ExoCortx Privacy Policy
Overview
ExoCortx is a private context assistant for user-controlled capture, local memory review, and on-device assistance. The iPhone 1.0 release does not require account registration, a developer-operated server, an Apple Watch app, or an accessory.
The shipping privacy manifest declares no collected data and no tracking. Core captures and settings remain on the iPhone unless you explicitly export information, contact support, or configure an optional private runtime or supported external device.
Settings and local records
ExoCortx stores settings and local state such as onboarding completion, capture mode, retention period, haptic and notification preferences, enabled signals, activity-log entries, assistant conversations and memory, context records, and review decisions in app-private storage on the iPhone.
Captures and user content
Depending on the features and permissions you choose, ExoCortx can process photos, audio notes, text notes, transcripts, assistant prompts, context events, timestamps, source labels, and related metadata. Captures may contain sensitive information based on what you record.
You are responsible for following applicable law and obtaining permission before recording other people, conversations, or private spaces. ExoCortx is not a covert-recording tool.
Permissions and automatic learning
Camera and Photo Library access support captures you choose. Microphone access supports audio notes you initiate. Location access can support on-device automatic learning about frequent departure places and routines when enabled. Bluetooth, local-network, and Bonjour access support optional compatible devices. Notifications support status and nudge flows.
You can change permissions in iOS Settings. The standalone iPhone assistant remains usable without optional device permissions, although the related feature will not work.
Optional devices and private runtimes
If you choose a supported smart-device integration, ExoCortx can process device identifiers and names, connection state, signal strength, battery and charging state, memory and temperature status, motion or telemetry frames, acknowledgements, commands, and audio or image frames received from that device.
You may configure a private-runtime URL and bearer token. When that optional runtime is active, selected captures, prompts, transcripts, context metadata, device identifiers, timestamps, nudge feedback, and usage events can be sent to the runtime you configured. Morphantic does not operate or receive records from a user-controlled private runtime. Records stored there are controlled by that runtime and its operator.
The submitted phone-v1 capability manifest marks third-party AI sharing as planned rather than public. The built-in assistant and local library do not require a third-party model provider.
Diagnostics, ads, and tracking
The reviewed iPhone release does not include a third-party analytics SDK, advertising SDK, or dedicated crash-reporting SDK. ExoCortx does not sell personal information, use it for third-party advertising, or track users across apps or websites. Apple, TestFlight, and the App Store may separately provide operational information under Apple's terms.
Local storage and security
Settings, activity records, review metadata, assistant state, and capture records are stored in app-private local storage. Captured files used by the review library are stored as app-private files. Some vault data uses AES-GCM with an app-generated key, but the current implementation does not claim that every local capture path has separate FileVault encryption. iOS app sandboxing and your device security settings also protect local data.
Retention and deletion
You can delete captures in the review flow and delete approved library items. ExoCortx also applies the configured retention period to eligible old, unapproved captures and metadata. Approved captures and assistant memory can remain until you delete them or use an applicable cleanup control.
Removing the app deletes its app container. A configured private runtime or optional device has its own storage and deletion controls. Contact wes@glassbox-bio.com to request deletion of information you voluntarily sent in a support or privacy message.
Contact
Privacy, access, and deletion questions can be sent to wes@glassbox-bio.com.