Privacy Policy
Last Updated: February 2, 2026 | Effective Date: February 2, 2026
1. Introduction and Architecture of Sovereignty
This Privacy Policy ("Policy") is a legally binding agreement between you ("User") and Triglavis LLC ("Triglavis," "we," "us"), regarding your use of WorkspaceOS (the "Service").
1.1 The Architecture of Sovereignty
Unlike traditional SaaS platforms that centralize your data to provide intelligence, WorkspaceOS is built on a "Local-First, Cloud-Optional" architecture. We believe that true AI autonomy requires absolute data sovereignty.
- Universal Vision: All screen capture, OCR, and file indexing occur locally on your device.
- Causal World Model: Your project graph is stored in an encrypted local database (the "World Model").
- No Silent Exfiltration: Triglavis does not stream your screen pixels or private files to our servers. Your data leaves your device only when you explicitly authorize an Agent to perform a specific external action.
BY ACCESSING OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY.
2. Definitions
- "Personal Information" means information that identifies or relates to a particular individual.
- "World Model" means the local, encrypted causal graph generated by the Service to represent the User's files, screen context, and workflows.
- "Universal Vision" means the local process of ingesting visual signals (screen pixels) and converting them into semantic vectors.
- "Agent Parliament" means the internal governance protocol that verifies autonomous actions against local constraints.
- "Sensitive Personal Information" includes financial data, passwords, or health data captured via the screen.
3. Information Processing & Ingestion
3.1 Local-First Ingestion
The Service is designed to process the majority of Personal Information locally on your hardware. The Service acts as a local agent, ingesting signals to build your World Model without transmitting them to Triglavis.
3.2 Universal Vision & Visual Data
The Service utilizes "Universal Vision" to ingest visual information from your device screen.
- Local Processing: All screen capture, OCR extraction, and visual pattern analysis occur locally on your device. Raw screen pixels are processed into semantic vectors and immediately discarded; they are not streamed to Triglavis servers.
- Redaction: The Service includes "Privacy Shields" designed to detect and redact sensitive fields (e.g., credit card numbers, passwords) before they are written to your local World Model.
- User Control: You retain full control over the "Vision Window," including the ability to pause capture, blacklist specific applications, or wipe the local visual index at any time.
3.3 Behavioral Patterns (Teleological Primitives)
We analyze your interactions to identify "Teleological Primitives" (Entities, Actions, Constraints). This behavioral modeling happens locally to automate your workflows. These patterns are stored in your local World Model and are not shared with Triglavis unless you explicitly choose to publish a "Domain Pack" or share a pattern with a team.
4. Use of Information
4.1 Primary Purposes
We process data to:
- Provide the Operating Layer: Enabling the "Universal Vision" and "Agent Parliament" features on your device.
- Local Inference: Running small language models (SLMs) on your device to categorize work without external API calls.
- Remote Inference (Authorized): Transmitting specific, redacted context to third-party LLM providers (e.g., OpenAI, Anthropic) only when required to answer a user prompt or execute a complex agentic task.
4.2 Model Training Policy
Triglavis does NOT use your specific World Model to train our foundational models. Your private causal graph, screen history, and files are yours. We may use aggregated, anonymized telemetry (e.g., "User X successfully used the 'Refactor' Action") to improve system performance and "Agent Parliament" decision-making logic, but your semantic content remains isolated.
4.3 Governed Autonomy (Agent Parliament)
The Service uses automated reasoning to execute tasks. To ensure safety, we employ an internal governance protocol known as the Agent Parliament.
- Pre-Execution Review: Autonomous actions are debated by internal sub-agents (Security, Quality, Efficiency) against your local Constraints.
- Thinking Stream: The system maintains a local "Thinking Stream" (audit log) of its reasoning. You have the right to inspect this log to understand why an automated decision was made.
5. Data Sovereignty, Storage, and Retention
5.1 Data Storage Architecture
- Primary Storage (The World Model): Your Causal Graph, visual index, and behavioral patterns are stored in an encrypted local database on your device.
- Cloud Sync (Optional): If you enable multi-device sync, data is encrypted on your device before transmission ("Client-Side Encryption"). Triglavis cannot decrypt or view your World Model.
5.2 Data Retention
- Screen Vectors: Retained locally for the duration configured in your "Memory Settings" (default: 30 days).
- World Model: Retained until you delete the Project or uninstall the Service.
- Logs: Operational logs are retained for 90 days.
6. Data Sharing and Disclosure
6.1 No Sale of Personal Information
We do not sell, rent, or lease your Personal Information or your World Model data to third parties.
6.2 External AI Providers
When you use features that require large-scale reasoning (e.g., "Ask WorkspaceOS"), specific text or context may be sent to third-party AI providers (e.g., OpenAI, Anthropic).
- Governance: The Agent Parliament reviews and redacts these payloads before transmission to minimize PII exposure.
- Zero-Retention: We negotiate "Zero-Retention" policies with API partners where possible, ensuring they do not train on your data.
6.3 Legal & Safety
We may disclose information if required by law or to protect the safety of users. However, because your World Model is encrypted locally, we may be technically unable to produce your specific content in response to a subpoena without your private keys.
7. Your Rights
Depending on your jurisdiction (GDPR, CCPA), you have rights regarding your data:
- Right to Access: You can export your entire World Model via the "Export Project" feature.
- Right to Delete: You can use the "Nuke" command to securely erase your local World Model and all associated indices.
- Right to Audit: You may inspect the "Thinking Stream" logs to verify how your data is being used by Agents.
To exercise these rights, use the in-app "Data Controls" panel or contact privacy@triglavis.com.
8. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect data from minors.
9. Changes to This Policy
We reserve the right to modify this Policy. If we make material changes—especially ones that affect the "Local-First" promise—we will notify you via the application and require affirmative consent.
10. Contact Information
Triglavis LLC
- Email: privacy@triglavis.com
- Website: https://tryworkspaceos.com
Security Reporting: To report a vulnerability in the Agent Parliament or Privacy Shields, contact security@triglavis.com.