Privacy policy
Agent Maxer uses a Mac app and hosted service to make agent task status and usage information available to Apple devices signed in to your account. This policy covers the Agent Maxer apps, their widgets and Live Activities, the hosted service (the Bridge), and this website.
Accounts and sign-in
Email/password, Sign in with Apple, and Google sign-in use Firebase Authentication. Authentication processes your email address, account and provider identifiers, and credentials or sign-in tokens. A sign-in provider may also supply profile information, such as your name and profile image URL. Passwords entered for email sign-in are sent to Firebase, not to the Bridge.
The account profile in Firestore stores your Firebase user ID, email address, creation time and, after a Mac is registered, its server-issued tenant ID and registration time. Each Mac relay has one server-recorded Firebase account owner and cannot be shared across different accounts. An account can register more than one Mac relay. A profile pointer or a locally calculated hash is not accepted as ownership proof.
Task status and usage
The Mac relay sends task IDs, short titles, provider names, states and timestamps to the Bridge. These fields are readable by the service. It also sends available provider usage totals, usage windows, limits, reset times and reset-credit metadata. The service stores the latest state, your recent/pinned source selection and completion-read acknowledgements to synchronize your devices.
The status payload is not a repository or full conversation upload. However, titles can contain information from your conversations, including confidential material. Formatted final responses are handled separately below. Do not put secrets in titles or assume that truncation removes sensitive information.
Speech and response text
Once the Mac relay is configured, completed responses are shared automatically with your signed-in devices. Current production limits response availability to 24 hours. The 30-day availability update described below is prepared but not yet live. New completions are read aloud automatically on eligible iPhones. Formatting removes fenced code blocks, but is not a sensitive-data filter.
Response text is encrypted on the Mac using AES-GCM before upload and decrypted on an authorized signed-in iPhone for system speech playback. Thread and response IDs, the speech context ID and expiry times remain readable. The Mac creates an independent random content key that is not derived from a device credential. When an eligible signed-in iPhone uses spoken responses, it publishes a device-specific public key. The Mac sends the Bridge a separately wrapped copy of the speech content key for each eligible iPhone; only the matching private key stored in that iPhone's Keychain can unwrap it. The unencrypted content key is never sent to the Bridge. Agent Maxer does not record your microphone or upload a voice recording for this feature.
Devices and notifications
A signed-in Mac asks the Bridge to create a server-generated tenant ID bound to the authenticated Firebase account. Each signed-in installation creates a random access credential, keeps the raw credential in Keychain, and sends only its hash during registration. The Bridge issues a device session bound to the account, selected Mac, device type and environment. An Apple Watch receives a separately scoped member credential through its signed-in iPhone. Speech private keys and the unencrypted speech content key remain in Keychain on their respective devices.
Live Activity and widget features register push tokens and, where applicable, an app-generated device ID, activity ID, push environment and widget kind/family. Stored push tokens are encrypted at rest; the service can decrypt them to send updates through Apple Push Notification service. Task status sent in notifications is processed by Apple and may be visible on your Lock Screen, watch or desktop. Signed-in devices can review and revoke registered installations.
Purchases
Apple processes App Store payments. RevenueCat processes receipts, transaction and subscription history, and entitlement status to validate purchases, restore access and provide subscription analytics. Agent Maxer identifies RevenueCat customers with their Firebase user ID, so purchase history is linked to your account. Agent Maxer does not receive your full payment-card details. Deleting an Agent Maxer account does not cancel an Apple subscription; manage it in your Apple account. See the terms of use.
Product analytics and app verification
Agent Maxer uses Google Analytics for Firebase on its website, iPhone, iPad and Mac apps to measure visits, account creation and sign-in, relay connection, and purchase or restore success. These events have no task titles, prompts, response text, email addresses, pairing keys, or provider usage details. Google may process app and device details, browser information, IP addresses and interaction data to provide these reports. Agent Maxer does not use this measurement for cross-app advertising tracking or personalized ads.
Website analytics are off until you choose to allow them. You can decline or change your choice below at any time. The iPhone, iPad, and Mac apps offer a separate analytics choice in Settings.
Analytics choice: not set.
Firebase App Check uses browser risk assessment on the website and Apple app attestation on supported iPhone and iPad devices, and DeviceCheck on supported Macs, to help reject forged requests. It supplements account sign-in and server authorization. The Apple Watch app and widgets do not run the Analytics SDK.
Local data and provider connections
Display preferences, imported wallpapers and cached status are stored on your devices. Widgets share selected state and entitlement settings with their app group. The Mac reads supported agent data from local files or helper processes you enable. Provider credentials are not included in the Bridge status payload; connections to an agent provider may use those credentials with that provider. The provider's own service and privacy terms apply to those connections.
The website uses Firebase browser storage to maintain sign-in. Its hosting service and account providers process network information such as IP addresses, user agents and request timing to deliver and protect their services. The website does not include an advertising pixel. This does not exclude service-provider logging or the analytics described above.
Service providers and purposes
Google/Firebase provides authentication and data storage; Google Cloud hosts the Bridge. Apple provides sign-in, purchases, device synchronization and push delivery. RevenueCat provides subscription processing and analytics. Website hosting processes requests and serves site assets. These services receive data needed for their roles, including operational and security information.
Google Sign-In's SDK also declares account/profile information (including phone number where available), approximate location, device identifiers and usage/technical data for functionality or analytics. Those SDK disclosures are broader than the fields saved in Agent Maxer's account profile. The reviewed app code does not use data for cross-app advertising tracking or include an advertising network. Provider retention and service terms also apply to data processed by those providers.
Provider information: Firebase privacy and security, Google privacy policy, RevenueCat privacy policy, and Apple privacy policy.
Retention and deletion
Latest relay state is replaced by subsequent updates. Other records, including profiles, registrations and acknowledgements, can remain until removed. The current production service limits speech response availability to 24 hours. Expiry is not a guarantee of physical deletion at that time; asynchronous provider cleanup, logs and backups can retain copies longer.
30-day availability update — not yet live. After the updated service and apps are released, new speech envelopes will be available for up to 30 days. A newer response in the same session will replace the previous one. Storage will be limited to 32 sessions per Mac relay by default (configurable up to 64). New uploads will remove expired responses first, then evict the least recently published responses when needed. Listening will not delete a response. Expired responses will be refused and removed when read; uploads will also clean up expired responses in bounded batches. This update will not extend existing encrypted expiry times or guarantee physical deletion within 30 days.
Account deletion first asks the Bridge to fence and remove relays owned by the signed-in account, their stored content and device registrations, and the account profile. Firebase Authentication is deleted last. If ownership is ambiguous or cleanup is incomplete, deletion stops and keeps sign-in available for a safe retry. Minimal retirement and operation records remain to prevent old credentials from being reused. Provider records, service logs, backups and Apple subscription records follow their providers' retention rules and may not be removed by this flow. Account deletion does not cancel an Apple subscription.
Your choices and privacy requests
You can stop the Mac relay to stop new relay uploads, choose which supported agents to connect, manage playback and display settings, and control visible notifications and widgets through Apple's settings. Account controls are available in the apps and on the account page. Signing out immediately suspends the affected local device. Server detachment prevents new reads, registrations and push admissions for that device and its connected Apple Watch while preserving other devices. If the device is offline, remote cleanup remains pending and is retried. Already submitted notifications may still arrive, and previously rendered offline content can remain until the system refreshes it. Existing stored data is subject to the limitations above.
Agent Maxer is provided by Numbus LLC. For privacy questions or account-deletion help, email admin@numbus.app. The same Agent Maxer privacy and account-deletion disclosure is also available at legal.numbus.app.