This privacy policy is a draft for legal review. It does not yet govern your use of Olympus.
Privacy policy
Olympus is a knowledge engine that runs on your Mac and answers questions about your own mail, files and notes, including questions you ask in ChatGPT. It is published by Open Coordination Unlimited, Inc. ("OCU", "we", "us"). This policy explains what data Olympus processes, where, why, who receives it, how long it is kept, and how you control it.
In short: your mail, files, notes and the index Olympus builds from them stay on your Mac. We do not have a copy. When you ask a question in ChatGPT, ChatGPT receives the question it sent, plus answers and excerpts built only from items Olympus has tiered Public or Personal, with citations. It never receives Private or Secret items. The Olympus relay that connects ChatGPT to your Mac passes requests through without storing or logging their content.
Where your data is processed
| Place | What is processed there | Who controls it |
|---|---|---|
| Your Mac | Everything Olympus reads from the sources you connect; the search index, built-in model and tier labels it builds; sign-in tokens for the accounts you connect; Olympus settings and logs. | You. OCU has no access. |
The Olympus relay (mcp.olympusplugin.ai) |
Requests between ChatGPT and your Mac, in transit only. See The relay. | OCU, on a server rented from Hetzner Online GmbH in Germany. |
| ChatGPT (OpenAI) | Your conversation, and what Olympus returns to it. See What ChatGPT receives. | OpenAI, under OpenAI's own terms and privacy policy. |
| Accounts you connect (for example Google or Dropbox) | Your Mac reads your items directly from these services using access you grant. | Those providers, under your agreement with them. |
The four tiers
Olympus labels every item, one by one, as Public, Personal, Private or Secret. Item names and titles are labeled separately from their contents, and are Personal by default.
- Public and Personal items may be used to answer questions in ChatGPT.
- Private items (for example health, money, legal and identity matters) are never sent to ChatGPT, not even as summaries. They can be answered only on your Mac with a local model, or by Venice if you choose to set it up (see Third parties).
- Secret items (for example passwords, recovery codes and private keys) are removed from the index and are never given to any model. Olympus keeps only a record that a Secret item exists.
Labeling is automatic and can be wrong. Olympus is designed to err towards the more protective tier when it is unsure.
Categories of data
Processed only on your Mac
- Content from sources you connect: files and notes on your Mac, and, if you connect them, mail and documents from accounts such as Gmail, Google Drive and Dropbox. This can include any information those items contain.
- Derived data: the search index, text extracted from documents, vector representations made by the built-in model, tier labels and their reasons.
- Credentials: the sign-in tokens that let Olympus read the accounts you connect, and the keys and tokens that link your Mac to ChatGPT.
- Settings and logs: your Olympus settings and local log files. Olympus's logs are designed not to contain message content or tokens.
What ChatGPT (OpenAI) receives
- The questions ChatGPT sends to Olympus on your behalf.
- Answers, and excerpts of evidence, built only from Public and Personal items.
- Citations for those items: source name, and title, date and link where available.
- When the only relevant items are Private: one fixed sentence saying the answer stays on your Mac. No titles, counts or content.
- Status shown in the Olympus dashboard: which kinds of sources are connected, indexing progress, and anything that needs your attention. It never includes Private or Secret items or folder names.
What OpenAI does with your ChatGPT conversations, including this material, is governed by OpenAI's terms and privacy policy and your ChatGPT settings, not by this policy.
What the relay processes
ChatGPT reaches your Mac through the relay at mcp.olympusplugin.ai. Your Mac keeps an encrypted, outgoing connection open to the relay, and the relay forwards ChatGPT's requests along it.
- In transit: the relay ends the encrypted connection from ChatGPT (TLS), so request and response contents pass through its memory while being forwarded. It does not store them.
- Not logged: request and response bodies, tokens and credentials, query strings, and caller IP addresses are not logged. The web server in front of the relay keeps no access log.
- Logged: short operational events (for example "session ready" or "request refused") with a time and a short one-way hash of your install's identifier.
- Stored: a registry entry for each install: a random install identifier, the install's public key, and timestamps. It holds no name, email, IP address, account or token.
- In memory only: IP addresses and counters used to limit abuse, and which installs are online.
- The relay does not create, check or store the tokens ChatGPT uses. Your Mac does.
When you are not using Olympus with ChatGPT
Our website, olympusplugin.ai, uses no cookies, analytics or trackers, loads nothing from other sites, and keeps no access log.
Why we process data
- To answer your questions from your own sources, as you ask.
- To connect ChatGPT to your Mac, and only to your Mac, once you approve it there.
- To keep the relay secure and available: rate limits, abuse prevention, and fixing faults.
- To respond when you contact support.
We do not sell your data, use it for advertising, build profiles of you, or use your content to train models.
Where the EU or UK GDPR applies, we rely on: performance of our agreement with you, to run the relay and connect ChatGPT to your Mac; our legitimate interests in keeping the relay secure and working; and our legal obligations where they apply. The content on your Mac is processed by Olympus on your own computer under your control.
Third parties and recipients
- OpenAI provides ChatGPT, which you use to ask Olympus questions. It receives what is described in What ChatGPT receives.
- Google and Dropbox (and other sources you choose) are reached directly from your Mac through their official APIs, with access you grant using your own accounts. Olympus asks for read-only access: for Google, read-only access to Gmail, Google Drive and, if you choose, Google Calendar; for Dropbox, read access to file content, file metadata and sharing information. You can withdraw that access in your account settings with those providers at any time. Olympus's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google is used only to answer your own questions, is not transferred to others except as described in this policy (for example to ChatGPT when you ask), is not used for advertising, and is not read by people at OCU.
- Venice (optional). If you choose to connect a Venice account, Olympus may send the text of Private items relevant to a question to Venice to produce an answer, or to build search vectors. It does this only if you set it up. Venice's handling, including how long it keeps what it receives, is governed by Venice's own terms and privacy policy.
- Other providers you configure yourself, for example an embedding provider, receive only what that setting sends.
- Hosting: the relay and website run on a server rented from Hetzner Online GmbH in Germany. Email to support is handled by our email service provider, which processes messages on our behalf.
- Legal requests: we may disclose the limited data we hold (see relay) where the law requires it. We cannot disclose your content: we do not have it.
Retention
- On your Mac: until you delete it. Uninstalling Olympus stops it but keeps its data until you delete that too (see Your controls).
- Answers in progress: a pending answer is held on your Mac for about 15 minutes after it is ready, so ChatGPT can collect it.
- Relay registry: until the install is removed. An install that has not connected for 90 days is removed automatically.
- Relay event logs: kept for 14 days, then deleted. They contain no content (see relay)..
- Support email: kept as long as needed to resolve your request, then deleted unless the law requires us to keep it longer.
- OpenAI and the providers you connect keep data according to their own policies.
Your controls
- Choose sources: connect and disconnect sources in the Olympus dashboard.
- Disconnect ChatGPT: remove Olympus in ChatGPT, or revoke ChatGPT's access on your Mac from the Olympus dashboard or with
olympus connections listandolympus connections revoke <id>. After revoking, ChatGPT cannot reach your Mac until you approve it again on the Mac. - Revoke account access: remove Olympus's access in your Google or Dropbox account settings.
- Stop Olympus:
olympus engine uninstallstops Olympus and removes its login item. It keeps your settings and data. - Export your data:
olympus data export --output <folder>. - Delete your data:
olympus data delete --alldeletes the index and data Olympus stored on your Mac (add--dry-runfirst to see what it will remove). This cannot be undone. - Relay registry: ask us to remove your install's registry entry by emailing support; otherwise it is removed after 90 days without a connection.
Depending on where you live, you may have rights to access, correct, delete or object to processing of personal data we hold, and to complain to a regulator. Because your content stays on your Mac, the data we hold about you is limited to what is described above. To exercise a right, email us; we will respond within the time the law requires (for example one month under the GDPR, 45 days under California law) and may need to confirm the request is yours.
EU and UK users have the right to access, rectify, erase, restrict or object to processing of their personal data, to data portability, and to lodge a complaint with their local data protection authority.
California residents have the right to know what personal information we collect, use and disclose, to delete it, to correct it, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you.
Sensitive information
Your own sources may contain sensitive information, such as health or financial records, government identifiers, or passwords. Olympus does not ask for this information and OCU does not collect it. Olympus is designed to label it Private or Secret so it is not sent to ChatGPT. Please do not paste such information into ChatGPT yourself.
Security
Connections are encrypted in transit. ChatGPT must be approved on your Mac before it can reach it, and only ChatGPT's published client is accepted. The relay cannot issue tokens or approve new connections. No system is perfectly secure; if we learn of a breach affecting you, we will tell you as the law requires.
Children
You must be at least 13 to use Olympus, the same minimum age as ChatGPT. If you are under 18, you need permission from a parent or guardian. Olympus is not directed at children under 13, and we do not knowingly process personal data from them. If you believe a child under 13 has used Olympus, contact us and we will delete any data we hold about them.
International transfers
OCU is based in the United States, and the relay runs in Germany. Requests from ChatGPT pass through the relay from wherever OpenAI processes them. Where we transfer personal data out of the EU or UK, we rely on an appropriate safeguard, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
Changes
We will post changes on this page with a new date, and for material changes we will give notice in the Olympus dashboard or by other reasonable means before they take effect.
Contact
Open Coordination Unlimited, Inc.
30 N Gould St Ste R
Sheridan, WY 82801-6317
USA
support@olympusplugin.ai