← All legal documents

Desktop and Machine Service Privacy Notice

Edition 2026.09.4 · Effective 26 September 2026

What leaves your computer when you run the Simorg machine service and Simorg Desktop, what stays on it, and what the anonymous diagnostics are for. A supplement to the Privacy Policy.

1. In short

The Simorg machine service collects as little as it can. Your account details are what you gave us when you registered, and the Privacy Policy governs them. Facts about this computer are sent so that agents can be placed on it and so that your machine page can describe it. Product diagnostics are completely anonymous. Everything your agents read, write and produce stays on your disk. Nothing is sold, and nothing is shared for advertising.

2. The anonymous diagnostics

To make Simorg faster and easier to use, the service and Simorg Desktop send diagnostic records that are anonymous. They carry no name, no email address, no user name, no account or machine identifier, and nothing else that could be traced back to you or to this computer. Because they identify nobody, they are not personal data, which is why they are sent without the consent the browser’s analytics asks for. The records made while the service runs are linked to each other by a random number held only in memory, so that a fault can be followed from one step to the next; nothing links one run to another, and nothing links any of it to you.

  • What is measured: which operations are asked for and in what order, how long they take, whether they succeeded or failed, the shape of an error or a crash, and the version of the service, the operating system and the architecture it runs on.

  • What is never included: your name, your email address, your user name, the name of this computer, its machine identifier, its IP address, file names, folder paths, file contents, source code, agent output, container logs, tokens and any other credential. Where a message would have contained a path or an address, it is removed before the record leaves this computer, and the platform discards the address the record arrived from.

  • What it is for: finding the steps that confuse people, the ones that take too long and the errors that happen most often, so that the next version is better at all three. It is never used to decide anything about you or your account.

The random number that joins one run’s records is generated when the service starts, kept only in memory, and gone when it stops. It is never written to disk and never sent anywhere else, so two runs on the same computer cannot be connected to each other, and none of it can be connected to you. Because the records carry nothing that identifies you, they are only ever read in aggregate, and there is no individual record for us to find, hand over or delete on request. That is the trade this design makes deliberately.

3. Your account

Your email address, your name, your user name and the preferences you set are stored on the platform and used to run your account: to sign you in, to show you as the owner of what you make, and to tell you about changes that matter. The Privacy Policy at simorg.tech/legal/privacy says everything about them, including how long they are kept and the rights you have. We do not sell personal data and we do not share it for advertising.

4. What this computer tells the platform

Registering this computer as a machine means describing it. Two things are sent, and one thing deliberately is not.

  • A fingerprint, derived through one-way functions from your operating system’s machine identifier. The identifier itself never leaves the service, because every other program on the computer can read it too and sending it would let this account be lined up against all of them.

  • A description, which is what your machine page shows: the computer’s name and host name, its operating system and version, architecture, processor, cores, memory, disk size and free space, time zone and locale.

  • While the service is running it also reports which agents are placed here and whether their containers are up, so the platform only sends work to a machine able to take it.

5. What never leaves this computer

The folders you grant an agent, the work its container does, the artifacts it caches and the output it produces all stay on your disk. The activity journal the service writes records that something happened and which agent it was for, never the content of a message and never a credential, and so do its own log files. The service keeps its files in the usual places for your platform:

  • macOS: Library/Application Support/Simorg, Library/Caches/Simorg and Library/Logs/Simorg in your home folder.

  • Windows: the Simorg folders under %APPDATA% and %LOCALAPPDATA%.

  • Linux: .config/simorg, .cache/simorg and .local/state/simorg in your home folder, or wherever the XDG variables point.

The session file there holds your sign-in token, and the service’s discovery file holds a key that lets programs running under your account reach it. Both are written so that only your user account can read them, and signing out deletes the session file. Programs you run under your own account can ask the service for your sign-in token, so that they can call the platform on your behalf; no other account on the computer can. The cache and the working directories are shown in Simorg Desktop and by the simorg command, with what each holds and how big it is.

6. Other people’s services

Signing in and everything else the service does with the platform travel over HTTPS to our API and over a secure web socket to the Hub. The programs you use to control the service talk to it only on this computer. The agent runtime image is fetched from download.simorg.tech, which is ours, and container images and model files come from the sources you or your agents name; fetching one tells that source your address, as any download does. The container engine you installed is third-party software with a privacy notice of its own.

7. Keeping it, and deleting it

Account data is kept while your account exists and is erased as the Privacy Policy describes. A machine record goes when you remove the machine. On this computer, signing out deletes the session file, the cache, your agents’ working directories and the activity journal. The cache can also be emptied at any time from Simorg Desktop, with the simorg command or by hand. Deleting the cache costs time, never work.

8. Your rights

You have the right to see what personal data we hold about you, to have it corrected or erased, to receive a copy, to restrict or object to its use, and to withdraw a consent you gave. Settings → Your data on the platform lets you do most of that yourself; for the rest, write to info@simorg.tech and we will answer within a month. If our answer does not satisfy you, you can complain to the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) or to the data-protection authority where you live.

9. Children

Simorg is not intended for people under 16, and we do not knowingly collect personal data from them.

10. Changes to this notice

When this notice changes, the edition number and date shown with it change too, and you are asked to accept again. The current edition is published at simorg.tech/legal/desktop-privacy.