AGI One ← Home

Privacy

Last updated 2026-08-21

AGI One is the public product brand for the Hugging Monkey macOS application. The app can hear you, see your screen, and operate your computer. That is a lot of access, so here is exactly what happens to your data — no marketing language.

There is no Hugging Monkey application-data server. We do not receive your voice, screenshots, files, API keys, or activity inside the app. The app talks directly from your Mac to the AI providers you configure, using your own accounts. The website's download service records only the limited delivery metrics described below.

What stays on your Mac

What is transmitted while you use it

When you are actively talking to the assistant, this goes directly to the AI provider you configured, over TLS, authenticated with your own key:

DataSent toWhy
Your speech audio and transcriptOpenAI (Realtime API) To understand you and reply out loud
Screenshots of your screenAnthropic (Claude) To see the screen it is operating
Text of tasks you dispatchAnthropic / OpenAI To carry out the work
Front camera framesAnthropic (Claude) Only when you explicitly ask — see below
Android image and assistant output audioLemonSlice Only when you configure and enable the optional digital human — to render synchronized talking-avatar audio and video. Your microphone, screen, and task text are not sent on this path.
Generated digital-human audio/videoYour configured LiveKit Cloud project To return the synchronized digital-human stream to the app

Screenshots capture whatever is on screen at that moment, which may include things you did not intend to share — other apps, notifications, documents, credentials. Close or minimize anything sensitive before asking it to look at your screen.

Your relationship for that data is with the provider, under their terms: OpenAI · Anthropic · LemonSlice · LiveKit. We are not a party to those requests and cannot see, log, or retain them.

The camera

The front camera opens only when you ask for it out loud. This is not a policy we promise to follow — it is enforced in code, against the actual speech-recognition transcript of what you said. The language model cannot open the camera by deciding it would be helpful, and cannot bypass the check by claiming consent in its tool arguments. A second check in the backend refuses any camera capture that does not carry the marker issued by the first.

Both checks are enforced in code and covered by a regression test suite that runs before every release — the consent gate alone has 37 assertions, including "the model sets consent = true by itself" and "consent for the camera must not unlock deletion".

Camera frames are captured only for the moment needed to answer your question, sent to the vision provider to be described, and not retained.

Download delivery metrics

The app contains no analytics SDK, telemetry, crash reporting service, advertising identifier, license server, account system, or phone-home on launch. We cannot see how you use the app.

When you request a .dmg or .zip from our download domain, the delivery service records the requested artifact and version, timestamp, response status, bytes transferred, whether the response completed, coarse operating-system category, country, Cloudflare edge location, and referrer hostname. This lets us count the founding batch accurately and diagnose failed downloads.

We do not store the raw IP address or full user-agent string. They are converted immediately into a salted SHA-256 identifier used only to deduplicate downloads. Download records are retained for up to 30 days and are not sold, used for advertising, or joined with activity inside the app. Cloudflare necessarily processes network request data while delivering the file under its own privacy terms.

macOS permissions

macOS grants these per app and you can revoke any of them at any time in System Settings → Privacy & Security. Revoking one disables that capability; the rest keeps working.

Deleting your data

Everything the app stores is in one folder: ~/Library/Application Support/Hugging Monkey/. Delete it and nothing of yours remains, apart from files you explicitly asked the assistant to create elsewhere. Uninstalling is dragging the app to the Trash.

To remove data held by the AI providers, use their own account controls — we cannot do it for you, because we never had it.

Purchases

If you buy Hugging Monkey Pro, the checkout is operated by Polar as merchant of record. Polar processes your payment under its own privacy policy; we never see your card details. What we receive from Polar is order information — the email address you used and what you bought — which we use to deliver your download and provide support. This is the only order and account data we hold, and it exists only because you bought something; using the app itself sends us nothing.

Children

Hugging Monkey is not directed at children. We do not knowingly collect personal information from children; the download service retains only the limited delivery metrics described above.

Changes

Material changes will be noted here with a new date and in the release notes of the version that introduces them. Changes to this policy do not alter records collected under an earlier version of the policy.

Contact

[email protected]