marking of AI-generated vault files to the EU AI Act section. 3 September 2026: stated what Stripe collects at checkout and the six-year billing-record retention; added receipt and product scans (Azure AI Document Intelligence and Azure AI Vision, no retention) and Ask on the phone companion (Azure OpenAI) to what we collect, sub-processors, and retention; replaced the statement that asambl has no account system with the optional asambl account (Microsoft Entra External ID, email or Sign in with Apple); disclosed that a subscription licence is linked to the email address paid with, and how trial keys are issued; added Stripe, Microsoft Entra External ID, Apple, and Microsoft Azure Notification Hubs as recipients; added push notifications, licence records, trial start counts, the account, and push registration to what we collect and retention; described in-app account deletion. 31 August 2026: recorded the close of the beta waitlist and beta tester programme (August 2026) and general availability with a 21-day free trial; set the retention window for beta-era records; renamed beta usage signals to usage signals with a 12-month retention cap; updated the product-update email list and the EU representative notice. 11 August 2026: expanded the Google Calendar disclosure with how calendar data is used and the commitment to the Google API Services User Data Policy, including its Limited Use requirements. 2026-07-18: added the optional screenshot attachment and its retention to the feedback and support disclosure. 2026-07-13: added beta usage signals (milestone counts tied to the beta key, opt-out in Settings) to network calls, legal basis, retention, and the Cloudflare sub-processor entry. 2026-07-05: added the website feedback form (message, optional email and details, and a truncated IP hash used for rate limiting) to what we collect, purposes, legal basis, retention, and the Cloudflare sub-processor entry. 2026-06-27: added Microsoft Azure Maps (weather and place search) and Ticketmaster (event search) to the sub-processor list. 2026-05-05: restructured the AI section into local vault, local embeddings, and request-level prompts; added EU AI Act provider declaration; extended the sub-processor list to include Tavily, Google Calendar, Sentry, and GitHub; raised the minimum age to 18; added DPIA, Article 22, and EU residents notices.
Contact
For privacy and data requests: [email protected]
For general enquiries: [email protected]