Privacy policy
Your work stays yours.
Axiom connects your own devices and services. We minimize the information our services can see, encrypt synchronized private content end to end, and keep machine control subject to the safety settings on your daemon.
Effective August 11, 2026
Information Axiom handles
- Account details such as your email address, user identifier, authentication method, and account status.
- Device and connection metadata such as a machine label, device public keys, app version, connection state, and capability declarations.
- Content you choose to create or synchronize, including chats, Notes, attachments, settings, commands, and keyboard learning data.
- Requests and selected context sent to an AI provider when you ask Axiom to use that provider.
Client-side encrypted sync with protected recovery
Private synchronized records are encrypted on your device before upload. The account service stores encrypted records and the metadata needed to route and synchronize them. Your password or sign-in method is not the encryption key. If you explicitly recover encrypted data after losing every approved device, Axiom's authorized recovery service can use protected KMS/HSM infrastructure to rewrap the account key for the newly authenticated device. This server-assisted recovery is not service-blind end-to-end encryption.
When you intentionally invoke a cloud model, the prompt and any context selected for that request are processed by the configured model provider under that provider’s terms. A cloud fallback cannot control an offline machine.
Machine access and approvals
The Axiom daemon runs on a computer or server you control. Actions requested from iPhone, iPad, Mac, web, or another approved entry point are executed under the daemon’s configured permissions, hooks, access tier, and confirmation rules. Axiom does not bypass operating-system permissions.
When an action requires confirmation, approval state is synchronized to the requesting client. Eligible iOS approvals use the device’s Local Authentication system.
Axiom Keyboard
The keyboard provides offline typing without Full Access. Full Access enables account-backed features such as encrypted learning sync and assistant entry points. Axiom does not require Full Access for basic typing, and secure fields or host-app restrictions may replace Axiom with the system keyboard.
Keyboard learning data follows the same approved-device encryption boundary as other synchronized private records.
Diagnostics
Diagnostics are opt-in. They may include structural connection timing, failure categories, app and operating-system versions, keyboard latency, layout measurements, and acceptance results. Diagnostic events are designed not to include chat text, Note text, tool arguments, tool results, filenames, credentials, tokens, encryption keys, or keyboard content.
Retention and deletion
Account data is retained while your account is active and as needed to provide synchronization, security, fraud prevention, and recovery. Deleted records use bounded tombstones so an old offline device cannot silently restore them. Operational and security records may be retained for a limited period where reasonably necessary or legally required.
You can export or delete your account from Axiom’s account settings. Ordinary sign-out does not erase local data; removing local data is a separate, explicit action.
Sharing and sale
We do not sell personal information. We disclose information only to service providers needed to operate Axiom, to providers you direct Axiom to use, to protect users and the service, during a corporate transaction subject to appropriate safeguards, or when legally required.
Your choices
You can control paired devices, revoke a device, choose model providers, change daemon safety settings, disable diagnostics, disable keyboard Full Access, export your data, and delete your account. Device and operating-system settings provide additional controls for notifications, microphone, speech recognition, camera, network, and Local Authentication access.
Questions or requests
For privacy questions, access or deletion requests, or concerns about this policy, contact us. We may need to verify that a request belongs to the account holder before acting on it.
privacy@aiaxiom.app