Private by design, practical by default
Talavine is built around explicit roles, configurable permissions, model routing choices, and human-readable approvals. You decide when employees can send email, contact external addresses, or spend cloud budget.
Last updated: October 2, 2026
What the website stores
The public website stores community topics, replies, moderation audit entries, and site pulse or release updates published through the authenticated agent update API. Community submissions can include the display name, email address, topic text, reply text, moderation status, timestamps, and operational logs needed to keep the board reliable.
What stays local in the desktop app
Talavine is local-first. The desktop app stores configured accounts, messages, contacts, tasks, calendars, agent profiles, tool history, preferences, local telemetry, and generated context in databases on the user's device unless the user chooses an integration or cloud model that requires sending data elsewhere.
Connected AI data sources
Connecting a Talavine profile to an external AI assistant shares the scope approved on the connection page. Profile access includes discovery and retrieval of enabled messages and documents, non-secret notes, contacts, tasks, calendar events, Matters, memories, context and knowledge-graph evidence, and available create, update, send and delete operations requested by the user while the desktop app is running. Older read-only grants remain read-only. Disabled sources, credentials and secret notes are excluded. The website stores the connection identifier, client identifier, authorization scope, token hashes, and expiry or revocation times. Requested search terms and record results pass through talavine.com to the connected AI service. Queued requests and responses are encrypted in the website's storage and removed after delivery or expiry. The website decrypts these results to deliver them; this integration is separate from the mobile companion's end-to-end encryption. The connected AI service handles received data under its own privacy terms. Disconnect in Talavine or revoke the connection in your AI service to stop further retrieval. Your underlying profile database remains on your computer.
Talavine mobile companion and encrypted relay
The optional Talavine mobile app pairs with a Talavine desktop installation using a QR code or short pairing code. The phone stores its pairing identifier, device token, shared secret, relay address, desktop name, and locally cached companion views on the phone. Pairing credentials are kept in the operating system's secure storage. Unpairing clears the phone's local pairing state and asks the relay to revoke the paired devices and delete their queued data.
Paired devices exchange end-to-end encrypted payloads through Talavine's hosted relay. The relay stores pair and device records, hashed bearer tokens, device names, Apple push-notification tokens, encrypted message payloads, and encrypted file or photo chunks needed to deliver companion features. Talavine's relay does not hold the key needed to decrypt message, email, note, artifact, approval, or photo contents. Acknowledged messages are removed by the relay cleanup process; undelivered messages expire after at most seven days, and unfetched file or photo blobs expire after at most three days. Unclaimed pairing codes expire after ten minutes.
If the user enables mobile notifications, the relay sends Apple a device push token and a generic alert category such as a new agent reply or an approval request. Message content is not included in the push notification. Talavine does not use the mobile companion for advertising or cross-app tracking and does not include a third-party analytics SDK.
The separately distributed Talavine Full Android app can optionally request permission to receive and send carrier SMS messages. If the user enables its live SMS bridge, new incoming phone numbers and message bodies are forwarded end-to-end encrypted to the paired desktop, and texts that the user or paired desktop authorizes can be handed to Android for carrier delivery. It does not read or import SMS history, and the user can disable the bridge or revoke either permission in Android Settings. The Google Play edition does not request these SMS permissions and does not contain the SMS receiver or send bridge.
SwarmSpan
SwarmSpan stores clipboard history, preferences, diagnostics, and paired-device records on the user's device. Clipboard contents and files move directly between devices the user explicitly pairs; Talavine, LLC does not operate a cloud relay for those transfers and does not collect their contents. The Mac App Store edition has no account, advertising, or analytics SDK and does not run external agent processes or an MCP bridge. Data remains on the user's devices until the user clears history, removes a paired device, deletes transferred files, resets the app, or uninstalls it.
When data leaves the device
Data may be sent to third-party services when a user connects an email, calendar, chat, model provider, MCP connector, or guided setup flow. If the user selects a cloud AI provider, prompts and relevant context can be sent to that provider to produce summaries, drafts, classifications, and agent actions. Local model options are available for users who prefer to keep model traffic on-device.
Model providers and subprocessors
Depending on configuration, Talavine may interact with providers such as OpenAI, Anthropic, Google Gemini, Ollama, email/calendar providers, chat services, and user-approved MCP connectors. Each provider processes data under its own terms and privacy policy.
Crash reports (opt-in, off by default)
The desktop app can email a crash report to support@swarmmarshal.com after it restarts following a crash. This is a diagnostic feature that is off unless you turn it on in settings. When it is enabled, the report is sent from your own configured email account — the same account the app sends mail with — so your address is visible to us and a copy will normally appear in that account's Sent folder. A report contains the exception type, the exception message, the stack trace, the app version, the operating system version, and the time of the crash; on macOS, native crash reports also include the crashed thread's name and the symbol names of its top stack frames. Reports are de-duplicated by fingerprint so the same crash is not sent twice, and no more than a few are sent per launch. Turning the setting off stops these sends.
Bug reports you send from the app
The desktop app has a bug-report button. It only ever runs when you press it. Pressing it sends an email to bugreports@swarmmarshal.com from your own configured email account, and the message includes a screenshot of the app as it currently appears on screen — which can contain message content, contact names, subject lines, or anything else visible at that moment — plus the tail of the local diagnostics log (up to 96 KB) and the app version. Close or navigate away from anything you do not want to send before pressing the button. Bug reports are used to diagnose the problem you are reporting and are retained only as long as needed for that.
Approvals and agent actions
Agents are designed to prepare work and ask for approval before sensitive actions such as sending external messages, changing connected systems, or spending cloud budget. Some automations can be configured by the user to run with narrower approval rules.
The hosted CRM service
Talavine also offers a hosted, multi-tenant CRM at
<workspace>.crm.talavine.com. Unlike the desktop app, this is a cloud service:
the data lives on our infrastructure, not on your device. Its commercial terms are the separate
CRM Service Terms.
What is stored. A CRM workspace holds the business records your team enters — companies, contacts, deals, activities, notes, tasks, files, and related history — plus user accounts and sign-in credentials for the people you invite, and application and audit logs needed to operate and secure the service. Signing up also creates a record on this website containing the company name, workspace name, administrator name, email, optional phone and company website, estimated user count, the plan chosen, the version of the terms accepted and when, and the IP address and browser user agent of the signup request. It also has fields for Stripe customer and subscription identifiers, which stay empty for a free-preview signup because no checkout takes place.
Where it is hosted. The CRM runs on Microsoft Azure — Azure App Service for the application and Azure SQL for the database — currently in the West US 3 region in the United States.
Payments. The hosted CRM is currently free and signing up does not collect a payment method, so no payment data about you exists or reaches any payment processor. When paid plans begin, subscriptions will be billed through Stripe, which acts as the payment processor and handles card details directly. We do not receive or store full card numbers; we keep the Stripe customer and subscription identifiers and the status of the subscription.
Controller and processor. For the data your team puts into a CRM workspace, the customer is the data controller and Talavine is a processor acting on that customer's instructions. For our own account, billing, and service-operation records about the customer, we are the controller. AI features in the CRM send the content they need to the model provider configured for that workspace (OpenAI, Anthropic, or Google, depending on configuration); tenant data is not used to train models and is not sold. Sub-processors are listed in the CRM Service Terms.
Access and deletion. Workspace administrators can request an export or deletion of their workspace data by emailing support@swarmmarshal.com. If you are an end customer of a business that uses the CRM, contact that business first — they control the record. Retention after cancellation is described in the Refund and Cancellation Policy.
Retention
Local app data remains on the user's device until the user deletes it, resets the app, removes an account, or changes retention settings. Local telemetry is retained for operational troubleshooting and defaults to a limited retention window. Website community and release records are retained as long as needed to operate the website, enforce community safety, resolve disputes, or satisfy legal obligations. Hosted CRM workspace data is retained while the workspace is live — free or paid — kept during suspension, and deleted after the retention window described in the Refund and Cancellation Policy; CRM signup and billing records are kept as long as needed for accounting and legal obligations.
Community safety
The customer bulletin board uses automated rule-based moderation to reject common abusive or spammy content before it appears publicly. Moderation is not perfect, and rejected or suspicious activity may be reviewed manually.
Security
Talavine uses explicit permission surfaces, local databases, platform storage, release checksums, and least-privilege connector flows where practical. No system can be guaranteed perfectly secure, so users should avoid connecting accounts or granting tools they do not want agents to access.
User choices and requests
Users can remove connected accounts, delete local app data, change model providers, disable tools, and stop using community features. Requests about website community data, access, correction, deletion, or privacy rights can be sent to privacy@swarmmarshal.com.
Children
Talavine is not intended for children under 13 or for anyone below the minimum age required by applicable law to use AI, email, calendar, or connected account services.
Changes
We may update this policy as Talavine changes. Material changes will be reflected on this page and, where appropriate, in release notes or in-app notices.