Praxa

Trust

Security and privacy at Praxa

Trust here does not rest on a promise in a policy document. It rests on what the running system does and does not let happen, described mechanism by mechanism below.

Consent is per source and revocable together, approvals are server recorded and fail closed, password values stay outside the model, and Praxa does not sell personal information.

How it works

Nine mechanisms, not nine promises

Each item below is a mechanism in the running system, not an intention in a policy document.

  1. 01

    The shape of the data

    Context state admits a closed signal vocabulary: a channel identity, a bounded numeric feature, a confidence value, and a timestamp. Raw coordinates, speed, event titles, message bodies, camera frames, audio, and provider content are not representable in that storage at all. Control layers on top: consent from the source, consent from you, a short expiry, and erasure the moment you revoke.

  2. 02

    Consent is per source, and revocable together

    Nothing turns on at sign-up. Onboarding tells you plainly that no permission prompts fire, and that camera, microphone, motion, Health, communications, and precise location stay off until you choose. One master switch revokes every source at once.

  3. 03

    Health

    Health data is read on your device for the specific request you made. The query, the samples, the draft, and any tool output are stripped before the conversation or the tool ledger is written, so Health data never enters context or memory. Writing a Health sample always requires an explicit confirmation card, and the on-device model cannot write Health data at all, by construction.

  4. 04

    Camera and face

    Camera frames, face images, identities, and raw landmarks are never uploaded. Praxa does not infer identity, emotion, diagnosis, or any other sensitive trait from a face.

  5. 05

    Voice

    No audio and no transcript are retained on the voice path. The derived cue clears the moment voice ends, consent is revoked, or verification fails.

  6. 06

    Approvals

    Every consequential action is matched, server side, against the literal instruction and host you approved. Absent a stored approval record, the action refuses. This check runs beneath the model, so it holds even if the assistant is talked into something it should not do.

  7. 07

    Credentials

    Connection tokens live in the device Keychain and travel only with the request that needs them. The model never receives or types password values, and generic browser tools refuse them. An approved device fill can enter a credential bound to the live site's host without exposing its value to the model; you can always take over. No card numbers or security codes are stored.

  8. 08

    Commercial posture

    Praxa does not sell personal information. There are no ads, and no one can pay to have Praxa promote a product or service in conversation.

  9. 09

    Sign-in

    Sign in with Apple or Google only. There is no Praxa password to breach.

Praxa doesn't display ads, and it doesn't let anyone pay to have Praxa promote products or services in conversations. The Praxa AI app is a space to think and get things done, not an advertising surface.

From Praxa's operating instructions

Read the documents

The privacy notice and terms of use are the full legal texts behind the mechanisms above. Report a concern directly to the team that owns them.

Report a security concern: team@praxa.io