Privacy

Privacy Overview

You choose when Invoko can observe: only when summoned, or during the proactive windows you configure.

Invoko privacy flow for On-Demand and Always-On modes, authorized sources, processing, defaults, and controls

When Invoko can observe

Choose On-Demand or Always-On. Invoko uses screen context within the mode, work windows, and system permissions you set.

On-Demand

01

After you summon Invoko

Invoko uses authorized screen context after you start a request with a shortcut, tap, or voice interaction.

Always-On

02

During the work windows you set

Invoko uses authorized screen context during configured work windows to generate proactive suggestions. Observation stops outside those windows.

ModeWork windowsSuggestion frequencyPause statusSystem permissions

What leaves your Mac

Invoko prepares authorized context on your Mac. A request, proactive suggestion, transcription, or approved action may require the task-relevant portion to leave your device.

A microphone starts a voice interaction and sends audio for transcription

Voice starts when you start it

Invoko captures microphone audio after you begin a voice interaction.

Always-On does not capture microphone audio continuously by default. Continuous capture requires separate configuration and permission.

Raw audio not retained by default
Invoko prepares authorized task context on your MacPrepared on your Mac

Invoko prepares authorized context on your Mac

Invoko assembles current task context from the screen, app, voice, file, and account sources you authorized.

Task-relevant context may leave your Mac when remote processing is needed. Saved task history, outputs, and memory remain local until you delete them.

Prepared locally
Only task-relevant transcript, authorized screen context, and request data leave your MacAuthorized
screen context

Invoko sends the context needed for the task

On-Demand starts after you summon Invoko. Always-On may use authorized screen context only inside the work windows you configure.

Invoko sends only task-relevant excerpts or image context. It does not upload a continuous screen history.

No continuous screen history
Task context travels through an encrypted tunnel to the selected providerEncrypted in transit.
Sent to the selected provider.

Context goes to the provider needed for the task

Invoko sends the task-relevant portion through its secure proxy to the selected transcription, AI, tool, or connected-service provider. The data-source disclosures below identify the processors and retention periods.

The result returns to your Mac and saved history remains under your control

Results return to your Mac

Invoko returns the result to your Mac. Task history, outputs, and memory remain local when you choose to save them. Screenshots are not retained by default, and remote providers handle task data under the retention terms disclosed below.

How Invoko handles your data

See when Invoko uses each type of data, what leaves your Mac, who processes it, how long it is kept, and what you can control.

01

Screen and app context

Screen and app context you authorize for requests and proactive suggestions.

Collection and trigger
Current app, window title, page URL, selected or focused text, accessibility context, and a screenshot when needed. On-Demand starts after you summon Invoko. Always-On runs only inside the work windows you configure.
Data sent off your Mac
Only task-relevant text excerpts, metadata, or image context needed for an AI request leave the device. Invoko does not upload a continuous screen history.
Retention
Screenshots are not retained by default. Local task history or memory may retain the context needed for continuity until you delete it.
Processors
The Invoko desktop app, Invoko's secure proxy, and contracted AI providers used for the request.
Purpose
To understand the work in front of you, answer a request, or generate a proactive suggestion during an enabled window.
Your controls
Change modes, edit work windows and suggestion frequency, pause Always-On, revoke macOS Screen Recording or Accessibility access, and export or delete saved history.
02

Voice and transcripts

Audio and transcripts from voice interactions you start.

Collection and trigger
Microphone audio is captured when you start a voice interaction. Always-On does not continuously capture microphone audio by default; continuous audio requires separate configuration and permission.
Data sent off your Mac
The audio stream, transcript, or relevant transcript excerpt needed to transcribe speech and complete the request may leave the device.
Retention
Raw voice recordings are not retained by default and are deleted after transcription. A transcript may remain in user-visible task history until you delete it.
Processors
The Invoko app and contracted transcription or AI providers used for the interaction.
Purpose
To turn speech into text and carry out the request you make.
Your controls
Stop the interaction, pause Invoko, revoke macOS Microphone access, review or export saved transcripts, and delete task history.
03

Tasks, files, history, and memory

Content you submit, generate, or save in Invoko.

Collection and trigger
Prompts, files, snippets, generated outputs, task state, and saved preferences are used when you submit, import, save, or continue a task.
Data sent off your Mac
Only the file contents or excerpts relevant to the active task are sent for remote processing. Your full local library is not uploaded as a unit.
Retention
Saved content remains locally until you delete it or close your account. Temporary remote processing follows provider retention commitments.
Processors
The Invoko app, Invoko's secure proxy, and the AI or tool providers selected for the task.
Purpose
To complete work, show results, support follow-ups, and preserve continuity you choose to keep.
Your controls
Choose what to submit or save, stop a running task, export results and history, delete individual items or all history, and request account deletion.
04

Connected accounts and approved actions

Records and actions from services you connect.

Collection and trigger
Account identifiers, authorized records, and action parameters are accessed only after you connect a service and a task or configured feature needs it.
Data sent off your Mac
Only the records, fields, and action details needed for the approved task are exchanged with the connected service and, when needed, the selected AI provider.
Retention
Connection tokens remain until revoked or the account is closed. Task results may remain in local history until you delete them.
Processors
Invoko, the connected service, and any contracted AI provider required to complete the task.
Purpose
To read permitted context or take an action you request.
Your controls
Disconnect the account, revoke access with the provider, stop the task, and export or delete resulting history. Sensitive account actions still require an explicit request, authorization, or approval.
05

Account and billing

Identity, account settings, subscription status, and billing metadata.

Collection and trigger
Email, sign-in identifiers, account settings, subscription status, and limited billing metadata are collected when you register, sign in, change settings, or subscribe.
Data sent off your Mac
Identity and session data needed for authentication, plus payment details sent directly to the payment processor. Invoko does not receive full card details.
Retention
Account data is kept for the life of the account plus 30 days after deletion. Payment records follow legal and processor retention requirements.
Processors
Invoko, the sign-in provider you choose, and Stripe for payments.
Purpose
To authenticate you, maintain settings, provide the subscription, prevent abuse, and meet legal obligations.
Your controls
There is no observation stream to pause. Update settings, export your data, revoke third-party sign-in access, cancel the subscription, or close the account and request deletion.
06

Diagnostics and reliability data

Crash, error, performance, app, and OS information.

Collection and trigger
Crash reports, error stages, coarse performance measurements, app and OS versions, and optional sanitized usage events are collected when an error or measured product event occurs.
Data sent off your Mac
Structured operational fields may leave the device. Voice content, screenshots, full transcripts, raw prompts, and default personal identifiers are excluded by design.
Retention
Diagnostic and usage telemetry is retained for up to 12 months and purged on a rolling basis.
Processors
Invoko and contracted diagnostics, analytics, and cloud infrastructure providers.
Purpose
To diagnose failures, protect the service, and improve reliability and performance.
Your controls
Turn optional diagnostics off in Settings and request access, export, or deletion where applicable. Core reliability diagnostics remain limited and on by default.

Future data sources: Invoko will publish these details before connecting a new source, including health data.

Controls you can change

Mode and work windows

Choose On-Demand or Always-On, edit work windows and suggestion frequency, pause observation, or return to On-Demand.

Sensitive account actions

Invoko requires your explicit request, authorization, or approval before a sensitive account operation.

Screenshots

Invoko does not retain screenshots by default. It discards them after the request or configured proactive suggestion.

Microphone audio

Always-On does not capture microphone audio continuously by default. Continuous capture requires separate configuration and system permission.