Legal · Privacy
Privacy Policy
This policy explains what Phantom handles on your Mac and in its cloud services, why it is used, who receives it, and the choices you have.
Effective 20 July 2026 · Version 1.3
1. Who we are
Benaja Raphael Heger, Haubenstrasse 32, 3672 Oberdiessbach, Switzerland, operates Phantom and is the controller for the processing described in this policy. This policy covers the Phantom website, macOS app, accounts, cloud features, subscriptions, support, downloads, and legal requests.
Phantom combines processing on your Mac with cloud processing when you ask it to use a cloud-backed feature. Services you choose to connect have their own privacy terms and may act as separate controllers.
When a download notice, app screen, or checkout control links to this policy, clicking Download or checking the applicable control acknowledges that you were shown the policy. It does not turn this policy into a contract or provide blanket consent. Where consent is legally required for a specific activity, we ask for it separately.
2. Information we handle
Depending on how you use Phantom, we may handle:
- Account information: your Google account identifier and the name, email address, profile image, and verification information Google shares for authentication, together with Phantom account identifiers, settings, accepted legal-document versions, and acceptance timestamps.
- Task content: prompts, short-term conversation context, transcripts, microphone audio, generated responses, and feedback. When a request needs them, this can also include screenshots, Accessibility information, running-app or visible-window information, selected text, clipboard text used for dictation, files or file paths you select, connected-service content, tool inputs, and results.
- Connections and actions: the services you connect, connection and account identifiers, authorization status, requested actions, action categories, parameters, returned results, and local workflow or approval state.
- Plans, usage, and transactions: plan and entitlement status, subscription and checkout identifiers, usage and cost-metering events, request and idempotency identifiers, timestamps, rate-limit data, checkout-consent records, payment status, and limited transaction contact information. Link and Stripe receive payment-method details directly; Phantom does not receive complete card numbers.
- Support and legal requests: contact details, messages, attachments you choose to send, relevant account or contract references, identity-verification information where needed, and our response.
- Website, download, and technical information: IP address, browser or device type, requested page or download, referrer, timestamps, access and security logs, app version, preferences and permission state, and metadata-only diagnostics or performance records.
We receive this information from you, your Mac when you grant a permission and use the related feature, services you connect, payment and infrastructure providers, and automatic service operations. Please do not provide information you are not authorized to use.
3. Purposes and legal bases
We process account, task, connection, action, plan, and support information to authenticate you, provide the features you request, carry out authorized actions, maintain task continuity, deliver files and responses, administer plans and usage, provide product support, and enforce the Terms of Service. Where the GDPR applies, the usual legal basis is performance of our contract or steps you request before entering it.
We process technical, security, usage, and limited content information as necessary to prevent abuse, protect accounts and infrastructure, diagnose failures, measure reliability and provider cost, enforce capacity limits, and establish or defend legal claims. The legal basis is our legitimate interest in operating a safe, reliable, and sustainable service, balanced against your rights.
We process transaction, tax, contract-confirmation, refund, sanctions, fraud, and rights-request records where necessary to comply with law. If we ask for consent for a separate optional purpose, you may withdraw it prospectively. A macOS permission is an important technical control, but is not by itself consent for every possible processing purpose.
We do not sell personal information, share it for cross-context behavioural advertising, or use task content for advertising. Phantom is not intended to make solely automated high-impact decisions about people. AI responses and actions can be inaccurate; the prohibited and high-risk uses in our Terms apply.
4. Processing and controls on your Mac
Phantom does not continuously watch your screen or maintain a passive inventory of running apps and window titles. Screen pixels, Accessibility information, running-app details, and visible-window details are collected on demand when a task needs them and only within the macOS permissions you grant. Granting Screen Recording or Accessibility permission enables the relevant capability; it does not cause continuous monitoring.
Current local storage is deliberately bounded:
- short-term conversation context stays in memory, is capped, and expires after about 30 minutes of inactivity or when Phantom quits;
- explicit task requests and compact task-result summaries are encrypted on your Mac, limited to 500 context items, and expire after 30 days;
- operator action-audit metadata is limited to 100 events and 30 days and records action category, policy, and outcome rather than screenshots, transcripts, typed text, or provider responses;
- operator and structured workflow records are each limited to 100 workflows and 30 days;
- API-usage and persistent performance logs contain metadata rather than task content and rotate at 1,000 records; their limit is record-based rather than time-based; and
- compact task-run state contains identifiers, statuses, and idempotency metadata rather than prompt content and is compacted regularly, but has no separate time-based expiry.
These local files are restricted to your macOS user account. The task-context database is encrypted; workflow, audit, task-state, usage, and performance files are not app-encrypted. Files you create in an export folder remain until you delete them.
Phantom’s Clear Local History control stops active work and removes its local conversation context, encrypted task context, workflow records, task journal, action audit, usage metadata, and persistent performance history. It does not delete exported files, connected-service data, your Phantom account, transaction records, provider records, or legally retained cloud data. Signing out also does not delete the account.
5. Providers, recipients, and international transfers
We send each provider only the information reasonably needed for its role:
- Google (authentication): Google OAuth provides the account identifier, name, email address, profile image, and verification information authorized for sign-in.
- Supabase: authentication, account, entitlement, checkout-consent, billing, usage, and legal-request records.
- Cloudflare: authenticated request routing, network security, queues, rate limiting, usage metering, and operational logs.
- OpenAI: prompts and the text, images, files, tool definitions, and task context needed to generate an AI response. Phantom requests non-persistent API processing where the API supports that setting.
- AssemblyAI: microphone audio, transcription controls, and key terms needed to produce live transcripts.
- ElevenLabs: response text, voice selection, and related controls needed to generate spoken output.
- Composio and connected services: connection identifiers and the inputs and results needed to read from or act in a service you choose to connect.
- Link and Stripe: checkout, seller, payment, tax, fraud, refund, dispute, and subscription administration. When Managed Payments is used, the Link entity identified at checkout or on the receipt is the merchant of record and acts as a separate controller for the transaction. Phantom receives identifiers, status, plan, consent, and limited customer or transaction details, not complete card numbers.
- Vercel and Vercel Blob: website and download hosting, including ordinary request and security information.
- Google (Gmail): hosting and delivery of messages sent to Phantom’s published support, privacy, and legal inbox, including the sender, recipients, subject, message content, attachments, and mail-security metadata.
Provider terms and privacy policies also apply. Depending on the activity, a provider may act for Phantom or as an independent controller. We may also disclose information to professional advisers, authorities, or transaction counterparties when reasonably necessary for legal compliance, safety, claims, or a reorganization.
Some recipients process information outside Switzerland, the United Kingdom, or the EEA, including in the United States. Where a transfer restriction applies, we rely on an applicable adequacy decision, approved contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism, together with supplementary measures where appropriate.
6. Website and cookies
The current website does not intentionally set cookies or use browser storage, analytics, advertising trackers, externally hosted fonts, or chat widgets, so it does not show a cookie banner. Vercel still receives ordinary request information when pages load. If we add non-essential tracking, we will update this policy and provide any consent or opt-out control required by law.
7. Cloud retention
The local periods are listed in section 4. Phantom’s product database is designed not to store the body of ordinary AI prompts, screenshots, or live audio after forwarding the request, although transient network copies and provider-side records can exist under provider settings, contracts, and law.
Account profile and entitlement data is retained while your account exists. After a verified deletion request, we aim to delete or de-identify account data within 30 days, except records that must be retained or are needed for security, claims, or another lawful purpose. Rate-limit buckets expire after about one day. Usage and metering records are generally retained for up to 24 months for billing reconciliation, capacity enforcement, fraud prevention, and disputes, unless they form part of a longer-retained transaction record.
Checkout consent, order, invoice, tax, refund, dispute, and contract records received by Phantom may be retained for up to 10 years where needed for Swiss recordkeeping, consumer-law evidence, or legal claims. Link and Stripe apply their own retention rules to transaction records they hold as merchant of record. Support and privacy-request correspondence is generally retained for up to three years after closure, unless a claim or law requires longer. Infrastructure security logs and backups follow provider and incident-response schedules and are removed or overwritten when no longer needed.
When a period ends, information is deleted or de-identified where feasible. A provider may retain information independently when it is the merchant of record, a connected service, or otherwise a separate controller.
8. Your controls and rights
You can manage Microphone, Screen Recording, and Accessibility permissions in macOS System Settings, choose an in-app Action Policy, disconnect connected accounts, clear Phantom’s local history, and delete exported files. Contact us to request account deletion; uninstalling or signing out is not an account-deletion request.
Depending on applicable law, you may ask to access, correct, delete, restrict, or receive a portable copy of personal information; object to processing based on legitimate interests; or withdraw consent prospectively. You may also ask for information about international-transfer safeguards. These rights can have legal exceptions, including for transaction records and legal claims.
Send a request to the contact below. We may ask for information necessary to verify identity and authority. We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
You may also complain to your local data-protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner.
9. Security and children
We use safeguards appropriate to the risk, including encrypted local task-context storage, owner-restricted local files, authenticated provider requests, scoped service connections, signed software updates, and access controls around account and billing records. No system is completely secure, and not every local file or external service has the same protection as the encrypted context database.
Phantom is not designed for anyone under 18. Contact us if you believe a child has provided personal information without legally valid authorization.
10. Changes and contact
We may update this policy when Phantom, its providers, or legal requirements change. We will preserve the version and effective date, publish the current version here, and provide additional notice when required.
Questions or privacy requests can be sent to hegerbenaja@gmail.com.
Operator and data controller: Benaja Raphael Heger · Haubenstrasse 32 · 3672 Oberdiessbach, Switzerland · hegerbenaja@gmail.com