Legal
Privacy Policy
Last updated July 29, 2026 · Pally Technologies, Inc.
Pally is a personal assistant built around your privacy. Your data is encrypted in transit and at rest, and AI processing happens with trusted providers Anthropic and OpenAI under their own privacy policies. You decide what Pally can see, remember, and do, and you can disconnect accounts or delete your data at any time.
This Privacy Policy explains what we collect, how we use it, and the rights you have under the EU General Data Protection Regulation (“GDPR”), UK GDPR, and the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”). It applies to Pally Technologies, Inc. and the Pally service.
If you have any questions, contact us at [email protected].
1. What Pally Is
Pally is a personal assistant you can reach over iMessage or RCS, or by calling the number you text it on. On Pally Max it can also place calls for you and gets its own dedicated phone number and email address. You talk to it like a person, and it helps you get things done: answering questions, remembering what matters, following up, researching, reaching people, calling, emailing, and taking action across the apps you connect.
Pally runs as a secure cloud service. To understand your messages and carry out what you ask, it processes your message content and the data from your connected accounts on our infrastructure, including with AI.
We design Pally to process only what it needs, keep your data encrypted in transit and at rest, isolate it by user, and leave you in control of what is connected, remembered, and deleted.
2. Data We Process
Here is what we process and why.
Messages and requests you send Pally
- Your messages and Pally's replies over iMessage or RCS, including text and any media or attachments you share
- On Pally Max, email sent and received through Pally's own email address
- If you add Pally to a group chat, messages from the group and participants' handles and names
- The requests you make and the context needed to carry them out
- Service, product, policy, or account updates that Pally's team sends to your Pally chat
- Per-recipient delivery state for those updates, used to prevent duplicate delivery and diagnose delivery failures
- Campaign message copy and aggregate delivery results, retained as operational records
We process and store these conversations so Pally can understand you, respond, and take part in the chats you add it to. Group conversations may include personal information about other participants. You can delete individual things in chat. When you delete your account, we remove or anonymize recipient-level account, connection, conversation, and provider identifiers associated with service communications, and the delivered chat message is deleted with your conversations. Campaign message copy and aggregate delivery results remain as operational records.
Memory
- Things you ask Pally to remember
- Profile details you share, such as your name, location, work, interests, and preferences
- Follow-ups, reminders, and open tasks
- Things Pally learns while helping you, including summaries and facts derived from your conversations and connected accounts
We store these so Pally can bring them back at the right time. You can ask Pally what it remembers or tell it to forget anything at any time, and we delete it.
Your contacts
Pally keeps a private contacts book of the people in your life. It may include names, handles, birthdays, relationship notes, and interaction summaries drawn from your conversations and the accounts you connect, such as WhatsApp, iMessage, your calendar and email, and your address book. We use it only to help you with the people you actually talk to. It is never shared, and you can delete any contact or ask Pally to forget what it knows about someone.
Connected accounts
- When you connect an app — WhatsApp, Gmail, Outlook, Google Calendar, Google Drive, Google Docs, Google Sheets, iCloud Calendar, iCloud Mail, iCloud Contacts, Notion, Linear, Slack, GitHub, Jira, Confluence, Todoist, Splitwise, Instacart, Granola, X, or a growing set of others — you authorize Pally to access the data needed to do what you ask
Pally only uses the connections you turn on, and only to help you. It does not bulk-copy your connected accounts. Your mailbox stays in Gmail and your notes stay in Notion: Pally reads what a task needs on demand and keeps only the information described in this policy, such as memories, contact details, files you ask it to save, and finance summaries.
OAuth app connections are brokered by Composio. Pally's database stores the connection status, not the OAuth tokens. You can disconnect any app at any time, which revokes Pally's access.
With WhatsApp, Pally watches connected chats only to flag messages that need you and prepare your catch-ups; it never joins or replies in your conversations, and never sends anything without your approval. So it can work in the background, your WhatsApp data is processed and stored on a dedicated per-user server, encrypted in transit and at rest. It is removed when you disconnect WhatsApp or delete the data.
You can also add your own MCP servers as custom integrations. The data Pally exchanges with a custom server is governed by that server operator's own terms and privacy practices.
Secure account sign-in
When you connect a website account, you sign in yourself through a secure browser session run by our browsing providers. Pally never sees, requests, types, or stores your passwords or one-time codes.
To keep you signed in for the tasks you authorize, these providers may store your session credentials, fully encrypted in transit and at rest. Their handling is governed by their own privacy policies: Browser Use, Browserbase, Bright Data.
Files you save
Pally stores attachments and emails you explicitly ask it to save, along with files it creates for you, such as spreadsheets and PDFs. Files are encrypted, subject to size caps, and deletable at any time.
Bank accounts
If you choose to link a bank account through Plaid, Pally stores the account balances and transaction summaries you authorize so it can answer your money questions. This access is read-only by design: Pally cannot move money, pay bills, or make transfers. Your bank credentials stay with Plaid, and access tokens are kept in an encrypted secrets vault, not Pally's database. Unlinking your bank deletes the stored finance data and revokes access at Plaid.
Purchases
When you approve a purchase at checkout, payment uses a single-use virtual card issued by AgentCard. The card is capped at the exact total you approved and closed after the charge. Pally never stores card numbers: they are held in memory only for the checkout and are never logged. If AgentCard requires identity verification, it happens on AgentCard's own surfaces, and Pally does not keep your identity documents.
Phone calls
You can talk to Pally on the phone on any plan by calling the same number you text it on; Pally verifies it's you with a PIN before the call gets access to anything. On Pally Max, Pally can also place calls on your behalf, such as calling a restaurant, always with your go-ahead, from its own dedicated number. Twilio carries the call audio, and OpenAI's realtime voice AI processes it live. Calls are never recorded. Pally keeps a text transcript so you have a record of what was said, and you can delete it like any other conversation.
Location
Location sharing is optional and off by default. If you share your location with Pally through iMessage, it stores your latest location, a short recent history, and places where you spend time to offer nearby suggestions, place-based reminders, and travel awareness. Pally receives only your own location and has no access to anyone else's. You can stop sharing at any time and delete the location data.
Account and authentication data
- Your phone number and email, account identifiers, and authentication tokens used to recognize you and keep your account secure
AI processing
Anthropic powers Pally's assistant intelligence. OpenAI powers realtime voice calls, voice-note transcription, and understanding features such as embeddings that make memory searchable. Both process Pally's requests under their own privacy policies and API data commitments. Neither uses Pally's API data to train its models. Pally also uses open-source models, routed through OpenRouter, for lightweight message triage.
You can read how each provider handles data: Anthropic Privacy Policy, OpenAI Privacy Policy.
Usage and diagnostics
- Pseudonymous usage events, app and operating-system version, device type, and general performance metrics
We use first-party, internal analytics to keep Pally reliable. We do not use third-party analytics or advertising trackers, and we do not send marketing emails.
Billing
Pally offers Free, Pro, and Max plans. If you choose a paid plan, payments are handled by Stripe. We do not store full card numbers.
Customer support
- Your email address and anything you choose to include in your message
- Diagnostic logs only if you explicitly choose to send them
3. How We Use Your Data (Purposes & Legal Bases)
Under GDPR, we rely on the following legal bases.
Contract (Article 6(1)(b))
To provide the Pally service and its features, including understanding and responding to your messages, remembering what you ask, connecting the apps you choose, and managing your account.
Legitimate interests (Article 6(1)(f))
- Keeping the service reliable and secure
- Preventing fraud, abuse, and misuse
- Understanding general usage patterns to improve Pally
We carry out legitimate-interest balancing tests where required.
Consent (Article 6(1)(a))
- Optional analytics and diagnostics
- Optional product communications
- Each app connection you choose to authorize and optional location sharing
Legal obligations (Article 6(1)(c))
To comply with tax, accounting, regulatory, and consumer-protection laws.
4. Your Rights
GDPR (EU/UK)
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure, the right to be forgotten (Art. 17)
- Right to restriction (Art. 18)
- Right to portability (Art. 20)
- Right to object to processing (Art. 21)
- Right to withdraw consent at any time
- Right not to be subject to automated decision-making (Art. 22)
CCPA/CPRA (California)
- Right to know what categories of personal information we collect
- Right to access specific pieces of information
- Right to deletion
- Right to correct inaccurate information
- Right to opt out of sale or sharing (we do not sell or share data for advertising)
- Right to limit the use of sensitive personal information
- Right to non-discrimination
You can exercise any of these rights at any time by contacting [email protected], and we may take reasonable steps to verify your identity. Many controls are also available right in the chat: you can ask Pally what it remembers, tell it to forget something, or disconnect any connected app.
5. Data Retention
- Messages and Pally's replies, memory, contacts, call transcripts, saved files, finance data, and location data: retained while your account is active and until you remove them or delete your account. You can delete individual things in chat, ask Pally to forget anything, or ask it to delete your data. Deleting your account deletes these items from Pally's systems; service-communication operational records are handled as described below.
- Service communications: campaign message copy and aggregate delivery results are retained as operational records. When you delete your account, recipient-level account, connection, conversation, and provider identifiers are removed or anonymized, and delivered chat messages are deleted with your conversations.
- Connected apps (other than WhatsApp): accessed on demand without bulk-copying your accounts. Pally keeps only the information described in this policy, including memories and contact details derived while helping you and files you ask it to save.
- WhatsApp: processed and stored on a dedicated per-user server, encrypted in transit and at rest, and removed when you disconnect or request deletion.
- Linked bank accounts: unlinking deletes the balances and transaction summaries stored by Pally and revokes access at Plaid.
- AI processing: handled by our AI providers under their own privacy policies and API data commitments.
- Secure browser sign-in: session credentials are stored, fully encrypted, by our browsing providers to keep you signed in, and removed when you disconnect or delete.
- Account and authentication data: kept while you maintain an account.
- Internal analytics: retained for a limited period, then deleted or aggregated.
- Support communications: kept only as long as needed to resolve your issue.
6. Cookies and Tracking
Pally is a texting service, so it does not depend on browser cookies to work. Where we use cookies or similar technologies, they are strictly necessary to operate the service — for example, to keep a secure browser sign-in session active while you connect an account. We do not use advertising, marketing, or cross-site tracking cookies.
7. International Data Transfers
Pally Technologies, Inc. is based in the United States, and your data may be processed there. If you are located in the EU or UK, we rely on legally recognized safeguards for these transfers:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements (DPAs) with our service providers
- Appropriate technical and organizational safeguards
8. Legal Requests and Disclosures
We may access, preserve, or disclose your information if we believe in good faith that it is reasonably necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms and policies; to detect, prevent, or address security, fraud, or technical issues; or to protect the rights, property, or safety of our users, the public, or Pally. Where we are legally permitted, we will make reasonable efforts to notify you of legal requests for your data.
9. Security
We implement industry best practices to protect your data, including:
- Encryption of data in transit and at rest
- Strict tenant isolation, so your data is never exposed to other users
- Least-privilege access controls and logging
- Minimization of personal data across our systems
- Regular security reviews
No system is perfectly secure, but we design Pally to minimize what is processed, keep your data encrypted and tightly controlled, and give you practical ways to see and delete what Pally knows.
10. Service Providers
We work with a small set of service providers, each bound by data-processing agreements. They process only what their function requires, and none of them receive your data for advertising.
| Provider | Purpose | Key data processed | Region |
|---|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure | Account metadata, encrypted data in transit and at rest, system logs | US |
| Anthropic | AI processing (the assistant's intelligence) | Message and request content, processed under its privacy policy | US |
| OpenAI | AI processing (voice calls, transcription, and understanding features) | Message, voice, and request content, processed under its privacy policy | US |
| OpenRouter | Lightweight message triage using open-source models | Short classification prompts; configured to disallow data collection | US |
| Photon | Text message delivery (iMessage and RCS) | Messages, media, and any location you share, in transit between you and Pally | US |
| Twilio | Phone-call carrier for calls with Pally | Call audio and phone numbers in transit | US |
| AgentMail | Pally's own email address on Pally Max | Email sent and received with Pally's address | US |
| Composio | Connecting the apps you authorize (MCP access) | Authorization to connected accounts; Pally stores connection status, not OAuth tokens | US |
| Granola | Meeting-notes integration, when you connect it | Your meeting notes, accessed on demand as authorized | US |
| Monid | Public social-media lookups (posts, profiles, and searches on X and Instagram) | The public search query, handle, or post link needed for the lookup, which can include names from your calendar when Pally preps a meeting | US |
| Plaid | Bank account linking, read-only | Account balances and transactions you authorize | US |
| AgentCard | Single-use virtual cards for purchases you approve | Approved amount and checkout details; card numbers are never stored by Pally | US |
| Stripe | Subscription billing | Payment details; we do not store full card numbers | US |
| Browser Use, Browserbase, Bright Data | Secure browsing and account sign-in you direct | Encrypted session credentials, plus page content and actions for the tasks you request | US |
| Task-specific services | Narrow lookups for tasks you request, such as web research, image generation, flight status, or weather | Only the specific query needed for that task | US |
We do not sell or share your data with advertisers. A current list of subprocessors is available on request.
11. Children's Privacy
Pally is intended for adults. You must be at least 18 to use Pally, and we do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has used Pally, contact us and we will delete the data.
12. Changes to This Policy
We may update this policy from time to time. If changes are significant, we will notify you by text, email, or in-app before they take effect.
13. Contact Us
Pally Technologies, Inc.
Email: [email protected]
Address: 643 Teresita Blvd, San Francisco, California, US 94127