Privacy Policy

Last updated: September 14, 2026

Overview

Local tools run on your Mac or Windows PC; available integrations vary by platform. Your chosen AI provider and optional cloud connectors receive the content needed for your requests under their own terms. A desktop AI app may also use a cloud model.

Application data used by local tools

  • Email content, subjects, senders, or recipients
  • Calendar events, titles, attendees, or locations
  • Contact names, emails, or phone numbers
  • Microsoft Teams messages, channels, or chat content
  • OneDrive or local file contents
  • Notes, iMessages, or Safari bookmarks
  • OmniFocus tasks or project details
  • Any data processed by MCP tools at runtime

Supported files and local indexes are processed or stored on your device. Tool results are passed to the AI client you selected. With Cloud Relay enabled, requests and responses also pass through LMCP infrastructure before reaching that client; a cloud provider may process and retain the requested content under its own terms.

What data we do collect

1. Anonymous heartbeats

The app sends operational heartbeats containing version and platform information, a hashed device identifier, uptime, resource usage and local search-index counts and timings. These heartbeat measurements do not include email content, subjects, senders or recipients. This limitation applies to heartbeat telemetry, not to content you explicitly request through an AI client.

Heartbeats are used to: detect outdated versions and push updates, understand platform distribution (Apple Silicon vs Intel), and measure overall product health.

2. Installation events

When you run the installer, we record: npm package version, macOS version, CPU architecture, Node.js version, which AI clients were configured, your approximate location (city/country via IP geolocation), and an anonymous machine ID. Your IP address is used only for geolocation and is not stored.

3. License information

We store your email address and license key to verify that the app is authorized to run. No payment data is stored on our servers. License validation makes an outbound request from your device to verify the key.

4. Feedback and bug reports

If you submit a bug report or feature request via the report_problem or request_feature tools, we store the message text, server version, and optionally your email address if provided. This data is used only to respond to your report.

5. Website analytics

The marketing website uses Cloudflare Web Analytics, Microsoft Clarity and Google Analytics 4 for traffic analysis, session insights and audience reporting. Clarity and Google Analytics may use cookies. These providers process website usage information under their own terms; website analytics do not themselves grant access to the content of your local apps.

Cloud Relay (optional)

Cloud Relay lets web AI clients connect to your local MCP server. When enabled, requests and tool responses travel through LMCP infrastructure over encrypted connections to the selected AI provider. That provider receives the content needed for your request and handles it under its own terms. Local tool execution does not mean the whole workflow stays on-device.

The Cloud Relay is opt-in and disabled by default. You can disable it at any time from the Settings page.

Data retention

  • Heartbeat records: 90 days rolling
  • Installation events: retained for product analytics, anonymized after 12 months
  • Account records: retained for account duration + 1 year
  • Feedback reports: retained until resolved or deleted on request

Third-party services

  • Railway — backend API hosting (EU and US regions).
  • Cloudflare — CDN, DNS, R2 storage for binary distribution, and website analytics.

Hosting and connectivity services may handle traffic needed to provide the service. Your selected cloud AI provider and optional connectors receive the content required for authorized requests under their own terms. Assess the complete data flow, including these recipients.

GDPR & data protection

Compliance depends on your full workflow, policies and provider agreements. LMCP alone does not guarantee GDPR or other regulatory compliance. Colibird is responsible for the account and feedback data described in this policy.

You have the right to: access the personal data we hold about you, request deletion of your data, and withdraw consent at any time. To exercise these rights, email [email protected].

Security

Local access is controlled through credentials and permissions. Connections to LMCP services use transport encryption such as HTTPS/TLS or secure WebSocket. Encryption in transit does not prevent an authorized receiving AI provider from processing the content you request.

Changes to this policy

We may update this policy as the product evolves. Material changes will be announced via the in-app update mechanism. The "last updated" date at the top of this page always reflects the current version.

Contact

Questions about this policy: [email protected]
General support: [email protected]