Privacy Policy
EFFECTIVE 2026-08-13
Offload ("Offload", "we", "us") is a desktop and mobile application and
cloud service that lets creators connect their platforms and tools and
delegate work to an AI agent. This policy explains what information we
collect, how we use it, and the choices you have. Contact:
saadosman450@gmail.com.
1. Information we collect
-
Account information. Your email address, used to sign
in (we send a one-time code) and to contact you about the service.
-
Your content. Chats, projects, drafts, and files you
share with the agent. Thread event history and projects sync to our
cloud backend so your work can be viewed and restored; media you
attach may be stored in our cloud storage. Connected-account call
arguments, results, and assistant replies derived from those results
remain in the device-local turn, are not copied into cloud thread
history, and are not replayed into later model requests.
-
Connected account data. When you connect a
third-party service (for example YouTube, TikTok, Instagram, X, Gmail,
Notion, Slack, or GitHub), we access the data you authorize — such as
your profile, posts, videos, messages, or analytics — solely to
provide the features you use. OAuth sign-in for most tools is handled
by our authentication partner (Composio), which stores and refreshes
access tokens on our behalf. TikTok uses Offload's native Login Kit
integration instead: Offload receives its access and refresh tokens on
the server, encrypts them at rest, and never sends them to the desktop
or mobile client. We do not receive or store your third-party
passwords.
-
Diagnostics and usage. When diagnostics are enabled
for a build or runtime, crash, performance, operational error, and
aggregate usage reports may be sent to Sentry and PostHog. Daemon
reports are scrubbed, omit raw crash stacks, and use no persistent
device identifier; their PostHog error events use a random identifier
that lasts only for the running daemon process. If renderer Sentry is
enabled, an application error can include stack frames, breadcrumbs,
performance traces, and a masked, media-blocked replay tail. When
mobile analytics is enabled, PostHog receives anonymous application
install, update, open, foreground, and background events; mobile
screen, touch, log, exception, survey, geolocation, and session-replay
capture are disabled. Mobile Sentry can receive native and JavaScript
crash reports and sampled performance traces, but mobile replay is
disabled. Offload does not intentionally attach chat or
connected-account content to telemetry.
-
Billing and model usage. Stripe processes
subscription payments and retains the billing details needed to do so.
Offload records provider-reported model usage, token counts, and cost
so it can show your running usage and report the billable amount to
Stripe. Offload does not receive your full payment-card number.
-
On-device storage. Offload's clients store session
material, settings, and cached application state locally. The desktop
client also stores chats, its media index, and generated descriptions
locally so the agent can work next to your files. The desktop
application data directory and workspace can remain after the app is
uninstalled; removing the application alone does not promise to erase
those files.
2. How we use information
-
To provide the service: run agent tasks you request, draft and publish
content you approve, sync your threads across devices, and show you
your connected accounts' data inside the app.
-
To process your requests with AI models: content you send to the agent
(and the connected-account data a task needs) is processed by large
language model providers acting as our processors. Their handling is
governed by our provider configuration and agreements.
- To operate, debug, and improve Offload.
- To communicate with you about the service.
We do not sell your personal information, and we do not
use your content or your connected-account data for advertising.
3. When we share information
-
Service providers that host and power Offload: cloud
database and sync (Convex), file storage (Cloudflare), billing
(Stripe), AI model routing (OpenRouter and the model providers behind
it), OAuth token management for supported non-TikTok integrations
(Composio), email delivery (Resend), inbound mailboxes (AgentMail),
crash reporting (Sentry), and analytics (PostHog). Each receives only
what it needs to perform its function.
-
The platforms you connect, when you ask the agent to
act — e.g. publishing a post to your own account.
-
Legal reasons, if required by law or to protect the
service and its users.
4. YouTube API Services
Offload uses YouTube API Services to let you connect
your YouTube channel. By using this feature you also agree to the
YouTube Terms of Service,
and Google's handling of your data is described in the
Google Privacy Policy.
-
When you connect YouTube, Offload accesses the data you authorize —
your channel profile, your videos and their metadata, comments, and
your channel analytics — to display it to you and to run the tasks you
ask the agent to perform (for example, analyzing how your videos
perform or drafting replies for your approval).
-
We store imported YouTube data only as needed to provide these
features and do not share it with third parties except the service
providers listed above acting on our behalf. A current analytics
snapshot may remain stored until it is replaced or you use the
deletion controls described below.
-
You can disconnect YouTube inside the app at any time. Disconnecting
immediately disables Offload's local use of the connection and asks
our OAuth manager to start provider-token revocation. Local
disablement is recorded before that external request, so an
interrupted or failed request stays disabled and can be retried. When
accepted, the manager currently returns an asynchronous job receipt
without an API that verifies completion, so Offload labels the
revocation pending and unverified instead of claiming
it has completed. Disconnect remains separate from deleting data
already imported into Offload. After disconnecting, use
Delete imported data in the desktop Stack screen to
erase the retained imported copy. You can also revoke Offload's access
directly in your
Google security settings.
5. TikTok and other connected platforms
When you connect TikTok (or another platform), Offload accesses only the
data you authorize on the platform's consent screen — such as your
profile, your videos, and their performance metrics — to display it to
you and run the tasks you request. TikTok access and refresh tokens are
stored only in an encrypted server-side credential record while the
connection is active. A TikTok disconnect immediately blocks local use,
requests revocation directly from TikTok, and deletes the credential
after TikTok acknowledges the request. If that request is temporarily
unavailable, the connection remains disabled and the encrypted
credential is retained only for a safe revocation retry. For other
connections managed by our OAuth partner, a returned asynchronous
revocation receipt is shown as pending and unverified unless
authoritative completion is available. Disconnecting does not by itself
erase data already imported into Offload. For supported connected tools,
the desktop Stack screen offers a separate
Delete imported data action after disconnect; you can
also revoke access from the platform's own security settings.
6. Data retention and deletion
-
Your chats, projects, and media are kept while your account is active
so they can sync across your devices. On desktop, the thread action
labeled Archive only hides a thread; it does not
delete local or cloud history. The mobile thread screen can request
deletion of that thread's cloud copy, while local Mac history and
user-created backups must be deleted at their source. Removing an
entire device from Offload starts a bounded cloud-mirror deletion
sweep. A content-free, generation-bound deletion ledger survives
device removal to stop provider backup restoration from resurrecting
an erased cloud thread; it contains identifiers, high-waters,
counters, status, and timestamps, not conversation payloads.
-
Moving media to trash is also an archive.
Empty trash starts durable permanent deletion of the
selected media from Offload's local index, local content-addressed
storage, cloud metadata, cloud object storage, and local generated
descriptions. Local metadata is removed after the cloud accepts the
deletion; background retries may continue until object-storage
deletion is verified. Copies you exported elsewhere remain yours to
delete.
-
Delete imported data, available on the desktop Stack
screen after disconnecting a supported provider, permanently removes
provider metadata, analytics snapshots, schedules, and
provider-operation ledgers retained by Offload. It does not remove
content already published on the provider, the provider's own records,
ordinary chat content, or user-created local/exported copies.
Background deletion may continue after the request is accepted.
-
Delete account is available in mobile Settings. After
you confirm, Offload cancels active Offload subscriptions linked to
the account, requests revocation of connected-account credentials,
signs out every Offload session, removes the account's identifying
email and login authority, and starts permanent deletion of its cloud
projects, conversations, files, connected-account data, settings, and
other user-authored cloud data. Deletion runs in bounded background
jobs so stored objects and retries can be verified. An anonymized
deletion marker, public issue attribution, and records that must be
retained for legal, security, or billing purposes may remain without
the account email. Local files, desktop-only archives, user-created
backups, exported copies, and content already published to another
platform remain at their source and must be deleted there.
7. Security
Data in transit is encrypted with TLS. Sign-in uses one-time email codes
and a signed access session that can last up to 30 days. An active
client may rotate that session into a new 30-day session; rotation
revokes the previous session. Signing out clears the session from the
current client and attempts to revoke it server-side. If that request
cannot reach the service, such as while offline, the server session can
remain valid until it expires even though this client no longer retains
it. Offload never sees a password for you or any connected account.
Access tokens for most connected platforms are held by our OAuth
partner. Native TikTok access and refresh tokens are held by Offload in
AES-256-GCM-encrypted server-side records, refreshed there, and retained
only while needed to operate the connection or complete a requested
revocation. Connected-platform tokens are never exposed to other users
or shipped to the desktop or mobile client.
8. Your rights
Depending on where you live, you may have rights to access, correct,
export, or delete your personal information. Email
saadosman450@gmail.com and
we will honor these requests. Offload is not directed to children under
13, and we do not knowingly collect their information.
9. Changes
We will post any changes to this policy on this page and update the
effective date above. Material changes will be announced in the app or
by email.