AI usage policy
Effective 3 September 2026 · Last updated 10 September 2026
The short version. Some of what you ask is answered by a model on your own Mac and never leaves it. The rest goes out to be answered, carrying only the context the request needs, and it is covered by your plan rather than by a second subscription you have to buy. Your content is not used to train any model, ours or anyone else’s. It gets things wrong, so read anything you are going to act on.
This policy sits alongside our privacy policy and terms of service. It exists because “we use AI” is not a disclosure, and because you cannot judge whether to trust an assistant that has access to your machine unless you know what it does with what it sees.
1. What the system is
Cory is a background service on your Mac. When a message addresses it, Cory assembles the context for that request. Simple requests are answered by a model running on the Mac itself. Anything heavier is sent to the model provider we contract with, under your plan. The model returns text; Cory decides what to do with it: reply in the conversation, write a Notion page, create a file, or run a command you asked for. Simple requests are often answered first by a small model built into macOS, which runs on your Mac and sends nothing anywhere. Beyond those two there is no model of ours, and no intermediary service operated by Crate Systems.
2. What gets sent, and what does not
Sent to the model, for the request you made:
- the message that addressed Cory;
- enough of the surrounding conversation to make it make sense, including a follow-up like “make it vegetarian” that amends what came before;
- the participants’ display names or handles, so it knows who is speaking and what they are allowed to ask for;
- results Cory gathered on your instruction: the contents of a file you asked it to read, output from a command you asked it to run, search results from your message history when you asked it to search;
- data from an account you connected, when the request needs it: the calendar events in the window you asked about, or the Notion page you asked it to update. Only the part the request needs, never the whole calendar or workspace.
Not sent:
- conversations you did not involve it in, unless you explicitly asked it to search your history;
- your files at large. It reads what a request requires, not the disk;
- the tokens for services you have connected, which are stored on your Mac and never sent with a request.
3. Training
- Crate Systems does not train, fine-tune or evaluate any model on your content. The only content we hold at all is chats you type in the desktop window while signed in, kept so they survive a reinstall, and never used for training.
- Our agreement with the model provider prohibits using anything we send for training. We will name our current sub-processors on request.
- Data obtained from a connected Google account is never used to develop, improve or train generalized AI or ML models. See the Google user data section of the privacy policy.
4. What it is not good at
The failure modes are predictable, so they are worth knowing:
- It can be confidently wrong. A name, a date, a price or a citation can be invented and will not look invented. Anything factual that matters should be checked against the source.
- It is not a professional adviser. Nothing it produces is legal, medical, financial, tax or safety advice, and it should not be relied on as such.
- Recommendations are not verified availability. It cannot see a restaurant’s book, a flight’s seat map or a shop’s stock. A suggestion is a place to start calling, not a reservation.
- It can misread an instruction. On a machine where it can change files, that has consequences. Keep backups.
- Prompt injection is real. Text in a file, a web page or a message from someone else can contain instructions aimed at the model. Cory constrains what non-owners can ask for, but no current system is immune. Do not point it at content you do not trust and then let it act unsupervised.
- It can be biased or stale. Model output reflects its training data, which has a cutoff and is not neutral.
5. Where a person stays in the loop
Cory does take actions, and it is worth being exact about which. Asked to, it writes a Notion page, creates a file on your Mac, adds a calendar event, or runs a command. Each of those changes something outside the chat, and each happens only in direct response to an instruction you typed.
One of them reaches somebody else. If you have connected Stripe, Square or PayPal, asking Cory to invoice a client creates and sends that invoice. There is nothing between the sentence and your customer receiving it. The app says so at the moment you connect the service, and it is repeated here because it is the only thing on this list with a third party on the other end.
What it will not do is act unprompted. It does not reply to a message on your behalf, does not spend money you have not told it to spend, and does not run on a schedule unless you set one up and confirmed it.
Before you act on Cory’s output in a way that is expensive, public or hard to reverse, read it.
6. Speed
A question your Mac can answer by itself comes back almost at once. Anything that has to go out takes longer, and how much longer depends on what you asked and how carefully you asked it to think. Cory sends an acknowledgement straight away so you know it heard you, because an assistant you are unsure heard you is worse than a slow one.
We are not printing an average here. We have not measured one across enough real machines to publish, and a number invented for a marketing page is worse than no number at all.
7. Permissions, and who can ask for what
- The owner of the Mac can direct Cory to read and write files, run commands, and search the full message history on that machine.
- Everyone else in a conversation gets a restricted version: it can answer and search within what it is permitted to see. It cannot run commands, reach the machine’s files, or use any service you have connected.
An assistant with a shell should not take orders from whoever is in the group chat.
8. Prohibited uses
You must not use Cory to generate or assist with material that is unlawful; to impersonate a person or organization in order to deceive; to produce content that sexualizes minors; to harass, defraud or discriminate against anyone; to generate disinformation for distribution; to develop weapons or malware; to make an automated decision about a person’s employment, credit, housing, insurance or legal rights without meaningful human review. These sit alongside the acceptable-use terms in the terms of service, which apply in full.
9. Disclosure to other people
Cory replies in your conversations, which means other participants read its output. It identifies itself: its acknowledgement is written in its own name, and it does not pretend to be a person. If you use it in a professional context where the other party needs to know they are reading machine-generated text, telling them is your call and your responsibility.
10. Changes and questions
Model providers change, and this policy will be updated when the facts do. The date at the top reflects the last change. If something here is unclear, or you think we have described the system inaccurately, write to hello@trycrate.net. That is a correction worth making.