Private beta · Updated August 21, 2026
Privacy notice
IntentX keeps browser sessions and credentials on your device while sending selected task context through its authenticated backend when you request AI-backed work.
Data kept on your device
Browser cookies and sessions, task history, evidence, workflows, approvals, bookmarks, imported browser summaries, and preferences stay in the desktop app. Saved or imported HTTPS credentials use system Keychain-backed encryption. A password CSV remains where you exported it until you delete that source file.
AI-backed requests
When you request AI-backed work, IntentX may send the request and task-selected text, HTML, screenshots, audio, URLs, conversation context, or structured data through the authenticated IntentX backend to the configured AI processor. Cookies, passwords, provider credentials, and API tokens are excluded.
Google Workspace data
If you connect Google Workspace, you choose whether to authorize Calendar, Drive, or both. Calendar access lets IntentX create events and invite guests only after you review and approve the proposed invitation. Drive access is read-only and lets IntentX search file names and contents, read file metadata and sharing permissions, and read or export file contents when you ask it to work with those files. IntentX does not use Drive access to edit, upload, move, share, or delete files.
Google Workspace OAuth tokens are stored in the encrypted local profile on your device. Google Workspace data selected for an AI-backed task may be sent through the authenticated IntentX backend to the configured AI processor only to provide the user-facing result you requested. Disconnecting Google Workspace removes the local OAuth record from this device; you can separately revoke the grant from your Google Account permissions.
IntentX's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Cloud billing
If you connect Google Cloud Billing, authorization happens through Google OAuth outside the embedded browser. The resulting OAuth record is stored in the encrypted local profile. IntentX uses only reviewed read-only BigQuery metadata and query tools, dry-runs billing queries before execution, and does not enable APIs, create billing exports, edit IAM, apply deny policies, or change cloud resources.
Billing-export metadata and query results may be included in the AI-backed request context when you ask IntentX to diagnose cloud spend. Disconnecting Google Cloud removes the local OAuth record from this device; you can revoke the Google grant separately from Google Account permissions.
Beta account data
An early-access request stores your normalized email address,
request source, request count, status, and timestamps. When you
submit the disclosed form, the backend also sends a
beta_access_requested event to Mixpanel. It uses your
normalized email as the event identity and profile email, together
with the request source, new-or-repeat status, environment, and
latest request time, so we can create and manage the beta-invite
cohort. The requester's validated IP may be used for approximate
country and region in Mixpanel.
If you later enroll, the backend also stores user and organization identifiers, device information, credential hashes, and bounded operational metadata without request bodies. After you connect Google in the desktop app, the signed-in email shown by that browser session replaces the installation's generated placeholder address. A business email domain may also become the display-only organization name; common personal email providers use “Personal workspace.”
Workflow sharing
Workflow and training submissions are not automatic. If you explicitly submit a workflow or verified example, the backend may retain its request text, domain, URLs, sanitized steps and values, and verification summary for review. Approved workflows may be shared with other users.
Diagnostics and analytics
Before you make an analytics choice, Mixpanel receives basic totals for controlled page visits, invite actions, and installer download clicks. These baseline events use a fresh identifier every time and do not use browser persistence, profiles, IP geolocation, or device properties. They include an allowlisted relative page path, a coarse referrer category, sanitized campaign labels, and bounded installer details. They cannot measure unique or returning visitors.
If you allow optional analytics, Mixpanel may persist a pseudonymous browser identity, measure journeys and returning visits, update a limited analytics profile, and derive approximate country from the transient browser IP. Turning optional analytics off removes its persistent browser state and returns measurement to basic totals. Neither tier uses autocapture or session replay or sends page contents, form entries, full URLs, raw query strings, private-beta tokens, page titles, external referrer URLs, submitted email addresses, or names. These website events are separate from the disclosed beta-access request event described above. You can change the optional choice below.
The desktop app does not automatically upload crash reports. Its optional Mixpanel product analytics is also off by default and starts only after you explicitly turn it on in Preferences. When enabled, it records successful sign-up plus task start, outcome, and completion events with bounded action/capability labels, entry surface, application label, base registrable domain, execution source, outcome category, duration, verification presence, app version, release channel, and pseudonymous account/device identifiers, a verified account email when available, and approximate country and region. For example, a Jira task records atlassian.net, not a tenant subdomain or page URL. Prompts, task contents, full URLs, paths, query strings, tenant subdomains, page titles, email addresses other than the disclosed account/beta email, names, credentials, cookies, screenshots, audio, page evidence, provider results, payment data, local file paths, and private-session tasks are excluded. A diagnostic export is created only when you request it and excludes task contents, visited URLs, credentials, cookies, and page evidence.
Deletion
Delete local data clears local browser and application state. When connected, IntentX first asks the backend to delete the beta account and associated records. If that network request fails, local deletion still proceeds; contact support to complete server deletion. Local or account deletion stops future analytics but does not by itself prove deletion of events already ingested by Mixpanel; use the privacy contact below to request that deletion.
Contact
For privacy questions or deletion help, email support@intentx.run. Do not send passwords, tokens, cookies, or private page contents.