Director ("we", "us") makes a macOS application for directing AI agents across your desktop by pointing, gazing, and speaking. Because Director can see your screen and act in your apps, we want to be precise about what stays on your Mac, what leaves it, and where it goes. Director is in private beta; this policy will evolve with the product.
The short version
Camera (hand & gaze) is processed entirely on your Mac. Video frames are turned into pointing data on-device and are never uploaded or stored by us.
Speech defaults to on-device transcription, and the microphone is push-to-talk — it only listens while you hold the activation control. Director is not always-listening.
To carry out a task, Director sends the screen context it needs — including screenshots and your instruction — to the AI providers that do the work. That is how an agent acts in your apps. We tell you who below.
We do not sell your data and use no advertising or tracking SDKs.
Processed on your Mac (local by default)
Camera frames — hand and head/gaze tracking runs on-device (MediaPipe). Frames are converted to pointing signals locally and discarded; they are not sent to us or anyone else.
Microphone audio — by default, speech-to-text runs on-device, so your audio stays on your Mac. Capture is push-to-talk only.
Screen context — open apps, window titles, and accessibility metadata are read on your Mac to resolve what you're pointing at.
Activity log — your commands, the resolved plan, screenshots taken, actions run, and approvals are recorded in a local log so you can review and replay them. This log is stored on your Mac.
What leaves your Mac, and to whom
Director only sends data off your device to understand or execute what you ask:
Understanding your intent — your transcript and the on-screen context needed to interpret it are sent to our backend, which uses OpenAI to return a structured plan.
Doing the task — to act in your apps, the relevant screen content, screenshots, and your instruction are sent to the AI and agent providers that perform the work (for example OpenAI, and the coding agents you direct such as Claude Code or Codex). Those providers process this data under their own terms.
Optional hosted speech — if you turn on hosted transcription, your audio streams to AssemblyAI instead of staying on-device. This is opt-in; on-device is the default.
Website — the email you enter to request the download is sent to us through our form provider so we can send you the build and beta updates.
Permissions Director asks for
Camera — hand and gaze pointing.
Microphone — push-to-talk voice.
Screen Recording — to see windows and take the screenshots an agent needs to act.
Accessibility & Input Monitoring — the activation hotkey and to control apps on your behalf.
You grant these in System Settings and can revoke any of them at any time.
Your control
Director shows a plan before it acts, and actions that change or send things wait for your greenlight. You can pause or interrupt at any time, and every action is kept in the local log for review. You own the local log and can delete it.
What we don't do
No always-listening — the mic only runs while you hold the control.
No selling of personal information.
No advertising, analytics, or tracking SDKs in the app.
We don't upload your camera frames or your on-device audio.
Retention & your choices
Local data (your activity log and settings) lives on your Mac until you delete it. We keep the contact details you give us only as long as needed for the beta. Email us anytime to access or delete what we hold. Data sent to third-party AI providers is retained and handled under their policies, linked above.
This is a plain-language summary for a private beta, written to match how Director actually handles data. It is not legal advice; have counsel review before any public launch.