twinly. / Docs

Docs · 09

Privacy & security

Twinly acts as you, so trust is the whole product. The design is simple: your private data stays on your device, every risky action waits for your one-tap approval, and you can stop the twin instantly. Here is exactly how that works.

01What stays on your device

  • Your messages, contacts, calendar, reminders, photos, and files are read on your device and never uploaded by Twinly.
  • Your voice clone is built and stored on-device (the on-device Twinly Voice never sends your voice anywhere). A paid voice key is the only case where audio goes to a cloud provider you chose.
  • Your learned memory, pathways, and failure history live on your device, not in a Twinly cloud profile.
  • Credentials you add (the Gmail app password, an optional voice-provider key, or a beta build's provider key) are stored in your OS keychain (the macOS Keychain, or Windows Credential Manager on a PC), the same vault your OS uses for your own passwords.

02What does leave, and why

The twin thinks with an AI engine, and to reason about a task it sends that engine the relevant context, the request, the draft it is writing, the part of the screen it is reading. On the managed Twinly engine that content routes through Twinly's servers to the AI infrastructure providers running the engine's models, only to generate the response, never to train models. On an older bring-your-own-key beta build it goes directly to the provider whose key you set, under your own account and their terms.

If you sign in, Twinly also processes your account email, subscription and usage-metering records for billing, and, while usage sharing is on, diagnostic telemetry that can include your task prompts; usage sharing switches off in Settings. The precise list is in the Privacy Policy.

Email is sent directly to Google's servers over an encrypted connection; calls go over your phone line. Nothing routes through a third party Twinly hides from you.

03The approval gate

This is the core safety mechanism. The twin drafts and plans freely, that costs nothing and changes nothing, but anything that actually affects the outside world stops and waits for your one-tap approval first:

  • Sending a text, an email, or a message in a group.
  • Placing a phone call.
  • Buying anything or submitting a form that commits you.
  • Posting publicly.
  • Deleting anything (and Twinly prefers the Trash over a hard delete, so it is reversible).

Approvals arrive as a notification, on the island, or in the app, with the exact draft quoted so you see precisely what would go out before you tap Approve. Learned pathways and replays pass through the same gate, there is no path that skips it.

04What is never automated

  • Nothing in the list above ever happens without your explicit approval, no exceptions, no quiet auto-send.
  • Financial actions (moving money, executing a trade) are never done on your behalf, the twin can prepare and surface them, but you complete them.
  • Anticipation only ever suggests; it never acts on its own.
  • Twinly does not run an AI in the background watching you, its suggestions come from reading your own calendar and mail locally, not from constant model calls.

05How to pause or stop the twin

  • Stop a running task from the island (the Stop button) or in the app, instantly.
  • End a call from the Phone tab or the island at any moment.
  • Decline an approval and nothing goes out, the draft is simply discarded.
  • Turn off learning (pathways) or suggestions (anticipation) with their master toggles.
  • Quit the app and the twin does nothing at all until you reopen it.

You are always the one in the loop. The twin is fast and capable, and the controls to slow it down or stop it are always one tap away.