Your content stays on your device. Only thinking requests run via our server — in normal operation it stores none of them.
This English version is provided for information only. The German version is the authoritative one; in case of any discrepancy, the German version prevails.
Privacy policy (Datenschutzerklärung)
As of: 25 September 2026
1. Controller
TCB GmbH, Europaring 4, 94315 Straubing, represented by Thomas Becheru, datenschutz@octovo.de . Competent supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach.
2. The most important point first
OCTOVO is a program that runs on your device. Your emails, files, contacts, appointments and everything OCTOVO has learned about you sit encrypted in a file on your computer. We have no access to it. There is no copy with us, no backup in our cloud, no remote access.
What our server sees: the single question OCTOVO puts to the language model so that it can answer. This question is passed through and not stored — no cache, no log with content, no error message with content. What is stored is solely the time, the account, the model used, the number of characters processed, the duration and the status code. We need these numbers for billing and operations.
3. When you visit the website
Each visit creates server logs containing the IP address (stored in shortened form), the time, the page accessed, the amount of data transferred and the browser identifier. The legal basis is Art. 6 Abs. 1 lit. f DSGVO (GDPR) — our legitimate interest in secure operation. Deleted after 7 days.
We use no analytics or advertising services , load no third-party fonts, no map services and no embedded videos. That is why there is no consent banner on this website — there is nothing to consent to. Technically necessary are merely a session cookie in the account area and the state of the payment process. On the public pages themselves nothing is stored on your device: no cookie, no local storage, no identifier.
Two things these pages do nevertheless, and you should know about both. The Status page asks, when opened and roughly once a minute thereafter, our own server whether it is reachable; every other page with the full footer — that is, not the start page and not the pages Features, Connections, The app, Security and Contact — asks a single time when opened, to fill the availability line in the footer. This creates the same server logs as described above, and nothing is transmitted about you that a normal page visit would not also transmit. And the Download page reads your browser’s identifier to move the matching package to the top — exclusively in your browser, without transmission and without storage.
4. When you create an account
The following is processed: name, email address, password (only as a non-reversible hash using Argon2id), optionally passkeys, licence and quota data, device list (name, operating system, time of last contact). Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of contract). Deletion: with the account, except where retention periods under commercial and tax law stand in the way (invoices: 10 years).
When creating the account you expressly agree to several things: the terms and conditions, the data processing agreement, the sending of emails about your contract and the AI liability notice; you also confirm that you have read this privacy policy. Each checkbox must be ticked individually — none of them is pre-ticked, and a missing tick counts as a no.
What we store about this and why: for each of these consents, the time, the wording you agreed to, the place where you did so, your IP address and a version stamp of the legal text in force at the time. The version stamp is a checksum derived from the text itself: if we change one line of the terms, the checksum changes, and it remains provable which text you agreed to. Legal basis: Art. 6 Abs. 1 lit. c DSGVO in conjunction with Art. 7 Abs. 1 DSGVO — we must be able to prove what was agreed. These records are never overwritten; a correction is created as a new entry next to the old one. They are deleted with the account.
What of this is revocable: The consents above carry the contract and cannot be withdrawn individually — if you no longer want them to apply, you cancel. Advertising is separate from this, voluntary and revocable at any time (section 9). You can view your complete record — which consent, when, in which version — in your account; it is at the same time the information under Art. 15 DSGVO on this point.
5. When you pay
Payments are handled by Stripe Payments Europe, Ltd. Card details never reach our servers. From Stripe we receive name, billing address, payment status and invoice number. Legal basis: Art. 6 Abs. 1 lit. b DSGVO.
6. When OCTOVO thinks for you
So that OCTOVO can understand or write an email, it sends an excerpt — never your entire mailbox — via our server to Microsoft Azure AI Foundry, where the approved OpenAI models run (default: GPT-5.6 Terra, fallback: GPT-5.6 Luna). Microsoft operates these models on its own infrastructure; OpenAI, as the manufacturer of the models, has no access to the request, according to Microsoft’s own documentation. For this transfer, we are the processor and you are the controller ; the data processing agreement is concluded together with the purchase and is available in your account as a PDF. The transfer follows the agreed processing chain and the standard contractual clauses that apply to it. Every payload sets store: false on the Responses path; OCTOVO stores no content in normal operation.
If the excerpts contain other people’s data (for instance your customers’), you remain responsible for its processing. OCTOVO expressly points this out during the first getting-to-know-you run.
The model boundary and fallback: The server accepts only exactly listed OpenAI identifiers. GPT-5.6 Terra is the immutable default; if that attempt fails, OCTOVO tries GPT-5.6 Luna exactly once. Other providers, bare names, aliases and manipulated identifiers are rejected before transport. In both cases the same necessary excerpt is transmitted — never your entire mailbox, never your memory as one piece and never an image of your screen.
What is stored: Only the time, account, model used, volume, duration and status code are stored for operations and billing. Request and response content are not placed in our server logs during normal operation. For processing on your behalf, the following remains unchanged: you are the controller, we are the processor.
7. When you switch on screen observation
This capability is switched off by default . If you switch it on, OCTOVO captures the screen content at an adjustable interval, reads it out as text entirely on your device and then discards the image. Before reading, a blocklist applies (password stores, banking and login pages, private windows and anything you add); blocked areas are never read in the first place. Card numbers, IBANs, keys and confirmation codes are removed before anything is filed. The text sits in the same encrypted file as your other data and expires automatically after the period you set (default: 7 days).
What leaves your device in the process: If you ask OCTOVO something that refers to what was seen, the necessary excerpt of this text travels, as part of a thinking request, the same route as in section 6 — via our server to Microsoft Azure AI Foundry and the OpenAI model running there. From observation, text is transmitted, never an image and never a video.
To be distinguished from this is the look on request. If a question of yours refers to something that is only on your screen — “what am I looking at right now?”, “why is this complaining?” —, OCTOVO takes an image of every connected screen at that moment and sends it as part of the thinking request the same route as in section 6, so that it really sees what you are referring to. This never happens by itself: the first time, it asks you for permission as a clickable question, you see every image reduced in the conversation, and you can withdraw the permission at any time under Settings → Screen. This route is independent of whether observation is switched on. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent), revocable at any time.
Inevitably, other people’s data also appears on the screen. You remain responsible for its processing; switch observation off during screen sharing and in other people’s sessions. On a work device, use without a works agreement is not permitted (§ 87 Abs. 1 Nr. 6 BetrVG); for professions bound to secrecy (§ 203 StGB), observation is blocked in confidentiality mode and must be enabled individually. Legal basis for switching it on: Art. 6 Abs. 1 lit. a DSGVO (consent), revocable at any time — “Forget the last hour” and complete deletion take effect immediately. Emotion recognition, biometric categorisation or behavioural assessment does not take place and is expressly prohibited in the terms of use.
8. Which connections OCTOVO establishes from your device
Not everything runs via our server. Some things OCTOVO fetches directly from your device — the other side then sees your IP address, just as it would with any request from your browser, and we see none of it . These connections are listed here in full:
- Your mailbox. OCTOVO talks directly to your provider’s mail server. The credentials sit in your operating system’s keychain and never reach us.
- Your calendar. OCTOVO talks directly to your provider’s calendar service — via CalDAV (such as iCloud or Nextcloud) or via the provider’s own interface. With Google and Microsoft you sign in once with the provider in your browser; the way back from that sign-in ends on your device, and instead of a password OCTOVO receives an access key together with a refresh key, with which it extends access without signing in again. Password and refresh key alike sit permanently in your operating system’s keychain and never reach us. We do not see appointments, participants or calendar names; your provider’s terms apply to your calendar.
- Setting up the mailbox. So that you only have to type in your email address, OCTOVO looks up the right settings with the provider: it queries
autoconfig.your-domainand.well-known, and reads your domain’s server records in the name service. What is transmitted is the part of your address after the @ sign, not the address itself. - The weather for the “Today” board and the “wetter” tool. It is queried from Open-Meteo (Germany and Switzerland). What is transmitted is solely the place name you yourself entered in your profile, or its coordinates — no account, no key, no identifier, no personal reference. The request runs from your device, so your IP address is visible to Open-Meteo; at most four times per hour. Without a place entered, no request takes place — if you delete the place, it stops immediately. The board visibly names Open-Meteo as the source.
- Web search — if you have stored your own access key. Under Settings → “Web search” you can store access to a search interface. OCTOVO then puts your search queries to it — either to Tavily (AlphaAI Technologies Inc., New York, USA) or to Brave Search (Brave Software, Inc., San Francisco, USA) — depending on which of the two you chose. What is transmitted is your search query in plain text, together with your key; the request runs from your device, so your IP address is visible to the service. Both are based in the USA, a third country without an adequacy decision for this case; both work with standard contractual clauses, and neither is certified under the EU-US Data Privacy Framework (checked on 22 August 2026). The account and the bill for it are yours, not ours — the respective provider’s terms apply. Without stored access, none of these requests take place — if you remove it, they stop immediately.
- Searching for news — even without access. For news OCTOVO needs no key: it queries the public news feed (RSS) of Google News (controller for users in the European Economic Area: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). What is transmitted is your search query in plain text as part of the address; the request runs from your device, so your IP address is visible to Google. This is the only route that runs without any action on your part : if no search access is stored, OCTOVO falls back to it when you ask about news, and a “News” board tile you have created refreshes through it as soon as you look at it and its content is stale. If you create no such tile and do not ask about news, nothing happens here either.
- Pages OCTOVO opens for you. If you ask it to read a page — or if it opens the best hits of a search — it fetches it directly from your device. To the operator of that page this looks like a visit with your browser: they see your IP address and the address requested. We see none of it, and there is no cache of it at our end.
- Connected channels (cloud storage, Facebook pages, Instagram business accounts, LinkedIn and the other networks). Here too your device talks directly to the platform. Their own terms and privacy notices apply; you remain responsible for your accounts there.
- The reachability check with us. The program asks at intervals whether our server and the thinking service respond. No content goes out in the process.
- GitHub, when you ask about a project. If you ask OCTOVO to look at the issues, pull requests or workflow runs of a repository, it calls GitHub directly from your device. GitHub then sees the repository name, your IP address and the time — and, if you have stored your own GitHub access token under Settings, that token. Public repositories need no token, so this path runs without any setup, but only when you ask for it: nothing happens here on its own. OCTOVO only reads there; nothing is written, commented or closed. The controller is GitHub, Inc. (88 Colin P. Kelly Jr. St., San Francisco, USA) or GitHub B.V. (Prins Bernhardplein 200, 1097 JB Amsterdam). GitHub is certified under the EU-U.S. Data Privacy Framework (checked 23 August 2026) and additionally relies on the European Commission’s standard contractual clauses.
The legal basis in each case is Art. 6 Abs. 1 lit. b DSGVO. For everything you set up yourself — mailbox, connected channels, search access — the following applies: the connection arises only because and insofar as you have set up the corresponding capability, and it stops as soon as you remove it again. For the requests that are possible even without any setup — the news feed and the opening of a page — the same applies with a different trigger: they arise only from an instruction you give, or from a tile you created yourself, and they stop as soon as you stop doing that or remove the tile. A request triggered neither by a setup nor by an instruction of yours does not take place.
9. Newsletters and system emails
We distinguish two kinds of email to you, and the separation is technically enforced in the program — not merely a promise.
- Service notices about your contract (outages, maintenance, changes to the terms, security notices, invoices) go to all customers with a valid licence. They contain no advertising. Legal basis: Art. 6 Abs. 1 lit. b DSGVO.
- Advertising newsletters go exclusively to accounts with confirmed consent via the double opt-in procedure. As proof (Art. 7 Abs. 1 DSGVO) we store the wording you agreed to, the origin of the sign-up, the time and IP address of the request and the confirmation, and, where applicable, the time of the withdrawal. Legal basis: Art. 6 Abs. 1 lit. a DSGVO in conjunction with § 7 Abs. 2 UWG.
Every email carries an unsubscribe link and the legal notice (Impressum). Unsubscribing takes effect immediately upon opening the link , without logging in and without follow-up questions. What remains afterwards is solely the record that you consented and withdrew again — it is the reason no further advertising reaches you. We use no tracking pixels and measure neither whether you open an email nor what you click in it; all that is stored is whether and when an email went out. Sending is done via Mailgun (EU region), see sub-processors .
10. Diagnostic mode
Only if you expressly switch it on for your account does our server record requests, encrypted and for a limited time, so that support can find a fault. The mode always has an expiry date (at most 7 days), is visible in the program while it is running, and deletes the recordings immediately when switched off. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent), revocable at any time.
11. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to withdraw a consent at any time and to lodge a complaint with a supervisory authority (Art. 77). For the data on your device you do not need us for any of this: in the program, under “Meine Daten” (My data), you can view, change and export everything, and delete it completely with one click.
12. Recipients
The complete, continuously maintained list is available at sub-processors . We announce changes at least 30 days in advance.
13. No automated decision with legal effect
OCTOVO makes no decisions within the meaning of Art. 22 DSGVO. It prepares and carries out what you have instructed it to do; responsibility and the sender role remain with you.