Gunzino OpenResponses

Privacy Policy

Last updated: September 29, 2026

OpenResponses runs entirely on your device until you decide to contact an external service. The app's primary network traffic is directly to OpenAI when you send a live request, plus any optional service integrations (such as Notion) that you explicitly authorize.

1. What Stays on Your Device

  • API Credentials: Your OpenAI API key and any optional integration tokens are saved locally in the iOS Keychain. They never leave your device except to authenticate directly with the corresponding service you configured.
  • Conversation Data: Chat message history, system prompts, and tool execution results are stored locally on your device. You can delete any individual conversation thread or uninstall the app to erase this data.
  • File Processing: Attachments are processed in memory, optionally converted on-device, and sent directly to the selected service. The file picker keeps a copy on your device, and files uploaded to OpenAI stay in your OpenAI account.

2. In-App Permission & Disclosures

  • Before making your first live AI request, OpenResponses shows an in-app disclosure detailing what data is sent to OpenAI and asks for your explicit permission.
  • No request data is transmitted to OpenAI until you tap Allow & Send. Voice mode and File Manager uploads are not covered by this prompt.
  • The "Explore Demo" feature operates fully offline and makes no external API calls.

3. Data Transmitted on User Request

  • OpenAI Responses API: User prompts, parameters, optional attachments, and request-related tool inputs/outputs are sent directly to OpenAI to generate a reply. This data is processed under OpenAI's terms.
  • Computer Use (Optional): Browser automation runs in an off-screen browser inside the app.
  • Connected Integrations: If you enable integrations like Notion, Slack, or GitHub, the assistant forwards only the prompts and parameters required for the specific action you initiated. Those services apply their own privacy policies.
  • New Models (automatic, from version 2.8): When your key's model list includes a model the app does not know yet, the app reads that model's public page on developers.openai.com, at most once a week, to learn its settings. The request carries no personal data, chat content, or API key. Explore Demo skips it.
  • Your Account's Models (automatic, from version 2.8): When an OpenAI API key is saved, the app asks OpenAI once per launch which models that key can use. The request sends only the API key.
  • Provider Sign-In Page (from version 2.8): monday.com, Airtable, Intercom and Vercel return their sign-in result to a static page at gunzino.me/openresponses/oauth/callback.html, which passes it straight to the app. The page loads nothing else and sends nothing.

4. Requested Device Permissions

  • Photo Library & Files: Allows you to attach screenshots, PDFs, documents, and other files to chat sessions.
  • Calendars, Reminders, & Contacts: Enables the assistant to create or modify items, once Apple integrations are on in Settings; individual actions are not confirmed.
  • Local Network: Not used.
  • Microphone & Location: The app asks for microphone access for voice input and Realtime conversations with OpenAI. It does not request speech recognition or location access.

5. Computer Use Safety Guardrails

  • Computer-use steps run without a prompt unless OpenAI flags a safety check; then the app asks you.
  • When the app asks and you decline, the automation chain stops immediately. The app never runs background commands without an active, visible audit trail in chat.

6. Analytics & Crash Data

  • Usage Metrics: Usage events stay in a log on your device and are not sent anywhere.
  • Diagnostics: Crash reports come from Apple's opt-in developer feedback system and do not contain chat transcripts or API keys.

7. Retention & Deletion

  • You can remove credentials or disconnect integrations in Settings at any time.
  • Delete messages from the chat menu, delete conversations one at a time, or reset first-send consent in Settings.
  • Uninstalling the app deletes all sandboxed files, database conversations, and Keychain items.

8. Contact

If you have privacy questions, file an issue at the GitHub Issues Tracker or email the developer at gunnarguy@me.com.