Msty Go is provided by CloudStack, LLC (“Msty,” “we,” “us,” or “our”). This policy explains how Msty Go handles data in the Msty Go desktop app and mobile controller, including local AI, remote control, cloud sync, notifications, and optional cloud AI features.
Desktop and Mobile Roles
Msty Go has two main product surfaces:
- Msty Go desktop app is the primary workspace. It runs chats, agents, tools, workspace context, local files, model/provider configuration, local model workflows, artifacts, and connected desktop work.
- Msty Go mobile app is primarily a controller for the paired desktop app. It can send prompts, commands, approvals, attachments, speech-derived text, and review actions to the desktop, and it can receive status, results, and notifications from the desktop.
- Mobile local features, where available, may run or store selected activity on the mobile device. Otherwise, mobile-origin work is generally routed to the paired desktop for processing.
Data We Handle
Account and sign-in data
Account sign-in is not required to pair the mobile controller with the desktop app. If you sign in or use cloud features, we may process your email address, name, authentication provider identifier, account ID, session tokens, and related account metadata.
Device and pairing data
To pair and connect the mobile controller with the desktop app, we process device names, install identifiers, device IDs, public encryption keys, pairing codes, hashed tokens, connection status, timestamps, and push notification tokens.
Desktop app content
In the desktop app, Msty Go may process prompts, conversation history, agent instructions, selected workspace context, tool results, attachments, images, documents, extracted text, generated artifacts, and review notes.
Desktop app content is stored and processed locally on the desktop. If you enable cloud sync, use remote-control routing, or configure the desktop to use a cloud AI provider or other third-party service, selected content may be transmitted only as needed to provide the feature you requested.
Mobile controller content
In the mobile app, Msty Go may process prompts, commands, approvals, review notes, selected attachments, captured media, documents, speech-derived text, and the desktop state needed to control or review work on the paired desktop.
Mobile-origin content is generally sent to the paired desktop so the desktop app can perform the requested chat, agent, or workspace action. If a cloud relay is used, device-to-device communication is end-to-end encrypted, and the relay is designed to pass encrypted traffic without reading or storing chat content.
Mobile local content
If you use a mobile feature that runs locally on the mobile device, related chats, attachments, model state, or cached data may be stored and processed on that device unless you choose to send the content to a paired desktop or a third-party AI provider.
AI provider request data
When the desktop app uses a cloud AI provider, the desktop may send the prompt, recent conversation context needed for the request, selected attachments or extracted attachment text, relevant workspace/source snippets, tool outputs, model settings, and request metadata to the selected provider.
If a request starts in the mobile controller and is performed by the paired desktop, the desktop is the component that sends any permitted cloud AI request to the selected provider.
Supported or user-configured providers may include OpenAI, Anthropic, OpenRouter, xAI/Grok Cloud AI when enabled, OpenAI-compatible providers, Anthropic-compatible providers, or local providers such as Ollama or MLX.
Local model download data
If you download local models, the app may contact model hosting services such as Hugging Face or the listed model repository host. Those services may receive network metadata such as IP address, requested model files, and request time.
Camera, photos, documents, microphone, and speech
Msty Go only accesses camera, photos, documents, microphone, or speech features when you choose to use those features or grant system permission. Selected content may be attached to a chat. Speech input is used to create text for your message.
Notifications
If you enable notifications, Msty Go handles push tokens and minimal notification payloads needed to notify you when an agent needs attention or finishes work. Notifications are alerts only and are not used to transmit readable chat content, attachments, workspace content, commands, approvals, or generated artifacts.
Diagnostics and support
If you choose to share diagnostics, we may receive app version, device/OS details, connection status, logs, and error information. Diagnostic sharing is user-initiated and is not intended to include chat text.
How Data Is Handled
Msty AI does not collect or store your Msty Go prompts, commands, approvals, attachments, chat content, workspace content, local models, or generated artifacts. The events below describe when data is handled on your end devices, sent end-to-end encrypted between paired devices, relayed as encrypted traffic, or sent to a provider you select for a specific feature.
Data may be handled when you:
- Type prompts, issue commands, approve actions, or attach files.
- Pair the mobile controller with a desktop.
- Enable cloud sync, remote access, or notifications.
- Download local models.
- Sign in or manage trusted devices.
- Share diagnostics or contact support.
Some operational metadata may be generated to operate and secure transit, pairing, notification, and support features, such as timestamps, token hashes, rate limits, connection status, and server logs. This metadata is not a copy of your chat content, attachments, workspace content, or generated artifacts.
Third-Party AI Sharing
When you pair the mobile controller with the desktop app, Msty AI asks you to opt in and acknowledge that mobile control follows the paired desktop’s configuration. If the desktop is configured to use a third-party AI provider, actions you take from the mobile controller may cause prompts, selected context, attachments, or other request data to be routed by the desktop to that provider. Because the mobile app is primarily a controller, mobile-origin content is usually sent to the paired desktop first. If the desktop then needs a third-party AI provider to complete the request, the desktop sends the permitted request data to the selected provider.
When you opt in to mobile control under that desktop configuration, the following may be sent to the selected provider:
- Your prompt.
- Recent conversation history needed to answer.
- Selected attachments or extracted attachment text.
- Relevant workspace, source, or tool context.
- Model settings and request metadata.
The recipient is the provider selected or configured for the active agent. The app or desktop may identify the provider/model before sending where available.
We do not intentionally send account credentials, payment details, or unrelated device data to AI providers unless you include that information in your prompt, attachment, or selected context.
Third-party AI providers process data under their own terms and privacy policies. For vendors we select to process user data, we require protections consistent with this policy and applicable requirements. If you configure your own AI provider or endpoint, you are choosing that recipient, and that provider’s terms apply.
Service Providers
For Msty Go remote-control traffic, the service-provider role is limited to relay infrastructure. The relay may pass encrypted traffic between the mobile controller and paired desktop app, but device-to-device communication is end-to-end encrypted. The relay is not designed to read or store chat content, attachments, workspace content, commands, approvals, or generated artifacts.
Msty AI does not use service providers to store Msty Go user content. Other third-party services are contacted only when you choose a feature that requires them, such as a selected AI provider, model-host download, social sign-in provider, push notification delivery, or user-initiated diagnostics/support.
Third-party services process data under their own terms and privacy policies. AI providers receive content only when you select or permit that provider for the relevant request.
Retention
Msty AI does not store your chat content, prompts, commands, approvals, attachments, workspace content, local models, or generated artifacts.
Retention depends on the feature:
- Desktop chats, local models, attachments, artifacts, and caches remain on your desktop until you delete them, clear app data, or uninstall the app.
- Mobile controller data, local mobile chats where available, attachments, and caches remain on your mobile device until you delete them, clear app data, or uninstall the app.
- Mobile-origin chats and artifacts performed by the paired desktop remain on the desktop unless you delete them there.
- Pairing state, device records, push tokens, and remote-access metadata remain on end devices or are processed as limited operational metadata needed to keep devices paired, trusted, connected, or reachable for notifications.
- Cloud sync moves encrypted app data between approved end devices when enabled. Synced content remains on those end devices and is not stored by Msty AI.
- Relay messages are routed in real time as end-to-end encrypted traffic between paired devices and are not stored by the relay.
- Support diagnostics are retained only when you choose to send them to us, and only as needed to provide support and improve reliability.
- Limited legal, security, and abuse-prevention records may be retained as required or permitted by law.
Security
Msty Go uses safeguards designed to protect user data, including encrypted transport, end-to-end encrypted remote sessions between paired devices, hashed tokens, local encrypted cache storage, trusted-device controls, and relay routing limited to encrypted traffic.
No system can guarantee perfect security. You should avoid including sensitive information in prompts or attachments unless you want that information processed by the selected AI provider or tool.
Your Choices
You can:
- Use Local AI/on-device models where available.
- Decline or revoke permission for third-party AI sharing.
- Choose or change the AI provider configured on your desktop.
- Unpair the mobile controller from the desktop.
- Disable notifications.
- Delete local chats, attachments, local models, and cached data.
- Revoke trusted devices or reset sync where available.
- Request deletion of account-related data by contacting us.
Children
Msty Go is not directed to children under 13, and we do not knowingly collect personal data from children under 13.
Changes
We may update this policy as Msty Go changes. We will update the “Last updated” date when we make material changes.