Privacy

Privacy policy

Continuo runs on your computer. This page says plainly what it keeps there, what never leaves, and the one content-free thing that does.

Draft 1 · 31 July 2026 · applies to Continuo for Windows and to getcontinuo.com

Draft — under review. This is not legal advice.

This is a working draft, published so it can be read and challenged before an attorney reviews it. It is not yet the binding policy, and it does not create rights or obligations. The final version ships with the first public build. If anything here does not match what the software actually does, the software is the fact and the page is the bug — tell us.

The short version

What this covers

This policy covers two things: the Continuo desktop application you install on your own computer, and this website. It describes what the software does with your data on your machine and what it transmits. Where a section applies only to one of them, it says so.

Draft note: this draft deliberately makes no statement about sign-in or account requirements for downloads, updates, or billing — that decision is still open. It describes only what the software stores and transmits. Any account-related processing must be added here before publication.

This website

No cookies, no analytics, no trackers, and no requests to anyone else — the page loads nothing from a third party. Your language, theme, and colour choices are stored by your own browser, on your own device, and are never sent anywhere.

If you email us at the address below, we have your email and whatever you wrote in it. We use it to answer you, and — if you asked to be told when the build is ready — to send you that one message.

Draft note: confirm what the static host records (request logs, IP addresses, retention window) and state it here before publication. This draft does not claim the host keeps nothing, because that has not been verified.

What Continuo stores on your computer

Everything below lives in a folder you choose, on your own disk. You can see the exact location in the app under Settings, in the "Where your data lives" row.

Media and the knowledge database are encrypted at rest on shipped builds, with the key held by Windows for your user account. The app shows the current state in Settings, under "Encryption at rest" — it reports honestly if encryption is off rather than assuming.

What never leaves your computer

None of the following is ever transmitted to us, on any tier:

This is a property of the architecture, not a promise about our intentions. There is no Continuo cloud holding your meetings, so there is nothing on our side to breach, subpoena, sell, or train a model on. When the consent basis for a meeting is lost, that meeting is held on your machine and is excluded from anything outbound until you resolve it.

What does leave your computer, and when

An honest list. Nothing here carries the content of your meetings except the last two items, which happen only because you asked for them.

1. Content-free diagnostics and crash reports

Public builds send at most an anonymous, content-free crash report. A report is a fixed, allow-listed set of fields and nothing else:

The exception message is deliberately never sent, because an error message can quote the thing that broke it. There is no field in the format that can hold text you or your colleagues wrote, so a bug in our code cannot cause meeting content to ride along.

You can see whether diagnostics are being sent in the app, under Settings, in the "Diagnostics sent off device" row. Whether they are sent at all is a single on/off setting in the app's configuration file; turning it off silences the transport completely.

Draft note: today the off switch is the telemetry.enabled key in the app's configuration; the Settings row is read-only. A one-tap in-app toggle is a pending product item, and this paragraph should be rewritten the day it ships.

2. Checking for updates

When update checks are enabled, the app periodically fetches a small version manifest to see whether a newer signed build exists, and downloads the installer only when you choose to update. The check sends nothing about you or your data.

3. Downloading the local AI model

The local model that powers your brain is too large to bundle in the installer, so the app downloads it once, from its public source, and verifies its checksum. This is a download; nothing about you is uploaded.

4. Accounts you connect

If you connect a calendar, mail, or chat account, your machine talks to that provider directly, using read-only permissions, to read your own data. Nothing in that exchange passes through us. The one exception is a write you turn on deliberately: the optional organiser notice, which appends a single line to invites you create so that attendees are told in advance — that line and nothing else.

5. The frontier bridge (Plus and Enterprise)

If you connect your own frontier AI assistant, using the bridge sends that question's context to the cloud model you chose. That is the one explicit, per-use exception to "nothing leaves," and it only ever happens when you invoke it. It never fires on its own, and content held in escrow is never eligible.

6. Documents you send

Minutes, briefs, and agendas are finished on your machine and wait for your review. When you send one, it goes where you send it — your mail client, a folder, a colleague. Approval is per document, never a standing permission.

We do not sell data, we do not share data with advertisers, there is no advertising in the product, and we do not train models on your content — there is no copy of it on our side to train on.

Keeping, expiring, and deleting

Media expires; knowledge does not. If you have opted into keeping recording material, it is pruned automatically once it reaches the age you set (the free tier's default is 30 days). The knowledge compiled from it — the minutes, the decisions, the memory — is kept indefinitely, under strict size budgets, so a two-year-old meeting has no playback but still answers "what did they commit to" with citations.

Deleting is real deleting. Because your data is on your disk and nowhere else, removing it removes it. There is no copy on our servers, no backup we hold, and no soft-delete state we can restore from — and equally, if you delete something we cannot get it back for you. Stopping a meeting with "discard" wipes that meeting's material immediately, including the work in progress.

Backups you choose to make are yours to manage. If you point the app's backup at an external drive, everything stays on your devices.

Draft note: before publication, confirm and describe the in-app controls for deleting a single meeting and for erasing everything. This draft describes deleting your own files, which is true today, but the policy should point at a control if one ships.

There is no Continuo cloud sync today. If an optional encrypted backup or sync is offered in the future, it is designed as a mirror your own machine encrypts before anything is uploaded, with the keys never leaving your devices — and this policy will be updated before any such feature ships.

Security

Shipped builds encrypt media, artifacts, consent records, and the knowledge database at rest, with the key held by Windows for your user account, so there is no extra password to manage and no key of yours in our hands. The public build ships code-signed, so Windows can show you who published it (signing is being set up as this draft is written). The website loads no third-party code.

No system is perfect, and the honest security story here is that most of the usual risk is absent rather than defended: there is no central store of customer meetings to attack. What remains is your own machine, which means your device security — disk encryption, screen lock, who else uses the account — is part of the picture.

Children

Continuo is a tool for professional work and is not directed at children. It is not intended for anyone under 16, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us information, write to us and we will delete it.

Changes to this policy

When this policy changes we will update the date at the top and post the new version here. If a change materially affects what the software stores or transmits, it will be announced with the build that makes the change — not slipped in quietly. We will keep the previous version available so the difference can be seen.

Contact

Questions, corrections, or a privacy request: [email protected]. If something on this page does not match what the software does, we want to know — that is a defect, and it gets fixed in both places.

Draft note: before publication add the legal entity name and postal address, the data-controller identification and a lawful-basis statement for readers under the GDPR/UK GDPR, the state-privacy-law disclosures (including a "we do not sell or share personal information" statement), and a response-time commitment for requests. Those belong to the attorney review, not to this draft.