Privacy Policy
Last updated: September 21, 2026
1. Scope and data controller
SECRETARY is a subscription service consisting of an AI work assistant installed on your Windows computer and a web panel used to manage it. This document is both a privacy policy and a privacy notice under Article 10 of Turkish Personal Data Protection Law No. 6698, known as KVKK. It explains which data is processed when you use the panel and desktop software, where and how long that data is stored, who receives it, and which rights you have.
The business providing the SECRETARY service is the data controller for your account data. For any question or request concerning personal data, contact us at: hi@secretary.sh
We consider a clear and auditable account of data flows a core responsibility. This document therefore explains separately which data is stored permanently and which content is retained only temporarily while an operation is in progress.
2. Where data is processed
- Your computer. Agent runs here, opens your files here, and writes generated reports here. WhatsApp and Telegram sessions, the browser profile, and website cookies remain here.
- Our server. Your account, task definitions, and run records are stored here. AI requests and connected application operations pass through this server.
- Our service providers. We use external providers for access to AI models, application connections, payments, email delivery, and hosting. Every provider is named in Section 13.
3. Data controller and processor roles
We are the data controller for your account data, including your identity, contact details, payment and usage records, computer information, and support correspondence.
The position is different for your business data. Documents, emails, calendar entries, WhatsApp and Telegram conversations, contact records, address book entries, and data collected from websites by Agent on your instructions belong to your business. The people in this data, including your customers, clients, patients, suppliers, and employees, have a relationship with you rather than with us. For this processing, you are the data controller and we act as the processor, solely on your behalf and according to your instructions. We do not use this data for our own purposes, sell it, or share it for advertising.
You are therefore responsible for having a valid legal basis under Articles 5 and 6 of KVKK, informing these people, obtaining explicit consent where required, responding to their requests, and sharing only data that is genuinely necessary when creating a task. If one of your contacts applies directly to us, we will forward the request to you and help you respond.
Special categories of personal data. Your documents and messages may contain health, biometric, religious, criminal conviction, or other sensitive data. We do not process this data for our own purposes. The service does not separately identify, classify, or protect it, so it follows the same paths as other business data. If you process such data with Agent, you are responsible for meeting Article 6 requirements under KVKK and applying any additional safeguards. We recommend excluding documents containing this data when it is not necessary.
4. Account and service data
Identity. You sign in with Google. We receive your name, email address, and basic profile information provided by Google, such as the profile image link. We request only profile and email permissions. We do not see your password, you have no password stored with us, and this sign-in does not give us access to your Gmail inbox. We also store the business name and language preference entered in the panel.
Contact details. You provide the WhatsApp number or Telegram chat ID used for notifications and, when both are connected, select your preferred channel.
Subscription and payment. We store your plan, subscription status, renewal date, payment and refund amounts and dates, and the order number from the payment provider. Your card details never pass through our systems. When you are sent to the payment page, your email address is added to the link and the incoming payment is matched to your account through that email address.
Computer information. For every computer where Agent is installed, we store the Windows computer name, your label, operating system type, installed Agent and component versions, component version summaries, available capabilities, installation and repair error text, latest connection and sync times, and the access key for that computer. We also keep a short event log for each computer, such as connected, stopped, or repair attempted.
Connection records. The IP address and port recorded when you create the account are retained unchanged. The IP address, port, and time of your latest panel access are refreshed at each sign-in. The address used by your computer to connect to our server is used in short-lived counters that limit misuse.
Usage and charge records. For every AI or paid tool request, we record the time, originating computer, model, amount of processed text, numerical size estimates for parts of the request, amount charged to your account, and result. These records do not contain the content of your messages or documents. The only exception is technical error text returned by a provider when a request fails, limited to 2,000 characters.
Task definitions. We store the text entered in the task setup wizard, the generated draft, your corrections, task rules, task folder, and selected settings.
Notifications. The full text of every message sent to your phone or Telegram account, the attachment name when applicable, and the sending time are stored on the server. Messages prepared by Agent during a task and held until the run finishes are also stored in full.
Support correspondence. Messages you send in panel support chat and the responses are stored. An AI model answers first. If the model cannot resolve the issue, it offers to transfer the conversation to our team. If you agree, a short summary, your name, and email address are sent to the WhatsApp or Telegram notification channel used by team administrators, and a team member takes over. We record who took over and what they wrote. Recent chat messages are sent to the model to create an AI response, but your account details are not included.
5. Records stored during task runs
Agent reports its actions to the server while running and after completing a task. Every run card shown in the panel is built from this record. The record contains the following text derived from your business data:
- The run summary written by Agent and the full text of the message sent to your phone;
- The Agent explanation and evidence line for each item. Evidence is usually a full file path on your computer and may include your Windows user name;
- Figures that do not reconcile in a table produced by Agent, including the value, file, page, and cell address;
- The NAMES and reasons for records that could not be processed or were excluded by a rule, such as an invoice file or record name, and names of files left unread in a folder that should have been processed;
- Names of temporary files left in the delivery folder and Agent workspace, and names of tools used, but not the values passed to those tools;
- The explanation written by Agent for approval requests and any folder paths offered as options;
- Task memory retained between runs as a free-form notebook written by Agent;
- A processed-item ledger containing an irreversible hash for each item, a short readable label, and an evidence note;
- Names of documents read as images, without folder paths, and names and reasons for unreadable documents. Records older than seven days are removed from these two lists;
- For failed runs, the final part of the sync log on your computer, limited to 3,000 characters of diagnostic text. The local Agent engine log is read on your computer, and only figures and tool names from it are sent to the server. Diagnostic lines may contain file paths or command text.
When a run is complete, the server uses this record to generate a closing report and, where necessary, a missing-items list. Your computer writes both to the task folder. These records are retained while your account remains open. Retention and deletion are explained in Section 18.
6. Content processed temporarily
The following content passes through our server to complete an operation but is not permanently stored beyond the temporary periods stated below:
- AI requests. Every question Agent sends to a model passes through our server. The request contains what Agent has read at that moment, which may include document text, an email body, an incoming message, webpage text, or task instructions. This content is not written to the database. Only the figures and charges described in Section 4 are recorded.
- Connected application results. A shortened copy of a response from Gmail, Calendar, Slack, or a similar application is retained in the server cache for 30 minutes. This is a security measure used to verify that a destination Agent wants to write to came from data it actually read rather than from a fabricated value. The sender address of an email with processed attachments is also cached for one hour.
- Files. When Agent uploads a file to the server for processing, delivery to you, or attachment to an application, or downloads an attachment from an application, the file remains on the server disk for no more than one hour and is then deleted. Its original name is retained for the same period. Limits are 100 MB per file and 25 MB per attachment sent to an application.
- Reading image documents. Image documents without a text layer, including png, jpg, and webp files, are sent through the server to an AI model capable of reading images. Text produced during batch reading is written to a temporary file that is also subject to the one-hour rule.
- Image generation and paid web search. When Agent generates an image, the prompt is sent to the AI provider. When it performs a paid search, the search query is sent. A generated image remains on the server for one hour, and the first 80 characters of the prompt are cached for the same period.
- Telegram bot token. The bot token pasted while connecting Telegram is not written to the database. It remains in server memory for no more than 30 minutes while waiting for your computer to retrieve it.
During their one-hour lifetime, video and image files may be served through an unlisted, randomly generated link that does not require sign-in. Some channels need to retrieve files from our server this way. The link works only for video and image file types.
7. Connected application operations
Operations in Gmail, Calendar, Slack, and similar connected applications run through our server. SECRETARY sends the operation and required parameters to the server. Our server performs the operation through Composio, our integration provider, and receives the result. Email bodies, attachments, and calendar entries therefore pass through our server while an operation is in progress.
We do not store application passwords or access tokens. When you connect an application, its permission screen opens in your browser and authorization tokens are stored by Composio. We send Composio your SECRETARY customer number to identify the account and the parameters needed for each operation, such as recipient, subject, body, or attachment.
8. WhatsApp and Telegram
The session remains on your computer. WhatsApp and Telegram are used through Agent on your computer with your own accounts. Incoming messages are received there and documents are saved there. Messages passing through these channels are also subject to the terms of the relevant platform. WhatsApp does not provide an official business interface for this service, and any restrictions applied to your account are decided by the platform.
A separate Agent handles WhatsApp messages. The Agent that runs your tasks is separate from the Agent that handles WhatsApp conversations. Each contact has a separate conversation session, and the WhatsApp Agent can use only a restricted set of tools.
Who can send accepted messages. If task scope is limited to your contacts, messages from numbers outside your contact list and your own notification number are rejected by the Agent engine on your computer. They are not processed, sent to AI, or recorded. If scope is set to everyone, messages from any number are accepted. Group messages are not processed.
Collect mode. Documents received from your contacts are copied on your computer to a sender-specific subfolder inside the task folder. The folder name is based on the saved name or number and the WhatsApp name. Message text is normally not sent to AI in this mode. In the exceptional case that the engine bypasses this rule, the message may still reach the model, but no reply is sent.
Reply mode. Agent replies to messages from your contacts according to the task instructions and by reading the source folder you selected. The contact message, conversation history, and source content pass through our server to the AI model and are not stored on the server. Before sending, Agent waits for a random few seconds and quotes the message being answered. Agent messages you when a matter needs your attention.
Information reported to the server. For each incoming message, your computer reports the sender number, WhatsApp name, names of saved files and the subfolder, and names and reasons for files that could not be copied. Message text is not sent. The server stores only the latest document arrival time for the matching contact. If a document from a number not on your list passes the engine gate, you are notified. That notification includes the number and remains in notification records. Files that could not be copied are also reported by name. Gate decisions are reported only as counts and contain no phone number or message content.
Selecting contacts from the address book. When WhatsApp is connected, Agent keeps a copy of contact data supplied by WhatsApp only on your computer, limited to 4,000 saved names and numbers. This copy is uploaded to our server only when you ask to import contacts in the panel. The upload contains at most 2,000 names and numbers for people who have a saved name and are not already contacts. The list is deleted from the server when you complete or cancel the selection, and only selected people remain as contacts. If you leave without choosing, the list remains until your next import or selection.
When you disconnect. Agent signs out of the WhatsApp session on your computer, removing it from the linked devices list on your phone. After a successful sign-out, the WhatsApp identity folder on your computer is deleted completely. Only success status and a short reason are reported to the server. If sign-out fails, the panel explains what to do on your phone.
9. Your contacts
A server record is created for each person you add as a contact. It includes the name, an optional tax or Turkish identity number, your notes, identifiers used to recognize the person, such as a phone number, email, WhatsApp ID, or file number, a label for each identifier, and its source. The record also stores the latest document arrival time.
- Contact phone numbers are downloaded to your computer as the WhatsApp gate allowlist.
- If task scope is limited to your contacts, up to 100 names, email addresses, and phone numbers are added to the task instructions and sent to the AI model.
- Deactivating keeps the record but removes the person from the allowlist, task contact lists, and document matching. The record can be reactivated.
- Deleting permanently removes the contact record and linked identifiers from the server. Documents and sender folders on your computer, tasks, earlier run records, and names already included in sent notification text remain unchanged.
You are the data controller for information about these people. The responsibilities in Section 3 also apply to these records.
10. Web operations and browser data
When your tasks require it, Agent visits websites on your instructions, collects information such as tables and lists, and downloads files. It uses a dedicated Agent browser profile on your computer rather than your personal browser.
- Cookies and sessions from visited sites remain in this profile on your computer and are not sent to our server. Downloaded files are saved on your computer.
- Page text read by Agent passes through our server to the model provider as part of an AI request so it can be processed.
- A card number, password, or code entered in task text is stored on our server with the task and sent to the model provider in an AI request so Agent can fill a page field. You decide whether to include such information in task text.
- Saved sign-in: when you connect a site that requires sign-in, or a task finds that the site session is closed, you enter the credentials, such as user name or identity number and password, in a small save window on your computer. No browser window opens for this step. Windows encrypts the information with the key of your Windows user and stores it only on that computer. It is not sent to our server or the AI model and is not shown in the panel. When the session is closed, Agent code on your computer fills the sign-in form with this information in a browser that is not shown on screen. Our server stores the sign-in route for the site, including the page and fields, whether credentials are saved on that computer, and the status of sign-in attempts, including warning text shown by the site. If the site requests a security code, only an image of the security-code section, excluding identity fields and buttons, and the code you enter on the Approvals page remain in server memory for up to 10 minutes while awaiting delivery to your computer. They are not written to the database. Saved credentials are deleted from the computer when you disconnect the site.
- Agent does not fill website sign-in forms by itself except through the saved sign-in process above, does not sign in with an electronic signature, does not access the computer itself or local network addresses, and does not download executable program files. It is instructed to reject optional cookies or accept only essential cookies in consent prompts.
- Free web searches are sent from your computer to DuckDuckGo, which receives the search query.
Visited sites are subject to their own privacy policies and terms. You are responsible for determining whether automated collection complies with the site terms and applicable law, and for having a legal basis when collected information contains personal data.
11. Access and changes on your computer
Agent runs with the permissions of your user account and can access files available to you. It is not confined to a sandbox because it works with actual documents in your folders. Every change made by installation is listed in Section 3 of the Terms of Use. We recommend reading that section before installation.
The following items may be deleted from your computer by a server instruction: temporary files left by a completed run in the delivery folder and Agent workspace, whose names are reported by the computer and selected individually on the server rather than guessed by Agent; the WhatsApp identity folder when you disconnect; and Agent tasks, channel sessions, and the browser profile when you remove a computer from the panel. The closing report and missing-items list written to your delivery folder are not deleted.
12. Processing purposes and legal bases
We collect and process account data through fully or partly automated means, including the panel, Google sign-in, Agent on your computer, payment-provider notifications, and support chat. Under Article 5 paragraph 2 of KVKK, we process it for the following purposes and legal bases:
- Establishment and performance of a contract, subparagraph c: account creation, Agent installation and computer pairing, task execution, connected application and channel operations, notification delivery, usage measurement and charging, subscription and payment operations, and support.
- Compliance with a legal obligation, subparagraph ç: retaining payment and invoice records for periods required by law and responding to lawful requests from authorized public bodies.
- Establishment, exercise, or protection of a right, subparagraph e: retaining operation and connection records, administration audit records, and support correspondence as evidence in potential disputes.
- Our legitimate interests, subparagraph f, provided that your fundamental rights and freedoms are not harmed: service security, prevention of misuse and excessive spending, rate limits, fault diagnosis, secure distribution of Agent versions, and service improvement.
We do not rely on explicit consent for these operations. Promotional commercial electronic messages are subject to the separate rules in Section 16. We process business data as a processor and according to your instructions. You provide the legal basis for that data, as explained in Section 3.
13. Data sharing and international transfers
We use the following providers to deliver the service. Each receives only the data necessary for its role:
- OpenRouter — access to AI models. Content read by Agent, task instructions, support chat, and text entered in the task setup wizard are sent here as part of model requests and then reach the selected model provider. DeepSeek, OpenAI, and Google models are currently used by default. Models may change over time.
- Composio — application connections. Authorization tokens are stored here. Your customer number, operation parameters, and files attached to applications are sent here.
- Polar — payments and subscriptions. Polar collects and processes payment details. We receive the amount, date, order number, and subscription status. Your email address and an account-specific reference number are sent to the payment page, and the payment is matched to your account through that reference.
- Resend — email delivery. Your address, the subject, and message text are sent here. Task content is not sent by email.
- Railway — infrastructure hosting the application, database, and temporary file storage.
- Sentry — server error monitoring. When a server error occurs, the error type, code location, and request address are sent here. Cookies, IP addresses, credentials, request bodies, and task content are not sent.
- Google — panel sign-in. Your name, email address, and basic profile information are received from your Google account during sign-in.
- DuckDuckGo — when Agent performs a free web search, your computer sends the search query to this service.
WhatsApp and Telegram are not our providers. You use these channels from your own computer with your own accounts, and messages travel between your computer and those platforms.
Apart from these disclosures, personal data is shared only to the extent required by a lawful request from an authorized public authority. We do not sell or rent your data or share it for advertising.
International transfers. All providers listed above are established outside Türkiye and process data on servers outside Türkiye. Using the service therefore requires account and business data to be transferred abroad. Transfers are made under Article 9 of KVKK, relying first on an adequacy decision by the Board or, when none applies, an appropriate safeguard listed in the law, such as standard contractual clauses. When these cannot be provided, a transfer is limited to the occasional situations permitted by law. Contact us for information about safeguards used for a transfer.
14. Use of AI and automated decisions
AI models are central to the service. Content sent to models may include task instructions, which can contain a contact list, documents, emails, calendar entries and webpages read by Agent, WhatsApp conversations in Reply mode, documents read as images, image-generation prompts, and text entered in the task setup wizard or support chat.
Model training. We do not use your data to train AI models. OpenRouter states in its privacy policy that it does not use inputs and outputs for model training. Each model provider reached through OpenRouter has its own retention and training policy, and these policies vary by provider.
Errors. AI can make mistakes. You are responsible for reviewing Agent output before relying on it for a decision.
Automated operations. Some account outcomes occur automatically. Agent stops when monthly usage is exhausted, payment fails, or a subscription ends. Requests are rejected when call or spending limits are exceeded. Agent pauses for your approval when an operation requires it. Under Article 11 paragraph 1 subparagraph g of KVKK, you may object to an adverse outcome caused solely by automated analysis of your data. Send an objection to hi@secretary.sh for review by a person.
15. Authorized team access
To provide support and diagnose faults, authorized team members with administration access can view account details, usage and payment records, run records, messages sent to your phone, computer event logs, and support correspondence. When necessary, they can enter your panel on your behalf. Every administration change and every entry to and exit from your panel on your behalf is written to an audit record with the identity of the team member. You may request this record.
16. Emails and commercial electronic messages
We send emails required to operate the service, including alerts when usage is low or exhausted, subscription renewal reminders, and mandatory service notices. These messages are necessary for the subscription relationship. Our team may also send account holders service announcements by bulk email.
Promotional or campaign-related commercial electronic messages are sent in accordance with Turkish Law No. 6563 on the Regulation of Electronic Commerce and related legislation, either with your consent or where the law does not require consent. You may opt out of commercial electronic messages at any time and without charge by writing to hi@secretary.sh.
17. Security
- The panel uses HTTPS. Session and form security cookies are marked secure, the browser is instructed to use secure connections only, and the panel cannot be embedded in other sites.
- Each computer has a unique access key that is renewed when the computer is paired again. Requests are rejected for closed accounts, expired subscriptions, failed payments, computers removed or disabled in the panel, and accounts with no remaining usage.
- Every executable downloaded to your computer is signed, and your computer does not install it before verifying the signature.
- The local Agent gateway is accessible only from the same computer. Other devices on the network cannot reach it.
- Every request is restricted to your account. A key for one account cannot access another account. Agent can call tools only for applications you have connected.
- Our endpoints apply rate limits per address and device, four separate controls for AI spending, and brute-force protection for administration sign-in.
- Keys belonging to AI and integration providers remain only on the server and are never downloaded to your computer.
- Only authorized team members can access the administration panel, and all changes are recorded.
Database fields are not separately encrypted at application level. Data is protected by the access controls described above and the security measures of the hosting infrastructure. No information system can provide absolute security, so we cannot promise uninterrupted or error-free protection.
Data breaches. If we learn that personal data has been unlawfully obtained by another party, we will notify the Turkish Personal Data Protection Board as soon as possible and no later than 72 hours, and affected people within a reasonable period, in accordance with Article 12 of KVKK and Board decisions. If the breach affects your business data, we will notify you without delay so you can meet your own reporting duties as data controller.
18. Retention periods and deletion
Account information, task definitions, run records, notifications and held messages, contact records, support correspondence, usage records, computer event logs, processed-item ledgers, and administration audit records are retained while your account remains open so we can provide the service. Use the application process below to request deletion.
The following items are deleted automatically:
- Files uploaded to the server or downloaded from an application, generated images, and batch-reading text: one hour;
- Cached copies of connected application results and Telegram bot tokens: 30 minutes;
- Names of documents read or not read as images: entries older than seven days are removed when a new record is written;
- An address-book import list: when you complete or cancel the selection;
- The temporary list of items submitted by a task for processing: when the run cycle closes.
When you remove a computer from the panel, it is removed from the service and cleans itself on its next connection. Tasks are deleted, channel sessions are closed, and the browser profile is reset. Historical records for that computer remain in the panel.
When you close your account, access ends, your computers are removed from the service, tasks stop, the sign-in address is disabled, and the Google account connection is removed. Deletion of records requires a separate request. To prevent subscription renewal, you must cancel through the payment provider.
To request deletion of your data, write to hi@secretary.sh. We will conclude the request within 30 days and confirm in writing what was deleted. Records that must be retained by law, such as payment and invoice records, and records necessary to protect a right are kept for the applicable period and then deleted, destroyed, or anonymized.
You can remove authorization for connected applications one at a time by selecting Disconnect in the panel, and you can also revoke access in the security settings of each application. Files created or collected by Agent on your computer belong to you and remain on your computer under your control.
19. Your rights under KVKK and how to apply
Under Article 11 of KVKK, you have the right to learn whether personal data is processed; request information if it is; learn the purpose of processing and whether data is used consistently with that purpose; know the third parties receiving it in Türkiye or abroad; request correction of incomplete or inaccurate data; request deletion or destruction under the conditions in the law; request notice of correction, deletion, or destruction to third parties that received the data; object to an adverse result caused by analysis solely through automated systems; and claim compensation for damage caused by unlawful processing.
How to apply. Under the Communiqué on Procedures and Principles of Application to the Data Controller, you may apply in writing, by registered electronic mail known as KEP, secure electronic signature, mobile signature, or from the email address registered in our system to hi@secretary.sh. Include your full name and, for a written application, signature; Turkish identity number if you are a citizen of Türkiye, or nationality and passport or other identity number if you are not; residential or business address for notices; email address and phone number for notices when available; and the subject of the request. We may request additional information to verify your identity.
We will conclude your application free of charge as soon as possible and no later than 30 days, depending on its nature. If processing creates an additional cost, the fee set by the Turkish Personal Data Protection Board may apply. If the application is rejected, the response is inadequate, or no timely response is provided, you may complain to the Board within 30 days of learning the response and in all cases within 60 days of the application.
Requests concerning data for which you are the controller, such as data about one of your contacts, should be submitted to you. If we receive such a request, we will forward it and help you respond.
20. Cookies
Our website and panel use only cookies that are essential to operate the service. They are used for contract performance and our legitimate interest in security. Under the KVKK Guidelines on Cookie Practices, explicit consent is not required for these essential cookies:
- sessionid — keeps your session active after sign-in. It is valid for up to two weeks and ends when you sign out.
- csrftoken — prevents another site from submitting forms on your behalf. It is valid for about one year.
- messages — is written when needed to show a one-time information message after an operation. It is deleted after display and expires when the browser closes.
The panel also uses browser session storage to remember which channel tab you left open. This information remains only in your browser and is deleted when the tab closes.
We do not use analytics, advertising, or marketing cookies, and we do not run third-party tracking tools. Page assets, including fonts, load from our own server. When you sign in with Google, Google uses cookies on its own site under its own policy. You may delete or block essential cookies through browser settings, but the panel will no longer allow sign-in.
21. Users in the European Union and other countries
If you are in the European Union or European Economic Area and the General Data Protection Regulation applies to the service, we process account data under Article 6 based on contract performance, paragraph 1 subparagraph b; legal obligation, subparagraph c; and legitimate interests, subparagraph f. You have rights of access, correction, deletion, restriction, portability, and objection, and may complain to the data protection authority in your country.
For business data, you are also the controller under the GDPR and we process data on your behalf. Data is processed outside the European Economic Area, including in Türkiye and countries where the providers in Section 13 operate. If an EU representative is appointed under Article 27, contact details will be published in this section. Until then, use hi@secretary.sh for all requests.
22. Children
The service is intended for businesses and adults. It is not offered to anyone under 18, and we do not knowingly collect account data from people under 18. If we identify such an account, we will close it.
23. Changes
This policy is updated when product operation changes, and the date above is revised. If an update materially changes how data is processed, we will send a separate notice before it takes effect.
24. Contact
For any question about this policy, your personal data, or your rights, contact: hi@secretary.sh