Privacy
Privacy policy
Continuo runs on your computer. This page says plainly what it keeps there, what never leaves, and the one content-free thing that does.
Draft 1 · 31 July 2026 · applies to Continuo for Windows and to getcontinuo.com
Draft — under review. This is not legal advice.
This is a working draft, published so it can be read and challenged before an attorney reviews it. It is not yet the binding policy, and it does not create rights or obligations. The final version ships with the first public build. If anything here does not match what the software actually does, the software is the fact and the page is the bug — tell us.
The short version
- Everything runs on your machine. Capture, transcription, the AI that writes your minutes, and the memory it builds all execute locally. The free tier works fully offline, forever.
- We do not operate a server that holds your meetings. No copy of your minutes, transcripts, or memory exists on our side — nothing for us to read, lose, hand over, or train on.
- Public builds send at most an anonymous, content-free crash report. That is the only thing the software sends us on its own, and it cannot carry meeting content by construction.
- Recording material is not written to disk by default. Audio, screen samples, and verbatim transcripts live in memory only while your machine turns them into knowledge, then they are gone.
- Nothing goes out without you approving it. Every outbound action — an email, a document, a question sent to an AI you connected — is a decision you make, each time.
- Consent is yours to obtain. Continuo makes lawful, disclosed recording the easy path and tells you when it has not seen a notice, but the responsibility for recording lawfully stays with you.
What this covers
This policy covers two things: the Continuo desktop application you install on your own computer, and this website. It describes what the software does with your data on your machine and what it transmits. Where a section applies only to one of them, it says so.
This website
No cookies, no analytics, no trackers, and no requests to anyone else — the page loads nothing from a third party. Your language, theme, and colour choices are stored by your own browser, on your own device, and are never sent anywhere.
If you email us at the address below, we have your email and whatever you wrote in it. We use it to answer you, and — if you asked to be told when the build is ready — to send you that one message.
What Continuo stores on your computer
Everything below lives in a folder you choose, on your own disk. You can see the exact location in the app under Settings, in the "Where your data lives" row.
- Knowledge, not recordings. The durable record is work product: minutes, decisions, action items with owners and dates, risks, open questions, and the memory graph of the people, projects, and topics in your work. Every stored claim carries a pointer to the moment it came from.
- Recording material — by default, none. Audio, screen samples, and verbatim transcripts exist only in memory while your machine processes them. If your own policies allow keeping recording material, you can turn that on explicitly and set how long it is kept; the default keeps nothing.
- Work in progress. While a meeting is being processed, the derived work product (partial minutes and memory updates, with their citations) is written to disk incrementally so that a crash or a power cut does not cost you the meeting. If you discard the meeting, that material is purged with it.
- A consent record per meeting. How notice was established, the text of it, timestamps, any screen crop used as evidence, and how you resolved any objection or escrow. It is kept because it is the evidence that the recording was disclosed.
- What it reads from accounts you connect. With a mail account connected, Continuo reads every folder except junk, deleted items, drafts and outbox — including mail you sent, because that is the record of what you actually did. Only a short preview of a message is kept, never the mailbox. Calendar and chat connectors work the same way: read-only, previews only.
- Access tokens for the accounts you connect, stored encrypted on your machine so you do not have to sign in again.
- A local diagnostic log — a capped, rotating debug log that stays on your machine. Field failures are meant to be debuggable without anyone sending us anything.
Media and the knowledge database are encrypted at rest on shipped builds, with the key held by Windows for your user account. The app shows the current state in Settings, under "Encryption at rest" — it reports honestly if encryption is off rather than assuming.
What never leaves your computer
None of the following is ever transmitted to us, on any tier:
- Audio recordings and screen samples
- Verbatim transcripts
- Minutes, briefs, agendas, and any other document Continuo writes
- Your memory graph — the people, organisations, projects, decisions, and commitments it holds
- The previews and metadata it read from your connected mail, chat, and calendar
- Anything captured while consent was unresolved or withdrawn
This is a property of the architecture, not a promise about our intentions. There is no Continuo cloud holding your meetings, so there is nothing on our side to breach, subpoena, sell, or train a model on. When the consent basis for a meeting is lost, that meeting is held on your machine and is excluded from anything outbound until you resolve it.
What does leave your computer, and when
An honest list. Nothing here carries the content of your meetings except the last two items, which happen only because you asked for them.
1. Content-free diagnostics and crash reports
Public builds send at most an anonymous, content-free crash report. A report is a fixed, allow-listed set of fields and nothing else:
- the kind of event (crash, diagnostic, metric, or "still running")
- a timestamp, the build variant, the app version, and the operating-system family
- which component it came from and which event it was — chosen from a fixed vocabulary; an unrecognised value is sent as unknown
- for a crash: the exception type and a stack of file names, line numbers, and function names
- bounded numeric counters (for example, how many meetings compiled)
The exception message is deliberately never sent, because an error message can quote the thing that broke it. There is no field in the format that can hold text you or your colleagues wrote, so a bug in our code cannot cause meeting content to ride along.
You can see whether diagnostics are being sent in the app, under Settings, in the "Diagnostics sent off device" row. Whether they are sent at all is a single on/off setting in the app's configuration file; turning it off silences the transport completely.
2. Checking for updates
When update checks are enabled, the app periodically fetches a small version manifest to see whether a newer signed build exists, and downloads the installer only when you choose to update. The check sends nothing about you or your data.
3. Downloading the local AI model
The local model that powers your brain is too large to bundle in the installer, so the app downloads it once, from its public source, and verifies its checksum. This is a download; nothing about you is uploaded.
4. Accounts you connect
If you connect a calendar, mail, or chat account, your machine talks to that provider directly, using read-only permissions, to read your own data. Nothing in that exchange passes through us. The one exception is a write you turn on deliberately: the optional organiser notice, which appends a single line to invites you create so that attendees are told in advance — that line and nothing else.
5. The frontier bridge (Plus and Enterprise)
If you connect your own frontier AI assistant, using the bridge sends that question's context to the cloud model you chose. That is the one explicit, per-use exception to "nothing leaves," and it only ever happens when you invoke it. It never fires on its own, and content held in escrow is never eligible.
6. Documents you send
Minutes, briefs, and agendas are finished on your machine and wait for your review. When you send one, it goes where you send it — your mail client, a folder, a colleague. Approval is per document, never a standing permission.
We do not sell data, we do not share data with advertisers, there is no advertising in the product, and we do not train models on your content — there is no copy of it on our side to train on.
Consent and recording law
This is the section worth reading twice, because the split of responsibility is real.
What Continuo does
- It looks for evidence that the people in the meeting were told — a notice in the invite, a disclosure in the chat, a platform recording banner, a known notetaker in the roster, or you saying you announced it out loud.
- It tells you when consent has not been detected, and keeps nothing durable until notice is established. An ignored prompt means nothing is recorded.
- If someone appears to withdraw consent, it flags it and asks for your confirmation. Code never judges a human's words on its own, and no automated signal can stop a recording — only you can.
- If the basis for consent disappears mid-meeting, everything downstream is held until you resolve it: no minutes, no memory learned, nothing outbound.
- It records how notice was established, so there is evidence afterwards.
What is yours
Obtaining consent is yours to do. Recording law varies by country, and within the United States by state — some require every participant to agree, and some settings (biometric identifiers, privileged conversations, workplace policy, client agreements) carry extra rules. Continuo does not and cannot determine what is lawful for your meeting. Using it does not make a recording lawful, and we do not condone unlawful recording.
The main page has a jurisdiction helper that links to official guides for several regions. It is a starting point for your own research, not legal advice, and it is not a substitute for asking a lawyer where it matters.
Keeping, expiring, and deleting
Media expires; knowledge does not. If you have opted into keeping recording material, it is pruned automatically once it reaches the age you set (the free tier's default is 30 days). The knowledge compiled from it — the minutes, the decisions, the memory — is kept indefinitely, under strict size budgets, so a two-year-old meeting has no playback but still answers "what did they commit to" with citations.
Deleting is real deleting. Because your data is on your disk and nowhere else, removing it removes it. There is no copy on our servers, no backup we hold, and no soft-delete state we can restore from — and equally, if you delete something we cannot get it back for you. Stopping a meeting with "discard" wipes that meeting's material immediately, including the work in progress.
Backups you choose to make are yours to manage. If you point the app's backup at an external drive, everything stays on your devices.
There is no Continuo cloud sync today. If an optional encrypted backup or sync is offered in the future, it is designed as a mirror your own machine encrypts before anything is uploaded, with the keys never leaving your devices — and this policy will be updated before any such feature ships.
Security
Shipped builds encrypt media, artifacts, consent records, and the knowledge database at rest, with the key held by Windows for your user account, so there is no extra password to manage and no key of yours in our hands. The public build ships code-signed, so Windows can show you who published it (signing is being set up as this draft is written). The website loads no third-party code.
No system is perfect, and the honest security story here is that most of the usual risk is absent rather than defended: there is no central store of customer meetings to attack. What remains is your own machine, which means your device security — disk encryption, screen lock, who else uses the account — is part of the picture.
Children
Continuo is a tool for professional work and is not directed at children. It is not intended for anyone under 16, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us information, write to us and we will delete it.
Changes to this policy
When this policy changes we will update the date at the top and post the new version here. If a change materially affects what the software stores or transmits, it will be announced with the build that makes the change — not slipped in quietly. We will keep the previous version available so the difference can be seen.
Contact
Questions, corrections, or a privacy request: [email protected]. If something on this page does not match what the software does, we want to know — that is a defect, and it gets fixed in both places.