Squillo
Get Squillo Consigue Squillo Obtenez Squillo

Privacy at Squillo

This page covers what Squillo cannot see by construction, what is collected, how long records live, and where the legal documents are. The privacy policy is the policy of record for the squillo.com website; this page describes what the architecture allows.

What we cannot see, by construction

The guarantee is architectural, not a promise. Squillo is built on four mechanisms.

Your content lives in storage you own. Your documents, vaults, and knowledge live in your own storage — your cloud drive, your device, your peers — not in a Squillo-hosted content store. API keys and vault contents stay local to your machine; Squillo's design does not exfiltrate them. Squillo is not the custodian of your data.

Access is deny-by-default. Every access in Squillo is an explicit grant on a permissioned ledger. No grant means no access, and that rule has no admin exception. Administering an organization is a separate permission from reading content. What organization administrators can and cannot see is published at what admins see.

Your agent never exceeds your authority. An agent acting for you can do at most the intersection of what it is allowed and what you are allowed. No agent, including an administrator's, can read what its human could not.

The control surface of your Squillo is local. The interface that drives your Squillo runs on your machine, reachable only locally and gated by a key held on your device. There is no cloud console into a running Squillo and no remote view of your screen or typing. Flows that cross machines — pairing a device, remote approval — require an explicit consent step.

Provenance, not surveillance

Squillo notarizes what agents do on people's behalf through APH — Agent-per-Human, an open protocol that stamps an agent's action with a verifiable credential binding it to the specific human it acted for. APH is attribution: when you or your agent act in a shared space, people who can already see the action can also see it was yours. It applies only to what is already visible in that space. It is not activity monitoring, and it does not create a new window into your work.

APH labels its own strength. A fully notarized action binds the human as a cryptographic principal. When only a weaker machine-authored stamp is available, it is labeled as the weaker claim.

The same machinery guards the sensors. When the camera is in use, a visible indicator lights in the OS. When an agent, rather than the person at the keyboard, reaches for a sensor, the access must carry a valid notarization and leaves a receipt in the audit log, or it is refused before the sensor is touched. Not every sensor leg is wired yet: today this gate is live for the camera on desktop; the desktop location leg and the microphone leg are designed but not yet wired.

What is collected

What reaches us, each with the place to verify it — and what does not.

  • What you hand us directly. If you create an account or email us, we receive what you send — contact details, the contents of your message. The privacy policy enumerates this.
  • What the website observes. squillo.com is an ordinary website: standard server logs and cookies, as described in the privacy policy. That policy — not this page — is the record for website data.
  • What organizations generate. An organization on Squillo produces a roster (names, emails, roles), organization-level billing and settlement events, and seat lifecycle status. These are visible to that organization's admins, and the full disclosure of that visibility lives at what admins see.
  • What an AI request carries. When you use AI features, the content you include in a request reaches the model that serves it. Which tools and models may be used, and where requests run, is controlled by policy that you — or your organization — set.
  • What never transits, by construction. Your vault contents, your API keys, and your personal vault activity stay in your storage and on your machine, per the mechanisms above.

A complete, independently audited census of every byte the product transmits does not exist yet. This page confines itself to the mechanisms above, each of which you can check. The compliance page tracks what is underway toward that formal evidence.

Retention

Retention follows ownership, so the answer depends on where a thing lives.

  • Content in your own storage is retained and deleted on your terms; it is in your cloud drive, on your disk, or on your peers. There is no Squillo-side copy.
  • Shared organization spaces are append-only. History in a shared vault is preserved, including its full edit history; it is designed never to be silently destroyed. Do not put something in a shared vault expecting to erase it later.
  • Records we hold about accounts and billing are governed by the privacy policy, which carries your access and erasure rights, including its GDPR and CCPA sections. For organizations, our data processing addendum additionally requires that personal information processed under it be returned or securely disposed of when the agreement ends.

A published retention schedule — fixed periods per class of record — does not exist yet. Until it does, the policy's rights and the DPA's obligations above are the retention commitments in force.

Where the rest lives

The privacy policy is the legal record for the website. What admins see is the full disclosure of admin visibility. The data processing addendum is the contractual form of the processing commitments. APH is the open provenance protocol in full. The security page carries the deeper mechanics this page relies on, and the compliance page carries our formal-evidence status, dated.

Questions

Can Squillo read my documents?

Your documents live in your storage, and your keys stay on your machine; Squillo's design gives us no copy to read. What does reach us is listed above: messages you send us, account and billing records, and organization-level events.

Can my organization's admins read my private vaults?

No. Private vaults are deny-by-default with no admin exception, and admin is not a reader role. The full disclosure is at what admins see.

Is my agent reporting on me?

Your agent acts with your authority and never more. APH stamps attribution in shared spaces, visible only to people who could already see the action. Sensor access by an agent is notarized and leaves an audit receipt, or is refused. None of this creates a channel that reports your activity to Squillo.

If I delete something, is it gone?

In your own storage: yes, on your terms. In a shared organization vault: no; shared history is append-only and preserved by design.

Does Squillo sell my data?

Your documents and vault contents never reach us; there is nothing of yours there to sell. For personal information we process for customers, the data processing addendum commits in writing that Squillo does not sell it or share it in the CCPA sense. For website data, the privacy policy is the record, including its CCPA and GDPR rights.

Why should I believe this page?

Every claim on this page names a mechanism you can verify. Where evidence is missing — an audited data inventory, a published retention schedule — the page says so. It carries the date we last verified it, and it sits beside what admins see, which follows the same discipline.

Last verified: 2026-09-16

Common questions

Is this page the privacy policy?

No — the policy is at /privacy. This page is the story behind it: what the design itself lets anyone see, before any policy applies.

What can my organization's admins see about me?

There is a full plain-language answer at /what-admins-see, written for members, not employers. In short: work you place in shared organization spaces is visible to the people with access to those spaces; your personal account, your private vaults, your screen, and your keys are not.

Can an agent see more than its person could?

No. What an agent may do is the intersection of what the agent is allowed and what its person is allowed — never the union, and never more than the person alone could do.

SquilloSquillo

Connect Anything. Automate Everything. Conecta cualquier cosa. Automatiza todo. Connectez tout. Automatisez tout.

Product Producto Produit

Get Squillo Consigue Squillo Obtenez Squillo For Enterprises Para empresas Pour les entreprises Book a Demo Reserva una demo Réserver une démo

Company Compañía Société

Careers Empleo Carrières Investor Relations Relación con inversores Relations investisseurs Press Prensa Presse

We're Hiring! ¡Estamos contratando! Nous recrutons !

Come join an innovative team that's snapping the world together. Únete a un equipo innovador que está uniendo el mundo, Snapp a Snapp. Rejoignez une équipe innovante qui assemble le monde, Snapp par Snapp.

See Openings Ver vacantes Voir les postes
Privacy Privacidad Confidentialité Terms Términos Conditions DPA DPA DPA Models Modelos Modèles Company Compañía Société Trust
Made with ❤️ in Indianapolis, IN Hecho con ❤️ en Indianápolis, IN Conçu avec ❤️ à Indianapolis, IN © 2021-26 Squillo Inc. All rights reserved © 2021-26 Squillo Inc. Todos los derechos reservados © 2021-26 Squillo Inc. Tous droits réservés