Terms of Service

Version 1.4 · Last updated 2026-07-10

<!-- terms-source-version: 1.4 -->

1. Preamble

READ CAREFULLY BEFORE INSTALLING OR USING RUNMYAI DESKTOP.

RunMyAI Desktop is an AI-powered automation application that delegates the ability to act on your behalf to AI agents. This means the Software can autonomously or under human supervision browse the internet, access your local data, send communications, and execute tasks — all from your own computer.

This is not a cloud-hosted AI service. The Software runs on your personal computer, uses your internet connection, your real IP address, and — where authorized by you — your local sessions and data.

If you do not agree with these Terms in their entirety, do not install, use, or purchase the Software. Using the Software constitutes full and unconditional acceptance of all terms described herein.

These Terms are intended to be clear, honest, and accessible. Any questions: legal@runmyai.app


2. What the Software Is

RunMyAI Desktop ("Software") is a personal computer application developed by RunMyAI ("Company") that uses large language models ("LLM") to plan and execute tasks on behalf of the user, either autonomously or under human supervision.

2.1 The Software IS

  • A delegation tool: the user instructs the agent; the agent acts.
  • A tool orchestrator: the Software connects local LLMs to built-in tools (web search, email, finance, documents, filesystem within attached workspace folders, image, video, and voice generation, process automation, and other product domains).
  • Locally operated software: processing, data, and browsing occur on the user's machine, not on the Company's servers.

2.2 The Software is NOT

  • A cloud service: unlike cloud-hosted AI assistants, the Software does not execute searches or actions on the Company's remote servers. Everything occurs on your machine.
  • An agent with legal personhood: all actions executed by the Software are legally attributable to the user who authorized them. The Software is a tool, not an autonomous agent with its own legal liability.
  • An AI model provider: the Software runs inference on the user's own machine using large language models distributed with or downloaded by the Software, all executing locally. The Software does not call third-party LLM providers on the user's behalf and does not require the user to supply provider API keys.
  • Infallible software: LLM outputs are probabilistic. They may contain errors, inaccuracies, outdated information, or content inconsistent with reality.

2.3 Software Capabilities

The Software includes, without limitation, the following capabilities that the user acknowledges and accepts:

  • Autonomous internet search from the user's machine
  • Web page navigation using a native browser engine (WKWebView / WebView2)
  • Reading and composing emails
  • Access to and management of local financial data
  • Task and project management
  • Image generation on the user's machine (stable-diffusion.cpp)
  • Video generation on the user's machine (MLX mlx-video; Wan and LTX-2 families)
  • Voice synthesis and transcription on the user's machine (text-to-speech and speech-to-text)
  • Execution of multi-step plans with parallel sub-agents
  • Iterative execution with autonomous refinement (quality loops)
  • UI control via navigation commands
  • Remote control of the agent from messaging channels (Telegram, iMessage, and, where enabled, WhatsApp, Slack, Discord, Signal, and an on-device WebChat), and from the user's own paired devices (Remote Link). Each install serves a single user; there is no cloud relay and no multi-user access.
  • Scheduled and proactive autonomous execution: the agent may run tasks on a schedule and initiate messages or actions without a contemporaneous prompt (for example, a morning briefing), subject to the autonomy level configured for the relevant product and surface.
  • Reading the user's local message stores when the user enables a messaging channel — for example, the macOS Messages database (~/Library/Messages/chat.db), which contains the user's conversations with third parties (see Section 5.6).
  • Agent-to-agent (A2A) communication: the agent may exchange cryptographically signed messages with another person's agent to negotiate an arrangement (for example, a meeting time) within a user-defined, scoped mandate, and may auto-confirm an outcome that falls entirely inside that mandate (see Sections 4.2 and 4.5).
  • Video and audio calls between the user and their contacts, established either directly between the two devices (peer-to-peer) or through a media server the user operates themselves. No call media passes through the Company's infrastructure at any point.
  • Recording of those calls on the user's device (and, where the user operates their own media server, on that server), followed by on-device transcription, AI-generated summaries, and extraction of action items and dates, all of which are attached to the originating email thread and made searchable (see Section 5.9).
  • Live, on-screen transcription while a recorded call or captured meeting is in progress. The live transcript is never persisted; only the final transcript is stored.
  • On-device capture of meetings held in third-party conferencing applications: the Software records the user's microphone and the device's system audio. No bot joins the meeting, nothing is installed on the other side, and the other participants receive no notice from the Software (see Section 5.9).
  • Import of externally produced audio and video recordings into the same local transcription and analysis pipeline, and re-transcription of any stored recording with a newer or larger model.

3. Local Execution and Digital Identity

3.1 Your Searches Leave Your Machine With Your IP

When the Software conducts internet searches, accesses web pages, or makes requests to external services on your behalf, those actions are executed from your computer, using:

(a) Your real IP address

The network address that identifies your internet connection. Unlike cloud-based AI services — where searches and browsing are performed by remote servers in data centers, using those providers' IP addresses — RunMyAI Desktop executes these operations directly from your device.

Every site visited by the agent will see your real IP address.

This means:

  • Your geographic location can be inferred by the sites the agent visits.
  • Your internet service provider (ISP) or corporate/home network may log these requests as part of your browsing history.
  • From the technical and legal perspective of remote servers, agent traffic is indistinguishable from your own browsing traffic.

(b) Your geographic location

Inferable from your IP address by the servers the agent contacts.

(c) Your browser fingerprint

The embedded browser engine (WKWebView on macOS, WebView2 on Windows) carries technical characteristics — operating system version, screen resolution, language, time zone, and others — that third-party sites may use to identify your device, independently of your IP address.

(d) Shared browser cookies and sessions

The Software uses a cookie store shared between:

  • The agent's automated search module
  • The embedded browser panel (when used by the user)

This means cookies set during your manual browsing in the embedded panel may be inherited by subsequent agent searches, and vice versa. In particular, authenticated sessions on websites (e.g., logins to web services) may be accessible to the agent's browser engine if you have previously browsed those sites in the embedded panel.

3.2 Why This Is Different From What You Are Used To

Users accustomed to cloud-based AI services (cloud-hosted chat assistants and search engines) are familiar with a model where:

  • The search is performed by the provider's servers, in geographically distant data centers, using the IP addresses of those data centers.
  • The searched site has no connection to the end user's IP address.

RunMyAI Desktop operates on a fundamentally different model:

  • The agent is you, from the internet's perspective. Every request made by the agent appears to the outside world as a request made by you, from your IP address, from your device.
  • This is a deliberate architectural choice that offers privacy advantages regarding your data (your data does not pass through the Company's servers), but it means your network identity is used by the agent.

3.3 Legal Implications

All activity performed by the agent on the internet, from your machine, is legally attributable to you. This includes:

(a) Compliance with third-party Terms of Service

You are solely responsible for ensuring that the agent's use of third-party websites, services, and platforms complies with those parties' Terms of Service. Many websites and services prohibit automated access, content scraping, bots, or software agents. Violations of those terms are your sole responsibility.

(b) Browsing history

Searches and pages accessed by the agent may appear in records held by your ISP, home or corporate router, or any network monitoring systems present in your environment.

(c) Third-party tracking

Sites visited by the agent may collect visit data, set cookies, and process your IP address exactly as they would if you had visited the site manually via a conventional browser.

(d) Personal data under GDPR/LGPD

Under the GDPR (EU General Data Protection Regulation), the LGPD (Brazilian General Data Protection Law), and equivalent laws, IP addresses constitute personal data. The processing of your IP address by third-party sites visited by the agent occurs under those sites' own privacy policies, over which the Company has no control.


4. Agent Autonomy and Responsibility

4.1 Autonomy Levels

The Software operates at five autonomy levels, configured independently by the user per product and per surface (desktop, Telegram, iMessage, and any additional channels). The levels are:

LevelNameDescription
0ManualThe agent answers questions and provides information only. It does not execute actions on the user's behalf.
1SuggestThe agent proposes individual actions. The user approves each one before execution.
2BatchThe agent proposes batches of related actions. The user reviews and approves the batch before execution.
3Confidence-GatedThe agent executes autonomously when its stated confidence meets a threshold the user configures. Below threshold, the agent asks for approval.
4AutonomousThe agent executes all actions immediately, without any runtime confirmation, including actions that affect third parties or external systems. All executions are logged to the local audit trail.

First-launch default. On first launch, every product and every surface is set to Level 0 (Manual). The Software does not recommend raising the level. The user raises each product and each surface consciously after evaluating the risk profile of the specific workflow.

The user is solely responsible for configuring an autonomy level compatible with their personal judgment, their available supervision capacity, and the sensitivity of the tasks being delegated. "Consent fatigue" — approving actions without careful review, or raising autonomy levels without reflection — is the user's sole responsibility.

4.2 Actions With External Consequences — User Assumption of Risk

Some actions, when executed by the agent, reach third parties or external systems that are not party to these Terms (people, services, banks, government agencies, remote APIs). Non-exhaustive examples:

  1. Sending emails, messages, or any communication on behalf of the user
  2. Executing financial transactions of any amount
  3. Accepting Terms of Service on third-party platforms
  4. Creating or modifying accounts on external services
  5. Sharing the user's personal data with third parties not previously authorized
  6. Writing to external APIs, databases, or services not owned by the user
  7. Negotiating and auto-confirming an arrangement with another person's agent over the Agent-to-Agent channel, within the scope of a mandate the user defined
  8. Executing any of the above on a schedule or proactively, while the user is away from the machine and not contemporaneously supervising

The user expressly acknowledges and accepts that:

  • At Levels 0-2, such actions will pass through the approval flow inherent to those levels (Manual does not execute; Suggest and Batch queue for explicit approval).
  • At Level 3, such actions execute without approval when the agent's stated confidence meets the user-configured threshold.
  • At Level 4, all such actions execute immediately with no runtime confirmation. The agent may send, transfer, accept, or create on behalf of the user at any time, without prompting.
  • The Software does not silently raise the user's autonomy configuration. Certain high-risk operations retain deterministic confirmation gates that are not removed by the autonomy level: financial and filesystem write operations, sensitive built-in tool domains, and any side-effecting action taken in a turn after the agent has consumed untrusted external web content. Outside these specific gates, the configured level is honored, and the user remains responsible for actions executed within it.
  • The user assumes full legal, civil, contractual, and reputational responsibility for every action executed at every level, including actions that affect third parties who did not consent to these Terms and who may have their own policies governing AI-agent interaction (for example, anti-spam policies of email providers, AI-transaction rules of financial institutions, bot policies of online services). Attribution of such actions is to the user, not to the Software or to RunMyAI.
  • The user is solely responsible for deciding whether Level 3 or Level 4 is appropriate for any given product, action, or surface, and for setting per-action or per-product overrides when finer control is desired. The autonomy settings UI presents informative metadata (risk level, categories of user data touched, reversibility) to support the user's decision at configuration time; that metadata is informative only and does not restrict the user's choice.

4.3 User Responsibility

The user is solely responsible for:

  • Validating and reviewing all agent-generated outputs before making decisions or acting on them
  • Configuring autonomy levels compatible with their available supervision capacity
  • Ensuring their use of the Software complies with applicable law in their jurisdiction
  • All actions executed by the agent that have been authorized, whether explicitly or through elevated autonomy configuration
  • Providing clear and precise instructions to the agent, knowing that ambiguity may result in unintended interpretations

4.4 Iterative Execution and Local Compute Cost

The Software may execute plans in iterative refinement cycles (e.g., generate, evaluate, refine, repeat). All inference runs on the user's machine, so each iteration consumes local CPU, GPU, memory, disk, and battery resources. The user acknowledges that multi-step plans, parallel sub-agents, and quality loops may substantially increase local resource usage, and that there is no per-token or per-call monetary cost paid to the Company or to any third-party model provider.

4.5 AI Disclosure on Agent Communication With Third Parties

When the agent autonomously composes and sends a communication to a third party — an email sent through the built-in mail tool, or a message exchanged with another person's agent over the Agent-to-Agent channel — the Software marks that communication as AI-generated. The mark has two parts: a short human-readable line in the message body (for example, "Sent by [your name]'s AI agent — RunMyAI") and a machine-readable header. This is the Software's implementation of the transparency obligation in Article 50 of the EU AI Act (see Section 8.3). The marking is applied automatically at the point of sending and the user cannot suppress it for autonomous agent sends.

This marking is not applied to messages the user composes themselves in the interface and then sends (the user is the author of those), nor to the agent-to-agent transport envelope's encoded payload, which is machine-to-machine signaling already labelled as an agent message at the protocol level.

The user acknowledges that this automatic marking covers the channels the Software controls. Where the user directs the agent to act through a surface the Software cannot mark, or where local law requires a different or additional form of disclosure, the user is responsible for providing it.


5. Known Risks and Limitations

The user acknowledges having been informed of and accepts the following risks:

5.1 LLM Inaccuracy

Large language models generate text probabilistically. Outputs may be factually incorrect, incomplete, outdated, misleading, or inconsistent with reality. No output should be treated as fact, professional advice (legal, financial, medical, technical), or absolute truth without independent verification by a qualified source.

5.2 Prompt Injection

Content present in web pages, documents, emails, or any other source processed by the agent may contain hidden instructions ("prompt injection") designed to manipulate agent behavior, potentially causing:

  • Actions not intended by the user
  • Exfiltration of data to third parties
  • Execution of commands outside the scope authorized by the user

The Software implements mitigations against prompt injection but does not provide absolute protection. The user should be aware of this risk, particularly when processing content from untrusted sources. Current mitigations include: (a) deterministic pre-injection filters applied to every byte of web-fetched content, including search_web snippets and fetch_page output; (b) Microsoft Spotlighting delimiting that marks web content as untrusted data in the LLM context via per-call randomized delimiters; (c) a structured sanitization verdict (clean / sanitized / rejected) accompanying every tool result; (d) a single input-sanitization chokepoint at the web tool dispatch point; (e) evasion normalization that detects injection phrases hidden behind homoglyph substitution, leetspeak, character-level spacing, multi-line fragmentation, and URL/HTML-entity encoded payloads; (f) flexible phrase matching that tolerates filler words inserted between tokens; and (g) multilingual injection phrase detection covering German, Spanish, Portuguese, and French, in addition to English. All mitigations run entirely on-device with no cloud inference. The same Spotlighting delimiting and untrusted-data labelling is also applied to email content processed by the mail AI features.

5.3 Session and Cookie Inheritance

The Software's browser module may inherit session cookies from sites visited by the user in the embedded panel. In some cases, this may result in the agent accessing authenticated sessions (e.g., accounts on web services) that the user did not intend to expose to the agent. The user may clear this data via the Software's settings.

5.4 Unintended Scope Escalation

When operating with multiple tools in parallel or iterative execution, the agent may access data domains beyond what was originally intended by the user (e.g., when searching for a project, the agent may access related emails). Use of supervised mode is recommended for highly sensitive tasks.

5.5 Third-Party Availability

The Software depends on third-party APIs and services (web search engines, email providers used by the local mail client, and other external services) that may be unavailable, may alter their terms of use, or may be discontinued without prior notice. The Company assumes no liability for interruptions caused by third parties.

5.6 Access to Sensitive Local Data

The Software, when authorized by the user, may access emails, documents, financial data, and other sensitive local data. The user is responsible for defining what data the agent may access and for not authorizing access to data whose exposure to the agent would be undesirable.

In particular, when the user enables the iMessage channel, the Software is granted Full Disk Access by the operating system and reads the local macOS Messages database (~/Library/Messages/chat.db). That database contains the user's entire conversation history, including messages exchanged with third parties who are not party to these Terms. The user acknowledges this scope of access and is responsible for the third-party personal data thereby made available to the agent, including any obligations the user has as a data controller under applicable data-protection law. Before the iMessage channel can be enabled, the Software requires the user to acknowledge this third-party access in a dedicated in-app disclosure; the channel cannot be activated until that acknowledgment is given.

5.7 Local Key File Dependency

The user's local database (runmyai.db) is encrypted at rest, and the 256-bit master key is held in a key file stored in the application's local data directory, protected by operating-system file permissions. The Company does not store, copy, escrow, or transmit the master key, and there is no recovery mechanism on the Company's side.

The user acknowledges that loss of the key file — whether through operating system reinstall, hardware change, user account loss, disk format, or any other event that destroys it — renders the local database, and the call and meeting recordings encrypted under the same master key (Section 6.1), permanently unreadable. There is no backdoor and the Company cannot recover the data.

The only sanctioned path for moving data between installs, or for keeping an independent copy that survives loss of the key file, is the password-protected Export and Import flow described in Section 6.7. The export contains the database — including every transcript, AI summary, and search index derived from recordings — but not the recording media files themselves, which have no key-independent backup path and are permanently lost with the key file. The user is solely responsible for proactively creating such an export before any event that may destroy the key file.

5.8 Channel and Agent-Mesh Safeguards

Because remote control and agent-to-agent communication widen what the agent can do, the Software applies deterministic safeguards on these surfaces that operate independently of the configured autonomy level:

  • Pairing by physical proximity. A messaging channel only accepts commands from the single device the user paired through a short-lived code generated on the desktop; messages from any other identity are dropped.
  • Reduced default scope on remote channels. Financial mutation operations are excluded from the default capability scope granted to a paired channel and require explicit opt-in, so a compromised channel cannot move money.
  • Outbound redaction. Credential-shaped values are stripped from every message the agent sends out over a channel before it leaves the device.
  • Scoped, signed mandates for agent-to-agent. An agent-to-agent negotiation is bounded by a user-defined mandate enforced in code (counterparties, topics, time window, duration), every message is cryptographically signed and verified, and an unsolicited first contact is held for explicit human approval before the agent will respond.

These safeguards reduce, but do not eliminate, the risks described in this Section. They are disclosed here as evidence of the Software's safety-by-design; they are not a warranty, and the user's responsibilities under Sections 4 and 8 are unchanged.

5.9 Recording of Calls, Captured Meetings, and Imported Recordings

The Software can record video and audio calls, capture meetings held in third-party conferencing applications, and import recordings produced elsewhere (Section 2.3). Every such recording, and every transcript, summary, and search index derived from it, contains the voice — and on video calls, the image — and the spoken words of the other participants, who are third parties not party to these Terms.

(a) Where this data lives. Recording, transcription, summarization, and indexing run on the user's device (or, for server-side call recording, on a media server the user operates). Nothing is transmitted to the Company. The user is the controller of this third-party personal data under the GDPR, the LGPD, and equivalent laws, with all obligations that role carries. Where the user records conversations in a professional or business context, personal-use exemptions of data-protection law will generally not apply.

(b) Participant consent is the user's responsibility. The laws governing the recording of conversations differ by jurisdiction and are determined by the location of every participant, not only the user's. Many jurisdictions require the consent of all participants before a conversation may be recorded or transcribed; in some, recording without consent is a criminal offense. Consent to be recorded does not automatically extend to transcription, AI analysis, indexing, or storage; where the applicable law distinguishes these, the user is responsible for covering each of them. The user is solely responsible for identifying the applicable law and for obtaining any consent or providing any notice it requires, before recording, capturing, or importing.

(c) What the Software does and does not do. Before the first recording, capture, or import on an install, the Software requires the user to acknowledge this responsibility in a dedicated in-app notice; recording, capture, and import are not available until that acknowledgment is given. While a call is recorded or a meeting is captured, the Software displays, by default, a persistent recording indicator on the user's device; after giving the acknowledgment described in this subsection, the user may turn this indicator off in the Software's settings. During a meeting captured from a third-party conferencing application, the Software gives no notice of any kind to the other participants — it records the audio the device already plays and captures. Informing the other participants is solely and entirely the user's obligation.

The acknowledgment notice and the recording indicator are awareness aids for the user only. They are visible solely on the user's own device, are not notice to or consent from any participant, are not legal advice, and do not satisfy any notice or consent obligation that applicable law places on the user. They do not transfer to the Company any part of the responsibility described in subsection (b), whether the indicator is on or off.

(d) No biometric identification. The Software transcribes speech to text; it does not create voiceprints, speaker-identification templates, or any other biometric identifier from recordings. The Company will not add such processing without updating these Terms.

(e) Retention and deletion. Recordings, transcripts, and derived data are retained locally until the user deletes them. Requests from recorded participants to access or delete their data are directed at the user as controller; the Company holds no copy and cannot act on them.


6. Data and Privacy

6.1 Locally Processed Data

The Software stores all user data locally, in the following directories:

  • macOS: ~/Library/Application Support/com.runmyai.desktop/
  • Windows: %APPDATA%\com.runmyai.desktop\

The user's primary data store is the local database file runmyai.db inside that directory. This database holds every store the Software writes locally: mail bodies and credentials, financial extractions, MyAI training pairs, MyChat conversation history, vector embeddings, and local diagnostic data.

The entire runmyai.db file is encrypted at rest with AES-256 via SQLCipher v4 (page-level AES-256-CBC, HMAC-SHA512, PBKDF2-HMAC-SHA512 key derivation with 256,000 iterations). The 256-bit master key is generated on first launch via a cryptographically secure random number generator and stored in a key file in the application's local data directory, protected by operating-system file permissions. The Company never receives the key and has no mechanism to decrypt the user's data. See Section 5.7 for the consequences of losing the key file.

Call and meeting recordings are stored as individual files outside runmyai.db, in a subdirectory of the same application data directory, and are encrypted at rest with AES-256-GCM under a key derived from the same master key that protects the database. A recording is decrypted only transiently, for playback or processing; the transient copies are removed when no longer needed and at every application start. Recordings made by versions of the Software that predate this encryption are migrated to the encrypted form automatically. The transcripts, AI summaries, and search indexes derived from recordings are stored inside the encrypted database. Deleting a recording removes the media file and its derived data. When the user operates their own media server (Sections 2.3 and 5.9), server-side call recordings are stored on that server's disk, under retention and access controls the user administers.

This data is NOT transmitted to RunMyAI, except as described in Section 6.2; when the user explicitly submits a bug report, as described in Section 6.6; or as the automatic, anonymous ModelIndex performance contribution described in Section 6.9.

6.2 Data Transmitted to Third Parties

When using the Software, the following data may be transmitted to third-party services:

(a) Sites and services accessed by the agent Web content accessed by the agent is returned to the local LLM context. The user's IP address and browser fingerprint are transmitted to the servers of those sites (see Section 3).

(b) Messaging platforms used to control the agent When the user pairs a messaging channel, the message content the user sends to the agent and the agent's replies transit the infrastructure of that platform (for example, Telegram's Bot API servers, or Meta's servers for WhatsApp). For iMessage, replies are sent through the user's own Messages application. This traffic flows under the platform's own terms and privacy policy; it does not pass through RunMyAI servers.

(c) Recipients of agent communications Email sent by the agent and Agent-to-Agent messages are delivered to their recipients through the user's own mail provider and the recipient's mail provider. They do not pass through RunMyAI servers. Such outbound agent communications carry the AI-disclosure mark described in Section 4.5.

(d) Call signaling through the user's mail provider When the user initiates or answers a call (Section 2.3), the connection metadata — a structured call invitation and answer carrying network addresses and encryption public keys, never call content — travels as email through the user's and the contact's mail providers, under those providers' own terms and privacy policies. In addition, every email sent from the built-in mail client carries a short machine-readable header that marks the sending installation as able to receive calls; recipients and mail providers can therefore technically observe that the user runs the Software. Call media itself never transits the mail provider: it flows directly between the devices or through the user's own media server (Section 5.9).

6.3 Telemetry, Analytics, and Service Connections

RunMyAI Desktop collects no telemetry about the user's content or activity: no analytics of what the user does, no automatic crash reports, no keystroke or interaction tracking, and nothing that identifies the user. Only two kinds of data about the user's system leave the device for RunMyAI, and neither carries the user's identity, content, or stored IP address:

  • an automatic, anonymous ModelIndex performance contribution (Section 6.9), which reports how models ran on the hardware, never what the user did with them; and
  • a bug report the user chooses to send (Section 6.6), which is user-initiated and shown in full for review before it leaves the device.

(a) Service connections. In addition to those two data flows, the Software makes a small set of content-free service connections to Company-operated infrastructure. They exist to keep the Software working — updates, licensing, model delivery — and none of them transmits user content, activity, or any telemetry about the user:

  1. Update check and download. The Software periodically (at launch and approximately every six hours) asks the Company's update endpoint whether a newer version exists. The request carries the operating system, CPU architecture, and installed app version — nothing else. When an update exists, the Software downloads it from the same infrastructure and cryptographically verifies its signature before applying it.
  2. License activation and refresh. A paid license is validated by sending the license token — a value that identifies the purchase, not the user's content — to the Company's license endpoint at activation and periodically thereafter to renew it. No usage data accompanies the token.
  3. Subscription management. When the user opens Manage Subscription, requests authenticated by the license token are sent to the Company's subscription endpoint; payment itself is processed by the payment provider under its own terms.
  4. Release notes. Opening the in-app release notes fetches the public changelog from the Company's endpoint; the request carries no payload.
  5. Model catalog and downloads. Downloading a model or runtime component fetches files from the Company's model repository or from the source model hub; the request identifies the file being fetched, not the user.

As with any internet request, the user's IP address is technically visible to the receiving server at the network level. The Company does not use these connections to identify, track, or profile the user.

The bug report is always:

  • Per-report opt-in — there is no global "share telemetry" toggle and no silent background transmission of any kind.
  • Previewed in full before sending — the user sees every field that will be transmitted, in a mandatory preview dialog, and must explicitly confirm before the report leaves the device.
  • Cancellable at any point before the user clicks Send, with no residual transmission.
  • Limited to a fixed allow-list of technical fields (app version, operating system, error code, library stack frames, timing metrics, and a short abstract summary generated by the local on-device AI).

The Company will not introduce any form of passive or automatic data collection in the Software without first updating these Terms and obtaining the user's renewed consent.

6.4 Data Retention and Deletion

All local user data may be deleted at any time via Settings > Data > Delete All Data. The Company does not hold a copy of this data, with the sole exception of bug reports the user has explicitly submitted under Section 6.6, which are retained under the policy defined in that Section and may be deleted by the user at any time via the User Hub > Support tab.

6.5 Age Restriction

The Software is not intended for persons under 18 (eighteen) years of age. By accepting these Terms, the user declares they are 18 years of age or older.

6.6 Bug Reports

The bug report described in this Section is user-initiated and per-report: nothing is transmitted unless the user opens "Report a bug", reviews the exact payload, and sends it. The Software never sends a report automatically, in the background, or at any autonomy level.

When the user explicitly chooses to submit a bug report via the in-app "Report a bug" function, a limited amount of structured diagnostic data is transmitted to RunMyAI servers for the sole purpose of investigating and fixing the reported issue. This is one of only two kinds of data that reach RunMyAI — the other being the automatic, anonymous ModelIndex contribution (Section 6.9). The bug report itself is always initiated by the user, never automatically and never in the background.

(a) What is transmitted The payload is built from a fixed allow-list of technical fields: app version, operating system and architecture, error code, stack trace frames from system libraries, timing metrics, and an abstract summary generated locally by the Software's on-device AI describing the nature of the problem. Optionally, if the user explicitly opts in, the payload may also include a free-text description written by the user. Before any transmission, the Software displays the complete payload to the user in a preview dialog; no data is sent until the user clicks Send.

(b) What is never transmitted Bug reports do not include and will never include: message contents (iMessage, Telegram, email, or any other communication), file contents from the user's filesystem, LLM prompts or completions from the user's normal use of the Software, credentials, API keys, tokens, keystrokes, session recordings, screenshots or any binary attachment, or any form of browsing or location history.

(c) Identity and authenticity A bug report is transmitted as a cryptographically signed message sent from the user's own email account to RunMyAI's support address, over the user's existing mail provider (the transport described in Section 6.2(c)). Because the report travels over the user's own email, the sending email address is visible to the Company, as it is for any email the user sends; a bug report is therefore not anonymous. The report is signed by a self-generated key pair (the local "Agent Passport") that the Company does not issue and cannot forge, which authenticates the sender without any central identity server. A report may include the user's subscription plan tier, for prioritization, but never the user's name, phone number, payment details, or any identifier beyond the sending email address and the allow-listed technical fields in (a).

(d) Storage A submitted report is received and held only within RunMyAI's own instance of the Software (its RunMyAI/MyProject application), operated by the Company on its own systems. No third-party managed database, object store, or support-desk service holds the report. The diagnostic content (the fields in (a)) is stored as a project record on that instance; no separate cloud database or third-party processor has access to it. Reports are text-only; the Software does not transmit screenshots or binary attachments.

(e) Retention A submitted report is retained only as long as needed to investigate and resolve the reported issue and to prevent its recurrence. The user may request erasure of any report at any time (see (f)); on such a request the Company removes the corresponding record from its instance. The Company will not retain reports for any purpose, or for any period, beyond what this Section permits without updating these Terms and obtaining the user's renewed consent.

(f) User rights At any time, the user may:

  • View every bug report ever submitted from their device, along with the exact content of each report, via the User Hub > Support tab;
  • Delete any individual report via the same interface, which removes the local record and signs and transmits an erasure request to the Company's instance so that the corresponding record is removed there as well.

(g) No secondary use Bug reports are used exclusively for diagnosing and fixing defects in the Software. They are not used for analytics, product research, marketing, machine learning training, profiling, advertising, or any purpose other than resolving the reported issue. They are not shared with or sold to any third party.

(h) Legal basis The processing of this data is based on the user's explicit, per-report consent given at the moment of submission. Withholding consent (by not clicking Send, or by cancelling the dialog) has no consequence for the user's ability to use the rest of the Software.

(i) Technical architecture reference The full technical specification of the bug report program — including the local data pipeline, allow-list composition, the role of the on-device AI in producing the abstract summary, the signed agent-to-agent transport over the user's own email, and the failure modes of the automatic layers — is maintained in the Company's technical architecture documentation. That specification is subject to the same independent legal review as this Section before any commercial launch.

6.7 Password-Protected Export and Import

The Software offers a password-protected Export and Import flow as the only sanctioned mechanism for moving data between installs, or for keeping a backup that survives loss of the key file (see Section 5.7).

(a) Export The user initiates the export and chooses a password. The Software writes a single file (default extension .runmyai-export) containing the entire local database re-keyed under a fresh PBKDF2-HMAC-SHA512 derivation (256,000 iterations) of that password. The file is independent of the originating install's key file and may be imported on any other install of the Software.

(b) Import Import is replace-only, not merge: importing replaces the current live database. Before replacement, the Software rotates the current file to a one-time safety copy retained for 24 (twenty-four) hours, after which it is automatically deleted.

(c) Password constraints The export password must be between 12 (twelve) and 256 (two hundred and fifty-six) characters. Single quotes and ASCII control characters are not permitted. A wrong password at import time produces an explicit "wrong password" outcome, distinct from a "file corrupted" outcome.

(d) User responsibility The user is solely responsible for (i) choosing a strong password, (ii) storing the password securely outside the Software, and (iii) storing the exported file securely. The Company does not store, retain, or escrow the password or the file, and cannot recover either if lost. The export file contains the same data protected under Section 6.1; the user should treat it with the same care.

(e) No transmission Export and Import are local operations only. The exported file does not pass through the Company's servers at any point.

6.8 No Monitoring and No Duty to Monitor

The Software runs entirely on the user's machine. There is no user account, no login, and no server-side record of the user's activity (the only data that ever reaches the Company is an automatic anonymous ModelIndex performance report (Section 6.9), which carries no identity or content, a bug report the user chooses to send (Section 6.6), and the content-free service connections described in Section 6.3(a)). As a direct consequence of this privacy-first, local-only architecture:

  • The Company has no ability to observe, inspect, monitor, log, or audit what the user does with the Software, what the agent is instructed to do, or what data the agent processes or transmits.
  • The Company has no technical means to detect a prohibited use (Section 8.2) before, during, or after it occurs, and no remote "kill switch" over an individual install.
  • The Company therefore assumes no duty to monitor, screen, review, or police any user's use of the Software, and the absence of monitoring is a deliberate privacy feature, not a deficiency.

This allocation of responsibility — full local control and privacy for the user, full responsibility for use resting with the user — is fundamental to these Terms.

6.9 ModelIndex Contribution (Anonymous Performance Data)

The ModelIndex is a community feature: your installation contributes anonymous performance measurements, and that shared data is what powers the hardware-matched model recommendations you receive in return. The contribution is anonymous — it carries no per-device identifier, so no report can be linked to another or to a person — and it is made automatically, the same way for everyone, with no regional distinction.

There are now millions of local AI models and quantizations, and the question every user faces — "which one actually runs well on my hardware?" — cannot be answered by synthetic, data-center benchmarks. The RunMyAI ModelIndex answers it: an aggregate, community index measured on real consumer hardware, which exists only because every installation contributes. Participation is part of how the Software works rather than a per-use export — the Software sends an anonymous performance report, and in return every user benefits from the resulting recommendations. By accepting these Terms and using the Software, the user agrees to this automatic, anonymous contribution. A user who does not agree should not install, purchase, or use the Software (Section 1). The report is transmitted to the Company, but it carries no identity, no content, and nothing that reveals what the user did (subsections (a)–(c)).

(a) What is transmitted A fixed allow-list of non-identifying technical measurements: the model name and quantization, a non-reversible hash of the hardware profile (CPU family, RAM tier, GPU type), tokens-per-second, time-to-first-token, the nucleus quality-gate pass rate, the distribution of task domains and execution strategies, the number of plans measured, model-pair metrics, and the subscription plan tier. Each report is signed with a single Ed25519 software-attestation key, which proves the report came from genuine RunMyAI software. This key is shared across all installations of a build, so it identifies the software, not the device or the user; the report contains no per-installation key and no other per-device identifier.

(b) What is never transmitted A ModelIndex report does not include and will never include: the user's name, email, phone, payment details, or IP address; conversation, message, or email content; prompts or model outputs; file contents or file paths; credentials, API keys, or tokens. It carries performance measurements and a hardware-class hash only.

(c) Anonymous, and on third-party infrastructure A report carries no identifier of the user: no name, email, account, license id, or IP address, and no content. Because the report contains no per-installation key and no other per-device identifier (subsection (a)), the Company cannot link one report to another or tie any contribution back to a device or an individual person, even in principle; reports are merged into an aggregate index across all installations. Reports are sent to a cloud aggregation service operated by the Company on third-party infrastructure (for example, managed hosting and database providers), where the anonymous report is processed to compute the public index. The user's IP address is visible to the receiving service at the network level, as with any internet request, and is not stored as part of the report.

(d) Purpose and no secondary use Contributed data is used solely to compute and publish the aggregate ModelIndex (rankings by model, hardware tier, quantization, model pair, and task domain) and to power in-product recommendations. It is not sold, not used for advertising or profiling, and not used to train machine-learning models, and it is never tied back to an individual user.

(e) Legal basis The report is designed to be anonymous: it carries no per-device identifier, so a single contribution cannot be singled out and the data is not personal data under the GDPR, UK GDPR, or LGPD. On that basis the contribution is automatic for everyone, with no regional distinction. To the extent any applicable law nonetheless treats a transmitted element as personal data, the Company relies on its legitimate interest (GDPR Article 6(1)(f) and equivalents) in maintaining the community ModelIndex, together with the user's acceptance of these Terms; the user's interests are protected because the data is anonymous, aggregated, allow-listed, and never used for advertising, profiling, or model training (subsection (d)). Where applicable law grants rights over any transmitted element, the Company will honor them.

(f) Changes The Company will not expand what a ModelIndex report contains beyond the allow-list in (a) without updating these Terms.


7. Limitation of Liability

7.1 Disclaimer of Warranties

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SOFTWARE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, CONTINUOUS AVAILABILITY, OR FREEDOM FROM ERRORS.

7.2 Disclaimer of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, RUNMYAI SHALL NOT BE LIABLE FOR:

  • Direct, indirect, incidental, special, punitive, or consequential damages
  • Loss of data, profits, revenue, goodwill, or business opportunity
  • Business or activity interruption
  • Actions executed by the agent that cause harm to third parties
  • Violations of third-party platform Terms of Service resulting from agent use
  • Exposure of the user's IP address or digital identity resulting from the agent conducting searches and browsing from the user's machine
  • Decisions made by the user based on agent outputs without independent verification
  • Damages caused by prompt injection or manipulation of the agent by third-party content
  • Recording, capture, transcription, AI analysis, or import of conversations performed by the user without the participant consent or notice that applicable law requires, including where the user has turned off the on-device recording indicator (Section 5.9)

THESE LIMITATIONS APPLY EVEN IF RUNMYAI HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND REGARDLESS OF THE LEGAL THEORY APPLIED (CONTRACT, TORT, ETC.).

7.3 Liability Cap

The Company's total and aggregate liability, under any circumstances, is limited to the greater of (a) the amount paid by the user for the Software in the 12 (twelve) months preceding the event giving rise to the claim, and (b) USD 100.00 (one hundred US dollars).

7.4 Legal Exceptions

Some jurisdictions do not permit the exclusion or limitation of certain warranties or liabilities, including liability for fraud or gross negligence, or non-waivable consumer rights. In those jurisdictions, the exclusions and limitations above apply to the maximum extent permitted by law. Nothing in these Terms excludes or limits rights that cannot be excluded by mandatory applicable law.

7.5 Indemnification by the User

To the maximum extent permitted by applicable law, the user agrees to indemnify, defend, and hold harmless the Company and its founders, officers, directors, employees, contractors, and agents from and against any and all third-party claims, demands, actions, proceedings, liabilities, damages, losses, fines, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) the user's use of or access to the Software; (b) any action the agent executed that the user authorized, whether explicitly or through the user's autonomy configuration, including actions affecting third parties or external systems; (c) the user's violation of these Terms or of any applicable law or regulation; (d) the user's infringement or misappropriation of any third party's rights, including intellectual-property, privacy, publicity, or data-protection rights; (e) any content, data, or instruction the user provided to or processed through the Software; and (f) any recording, capture, transcription, AI analysis, or import of a conversation the user performed, including claims by recorded participants or by authorities arising from the user's failure to obtain any consent or give any notice required by applicable law (Section 5.9).

This indemnity does not apply to the extent a claim arises from the Company's own fraud, gross negligence, or willful misconduct, or to any liability that mandatory applicable law does not permit to be allocated to the user (including non-waivable consumer protections). The Company will give the user reasonable notice of any claim subject to this Section and may, at its option, participate in the defense with its own counsel.

7.6 Time Limitation on Claims

To the maximum extent permitted by applicable law, any claim or cause of action arising out of or related to the Software or these Terms must be commenced within one (1) year after the claim or cause of action first arose; otherwise it is permanently barred. Where applicable law does not permit this shortened period, the shortest limitation period that law does permit applies instead.


8. Compliance with Applicable Law

8.1 User Responsibility

The user is solely responsible for ensuring their use of the Software complies with all applicable laws in their jurisdiction, including but not limited to:

  • Personal data protection laws (e.g., GDPR — European Union, LGPD — Brazil, CCPA/CPRA — California/US, PIPL — China)
  • Computer access and cybercrime laws (e.g., CFAA — US, Budapest Convention, Lei 12.737/2012 — Brazil)
  • Intellectual property and copyright law, including protections over web-scraped content
  • Sector-specific regulations applicable to the user's activities (financial services, healthcare, legal, government, etc.)
  • Terms of Service of third-party platforms and services with which the agent interacts

Messaging-channel platforms. The Software can connect to Telegram, iMessage, WhatsApp, Slack, Discord, and Signal so the user can drive their own agent. These connections run under the user's own accounts (a Telegram bot token the user creates, the user's Apple ID for iMessage, a linked-device session for WhatsApp, and so on). Several of these platforms restrict or prohibit automated access, unofficial clients, or bot-mediated use in their own terms. The user is solely responsible for confirming that connecting and using each channel is permitted by that platform's current terms, and assumes the risk of any account restriction or termination the platform may impose.

8.2 Prohibited Use

Use of the Software for the following purposes is expressly prohibited and constitutes grounds for immediate termination of access, without prejudice to applicable civil and criminal liability:

  • Collecting, processing, or using third-party personal data without an adequate legal basis
  • Recording, capturing, transcribing, or importing a conversation without the participant consent or notice that applicable law requires (see Section 5.9)
  • Unauthorized access to third-party computer systems
  • Scraping content in violation of Terms of Service or applicable law
  • Generating illegal, defamatory, deceptive, or rights-infringing content
  • Any activity that causes harm to third parties or constitutes a crime in any relevant jurisdiction
  • Trading in, facilitating, or arranging illegal goods or services (including controlled substances, weapons, stolen data or credentials, or counterfeit goods)
  • Fraud, scams, phishing, social engineering, or impersonation of any person or entity
  • Generating or distributing child sexual abuse material, or any content that sexualizes minors
  • Harassment, stalking, doxxing, threats, or coordinated intimidation of any person
  • Sending unsolicited bulk or automated messages (spam) over any channel, or operating messaging, email, or platform accounts in a manner that violates the platform's terms
  • Market manipulation, money laundering, or evasion of taxes, sanctions, or export controls
  • Generating or amplifying disinformation, or operating undisclosed automated identities ("bots") where disclosure is required
  • Using the Software's local, anonymous operation to conceal, organize, or carry out any of the foregoing, or to evade lawful process

The user acknowledges that, because the Software runs locally with no account and no server-side visibility into the user's activity (Section 6.8), the Company has no technical means to detect or prevent a prohibited use in advance. This list defines the contractual boundary of permitted use; it is not, and cannot be, a monitored or enforced control. Responsibility for staying within it rests entirely with the user.

8.3 EU AI Act

For users in the European Union: the Software qualifies as a general-purpose AI system, and the agent interacts directly with natural persons and produces AI-generated content. The transparency obligations under Article 50 of the EU AI Act take full effect on 2 August 2026.

The Software addresses the Article 50 transparency duty for the communications it controls by marking autonomous agent messages to third parties as AI-generated, as described in Section 4.5. The Company commits to keeping these Terms and the Software's disclosure behavior updated in accordance with the EU AI Act implementation schedule. Where the user directs the agent to act through a surface the Software cannot mark, the disclosure obligation for that interaction rests with the user (Section 4.5).


9. Jurisdiction and Dispute Resolution

9.1 Informal Resolution First

Before commencing arbitration, a party must first try to resolve the dispute informally by sending written notice of the dispute to the other party (to the Company at legal@runmyai.app). The parties will negotiate in good faith for 30 (thirty) days from that notice. Only if the dispute is not resolved within that period may it proceed to arbitration.

9.2 Binding International Arbitration

Any dispute, controversy, or claim arising out of or relating to these Terms or the Software — including its existence, validity, breach, or termination — that is not resolved under Section 9.1 shall be finally settled by individual and binding arbitration under the Rules of Arbitration of the International Chamber of Commerce (ICC). The seat of arbitration is Geneva, Switzerland; the language is English; and the tribunal consists of a sole arbitrator unless the ICC determines otherwise. The award is final and binding, and judgment on it may be entered in any court of competent jurisdiction (the New York Convention applies). Nothing in this Section prevents either party from seeking interim or injunctive relief from a competent court where necessary to preserve rights pending arbitration.

9.3 Class Action Waiver

To the maximum extent permitted by applicable law, all disputes are conducted on an individual basis only, and the user waives any right to participate in a class, collective, consolidated, or representative action against the Company. This waiver applies to the fullest extent the law allows; where mandatory law (for example, in Brazil or in European Union member states) does not permit it, this Section does not deprive the user of any non-waivable right to collective redress that such law guarantees, and the remainder of this Section 9 continues to apply.

9.4 Governing Law

These Terms, and any dispute arising out of or relating to them or the Software, are governed by the substantive laws of Switzerland, without regard to its conflict-of-law principles and excluding the United Nations Convention on Contracts for the International Sale of Goods. Mandatory rights guaranteed to a consumer by the law of the consumer's country of habitual residence — including non-waivable consumer protections under the Brazilian Consumer Defense Code, EU Directive 2019/770, or equivalent legislation — are not affected by this clause and prevail to the extent applicable; this choice of law does not deprive a consumer of the protection afforded by provisions that cannot be derogated from by agreement under the law of their country of habitual residence.


10. Term, Termination, and General Provisions

10.1 Term

These Terms take effect upon acceptance by the user and remain in force until the user uninstalls the Software or the Company discontinues the product, whichever occurs first.

10.2 Termination by User

The user may terminate these Terms at any time by uninstalling the Software. No automatic refund is issued for interrupted use (see separate refund policy). Uninstallation removes all local data; the Company holds no copy of that data.

10.3 Termination by Company

Because the Software is locally operated with no user account and no server-side service the Company can revoke (Section 6.8), the Company has no remote means to disable an individual installation. In the event of a breach of these Terms, the Company may withdraw the user's right to use the Software and may decline to provide updates, support, or future licenses; the user is then contractually obligated to cease use and uninstall. Nothing in this Section limits the remedies available to the Company or to affected third parties under applicable law for a breach or an unlawful use.

10.4 Updates to These Terms

The Company may update these Terms periodically. Material updates will be communicated to users through:

  • An in-app notification upon opening the Software
  • Email to the registered address (where applicable)

Material updates require a new explicit user acceptance before the Software may be used. Users who do not agree with updates must uninstall the Software.

Best practice note: The Company will maintain a public version history of these Terms, with the effective date of each version, accessible at: runmyai.app/legal

10.5 Severability

If any provision of these Terms is held invalid, illegal, or unenforceable by a court, tribunal, or authority of competent jurisdiction, that provision is severed or limited to the minimum extent necessary, and the remaining provisions remain in full force and effect.

10.6 Survival

Any provision that by its nature should survive termination or expiry of these Terms survives, including (without limitation) the attribution rule in Section 3 and Sections 4, 5, 6, 7 (disclaimers, limitation of liability, indemnification, and time limitation), 8, 9, and this Section 10.

10.7 Entire Agreement; No Reliance

These Terms, together with any separate refund policy and any policy expressly referenced herein, constitute the entire agreement between the user and the Company regarding the Software and supersede all prior or contemporaneous agreements, understandings, communications, marketing materials, and representations on that subject. The user acknowledges that they have not relied on any statement, promise, or representation not expressly set out in these Terms.

10.8 Force Majeure

The Company is not liable for any failure or delay in performance resulting from causes beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, epidemic, labor disputes, governmental action, sanctions, or network, power, or third-party-service failures or discontinuations on which the Software depends (Section 5.5).

10.9 No Waiver

The Company's failure or delay in enforcing any provision of these Terms is not a waiver of its right to enforce that or any other provision later. A waiver is effective only if made in writing by an authorized representative of the Company.

10.10 Assignment

The Company may assign or transfer these Terms, in whole or in part, including in connection with a merger, acquisition, financing, reorganization, or sale of assets, without the user's consent. The user may not assign or transfer these Terms or any rights or obligations under them without the Company's prior written consent; any attempted assignment in breach of this Section is void. These Terms bind and benefit the parties and their permitted successors and assigns.

10.11 No Agency or Partnership

Nothing in these Terms creates any agency, partnership, joint venture, franchise, employment, or fiduciary relationship between the user and the Company. The user has no authority to bind the Company in any way.

10.12 Capacity and Authority

By accepting these Terms, the user represents and warrants that they have the legal capacity to enter into them and, where they accept on behalf of an organization, that they are duly authorized to bind that organization, which is then equally bound as the "user".

10.13 Controlling Language

These Terms are authored in English (the controlling master version) and may be made available in other languages for convenience. In case of any conflict or discrepancy, the English version prevails to the maximum extent permitted by applicable law; where mandatory local law requires the local-language version to govern for a consumer, that requirement prevails for that consumer.


11. Acceptance and Consent Mechanism

11.1 In-App Acceptance Mechanism (Product Team Specification)

Acceptance must be obtained in 3 sequential steps at first use of the Software:

Step 1 — Risk Summary (plain language)

Display a screen with the 6 critical risks in short bullet points:

  1. Internet searches run from your machine, using your real IP address.
  2. The agent can act autonomously at Levels 3 and 4. You configure the level per product and per surface; you assume full responsibility for what runs.
  3. AI outputs may be wrong — always verify before acting.
  4. Malicious web content may attempt to manipulate the agent (prompt injection).
  5. Your local data is encrypted with a key held in a key file on your computer. If you lose that file (OS reinstall, account loss, format) without first creating a password-protected Export, the data is permanently unrecoverable.
  6. RunMyAI contributes anonymous performance measurements (model and hardware only — never your content or identity) to the community ModelIndex (Section 6.9); this is automatic for everyone, and the report carries no per-device identifier.

Button: "I understand the risks — view full Terms"

Step 2 — Full Terms With Checkboxes

  • Mandatory scroll to end of document
  • Checkbox 1: "I have read and fully understand the Terms of Use and Risk Acceptance"
  • Checkbox 2 (separate and required): "I understand that web searches and browsing performed by the agent occur from my machine using my real IP address, and that such traffic is attributable to me in relation to third parties"
  • Checkbox 3 (separate): "I confirm that I am 18 years of age or older"
  • Button enabled only after full scroll and all checkboxes checked

Step 3 — Initial Autonomy Configuration

Before any agent execution, the Software presents the five autonomy levels (Section 4.1) with plain-language descriptions and confirms that every product and every surface is set to Level 0 (Manual) by default. The Software does not recommend a specific level to new users. The user may keep the defaults or raise individual products/surfaces consciously.

11.2 Feature Availability at Higher Autonomy Levels

All features of the Software are available to the user immediately after the general acceptance (Section 11.1) is obtained. The Software does not gate specific features (for example, autonomous email sending, autonomous financial transactions, autonomous account creation on third-party services) behind additional acceptance steps.

Two point-of-use acknowledgments are the exception, because each opens a specific scope of third-party personal data: the iMessage third-party-data acknowledgment (Section 5.6) and the recording acknowledgment (Section 5.9). Each is shown once, at the moment the user first engages that scope, and records the user's acknowledgment of the responsibility described in the corresponding Section.

When the user raises the autonomy level of a product or surface to Level 3 or Level 4 for the first time, the Software may display a one-time plain-language summary of what that level will now execute autonomously (for example: "At Level 4 in MyMail, emails will be sent without asking"). This disclosure is informational only; it does not require a second acceptance and does not gate the configuration change. The user's general acceptance under Section 11.1, combined with the conscious per-product per-surface autonomy configuration, covers all feature use.