Privacy
Your data has a destination.
Graze is a client for your own herdr host. This policy describes the current release candidate from Tlon OU.
Updated September 26, 2026. The app is not yet available on the App Store.
Data sent to your host
The app sends commands, message text, selected agent identifiers, and an access token to the HTTPS bridge you configure. It retrieves agent names, project and host labels, terminal excerpts, and management results. Your host, terminal, coding agents, and their providers may retain commands and output under their own settings and policies.
Voice
When you record, the app sends the recording to your configured bridge for transcription. The bridge forwards it to the speech provider selected by the host operator. When you choose to listen, output text is sent through that bridge to the text-to-speech provider. Playback is an AI-generated voice. The bridge supports configurable provider endpoints; ask the host operator which provider and retention settings apply before sending sensitive content.
Storage on your device
The bridge address is stored in app preferences. The access token is stored in Apple Keychain, restricted to this device. Pending messages and host actions are saved in protected app storage to reconcile uncertain outcomes. They may contain message text, target details, or action parameters and are removed when the app clears the pending operation. Conversation history, agent details, and drafts are saved locally using SwiftData so they remain readable offline. These records persist between app launches and are not synced through CloudKit. Removing the app removes its local conversation database.
Recordings use temporary files that the app attempts to delete when recording finishes or is cancelled. A crash or storage failure can leave temporary data until the operating system removes it. Removing the app does not revoke its bridge token or erase host/provider records; Keychain entries can survive reinstalling.
Storage on the bridge
The bridge keeps a local delivery journal to prevent duplicate commands. Message records include an operation identifier, a hash of the request, and its outcome. Management receipts also retain returned results, which can include terminal output and host information. The bridge currently also stores terminal-derived conversation text and message revisions in a separate chat database for reconnects. These databases have no automatic expiry. The host operator controls access and retention; deleting the journal can remove protections against replaying old commands.
Tracking and website data
The app includes no advertising or third-party analytics SDK. This website has no analytics scripts, advertising, contact forms, or application cookies. Vercel hosts the site and may process request information such as IP address, browser information, requested URL, and timestamps to deliver and secure it. See Vercel’s privacy policy.
Your choices
Use text without granting microphone access. Choose which host to connect to and review voice transcripts before sending. Ask the host operator to rotate credentials or address host records, and contact the relevant provider about data it retains. Do not send credentials or private source code in support requests.
Contact
Contact Tlon OU at mati@tlon.sh. Please describe your request without including credentials or private agent content.