Twoody
Privacy

Privacy policy

This policy covers the Twoody for Mac app and this website. In short: the app keeps your data on your Mac and sends no telemetry; what leaves it is listed below, item by item. The online Twoody account, optional, in private beta and closed to new sign-ups, has its own policy.

Last updated: 25 September 2026

01Data controller

The data controller is Osmove SASU, 146 ave Léon Blum, 92160 Antony, France (RCS Nanterre 902 644 970). Contact: support@twoody.com.

The Twoody for Mac app

The app works without an account. We receive neither your conversations, nor your documents, nor your memories: here is what it keeps, and everything it sends over the internet.

02Your data stays on your Mac

Your conversations, your memories and the index of your documents are stored in a local database, in ~/Library/Application Support/twoody-desktop, readable only by your macOS user account. Twoody does not encrypt that database itself: FileVault does, if it is turned on on your Mac. Scanned PDFs are read (character recognition) on your Mac too, by macOS. A Brave Search API key, if you enter one, is kept encrypted in the macOS Keychain. To erase everything: uninstall the app, then delete that folder.

03No telemetry, no analytics

The app sends no telemetry, no usage analytics and no crash reports.

04The update check

At most once a day, the app asks downloads.twoody.com (served by Cloudflare) for a small file to know whether a new version exists. That server sees the request and the IP address it comes from, nothing that tells your Mac from another. Nothing is downloaded without your click, and the check can be turned off in Settings.

05The models you install

When you install a model from Twoody, its files are downloaded from Hugging Face (huggingface.co), which sees that download like any visitor's: IP address and requested file. If you use a model from LM Studio, Ollama or mlx-lm, what those applications contact depends on their own settings.

06Web search, if you turn it on

It is off by default. When you turn it on, in the chat or in Code, your search is sent to the engine you chose — DuckDuckGo by default, Brave Search with your API key, or your SearXNG server — then the app fetches the first pages found. That engine and those sites see your Mac's requests, as with a search in a browser; your documents are not sent to them.

07Code (beta)

Code reads and changes the files of the folder you open with a model running on your Mac. It does not send them over the internet; only web search, if you turn it on, sends your searches out.

08The private beta, only if you sign in to an account

The private-beta option in Settings, off on a new installation, lets you sign in to an online Twoody account. Only in that case: the app talks to that account (part B); if you turn it on, it lends the Mac's models to that account, and requests made from the account then go through our servers; and the iPhone app can reach your Mac away from home through a relay that is end-to-end encrypted between the phone and the Mac. The relay sees account tokens, IP addresses, message sizes and timing, not their content, and keeps the encrypted messages only for as long as it takes to pass them on (two minutes at most).

This website

twoody.com and its pages.

09Cookies

The pages of this site set no cookie. Only the online account uses cookies, when you sign in to it: _twoody_session (sign-in and form security, deleted when the browser closes), and remember_user_token if you tick "Remember me". No audience-measurement or advertising cookie.

10Audience measurement

No audience-measurement script, no advertising tracking. When a visit comes from a campaign (utm_… parameters, an ad click identifier) or from another site, our servers record it, on the basis of our legitimate interest in knowing where visits come from: source, campaign, landing page, referring site, browser, country and IP address. These records are not linked to any account. They are kept for 13 months, then deleted; you can ask for them to be deleted sooner, or object to them.

11Services loaded by the pages

The pages load nothing from another service: their icons and their one script come from this site. The site is served by Heroku, behind Cloudflare, which see your IP address as any host does.

12If you left your email

If you left your address on this site to be told about the launch, we have kept it, with its date, the language, the country, the IP address, the browser and the campaign you arrived from, to write to you about it. Write to us to have it deleted.

For everyone

13If you write to us

Emails sent to our addresses (support@twoody.com, hello@twoody.com…) arrive in our mailbox, hosted by Google (Google Workspace), where we keep them to follow up on your request.

14Security

The measures in place are described on our security page.

15Your rights

Under the GDPR, you can access your data, rectify it, erase it, restrict its processing, object to it and ask for its portability. Write to us to exercise these rights: support@twoody.com. You can also lodge a complaint with the CNIL (cnil.fr) or with the data protection authority of your country.

16Children

The online account is not intended for children under 13.

17Changes

We may change this policy. The version in force is the one published on this page, with its date; a significant change will also be announced on this website.