Gunzino OpenCone

Privacy Policy

Last updated: September 27, 2026

OpenCone is a cloud-hybrid retrieval client that parses documents locally, sends chunk text to OpenAI and Pinecone for the retrieval path, and uses the OpenAI Responses API for grounded answers. This policy describes those data flows so you can understand the privacy boundary clearly.

1. On-Device Processing

  • Local Sandboxing: Source documents you import (PDFs and text files) are copied into the secure application sandbox for indexing. Images you import are copied there too.
  • Local Text Extraction: Text extraction runs locally on your device using PDFKit and native Apple text utilities. Apple's Vision OCR reads the text in images, also on the device.
  • Background Threading: Embedding generation queues work on a background thread. Local diagnostic logs record processing status, file names and paths, and conversation IDs.
  • Bookmark Storage: Bookmarks to sandbox copies are kept in memory, not in the Keychain.

2. Data Sent Off Device

To perform its core functions, OpenCone transmits data directly from your device to the following services using secure HTTPS connections. No data is routed through or stored on developer-owned servers.

Destination Data Sent Purpose Notes
OpenAI Responses API Conversation history (user prompt + retrieved context snippets) Generate natural-language answers using RAG Transmitted over HTTPS. OpenCone may retain local answer history until you clear it, but no developer-owned server is involved in the request path.
OpenAI Embeddings API Chunked text generated from your documents Produce high-dimensional vector representations Only the specific text chunks being embedded are transmitted.
Pinecone Vector DB Embedding vectors and metadata for each chunk: its full text, a 200-character preview, the document ID and file name, and the file's path on your iPhone Similarity search and retrieval Encrypted in transit. Each record keeps the chunk's full text in your Pinecone index.
Apple Speech (voice input) Your recorded audio, only when you use voice input Turn what you say into your question The app allows Apple's servers to transcribe, so the audio may leave your device.

3. Keys & Authentication

  • User-Provided Credentials: You supply your own OpenAI and Pinecone API keys via the in-app onboarding flow.
  • Keychain Storage: Stored credentials are saved in the iOS Keychain and are never shared with the developer or third parties.
  • Build Guard: Release builds must not include default API keys; without your keys, the app opens setup.

4. Retention & Deletion

  • Document Removal: Removing a document in OpenCone deletes the sandbox copy and requests deletion of associated vectors from your Pinecone index.
  • Clearing History: Clear Conversation History removes the saved OpenAI conversation ID. Requests to OpenAI remain direct API calls rather than developer-proxied state.
  • Application Reset: Settings → Data & Privacy → Reset All Data removes API keys, preferences, the saved conversation ID and bookmark consent. It does not delete imported file copies.

5. Analytics & Tracking

  • OpenCone does not include or utilize third-party analytics, tracking SDKs, or advertising libraries.
  • Only local diagnostic logs (viewable in the Logs tab) are retained on-device for user troubleshooting.
  • In-app Disclosures: Before your first import, OpenCone asks you to allow file access.
  • Privacy Reset: Settings → Data & Privacy → Reset All Data removes API keys, preferences, the saved conversation ID and bookmark consent.

7. Contact

For privacy questions or data deletion requests, contact support at: gunnarguy@me.com or gunnarguy@me.com.