Privacy Policy

Effective October 6, 2026 · Lowgear · lowgear.ai

This Privacy Policy explains how Lowgear (“Lowgear,” “we,” “us”) handles information when you use our website, desktop workbench, and related cloud services (together, the “Service”). Lowgear is a local-first ops workbench: much of your day-to-day work can stay on your device, while account, organization, and realtime collaboration features use our cloud infrastructure when you sign in.

1. Scope

This policy covers:

  • The marketing website at lowgear.ai and related pages
  • The Lowgear desktop application
  • Cloud services we operate for authentication, organization data, realtime rooms, usage metering, and AI-assisted features

It does not cover third-party products you connect through Lowgear (for example tools reached via MCP or other integrations). Those services have their own privacy policies.

2. Information we collect

Account and profile

When you create or sign in to an account, we may collect:

  • Email address
  • Name or display name
  • Authentication identifiers from our identity provider (for example Amazon Cognito)
  • Profile details provided by a sign-in provider you choose (for example Google: email, basic profile)

Organization and workspace data

If you use Lowgear with a team, we may store organization membership, roles, board or “Gears” status information, room participation, and other workspace metadata needed to show who is on what and to sync collaboration features.

Content you create or send through the Service

Depending on how you use Lowgear, this may include:

  • Messages and prompts you send in workbench chat
  • Files, snippets, or context you attach or reference in the app
  • Configuration for connected tools your organization enables

Local-first design means a substantial amount of work product may remain on your device unless you sync it, share it in a room, or send it to a cloud or AI feature. You and your organization control what you put into the Service.

Usage and operational data

We may collect:

  • Service usage needed for metering, quotas, billing readiness, and abuse prevention (for example AI token usage tied to your account)
  • Technical logs such as IP address, device or app version, timestamps, error reports, and diagnostic events
  • Basic website analytics or server logs when you visit lowgear.ai (pages requested, referrer, user agent)

Communications

If you email us (for example at hello@lowgear.ai), we keep the content of that correspondence to respond and improve the Service.

3. How we use information

We use information to:

  • Provide, operate, and secure the Service
  • Authenticate users and manage organization access
  • Enable realtime collaboration (for example WebSocket rooms)
  • Run AI-assisted features you invoke
  • Measure usage, prevent abuse, and troubleshoot issues
  • Respond to support requests and communicate Service-related notices
  • Improve product quality and reliability
  • Comply with law and enforce our Terms of Service

We do not sell your personal information.

4. AI features

When you use AI-assisted features in Lowgear, the prompts, context, and related outputs you submit may be processed by infrastructure providers we use (for example Amazon Bedrock or other model providers we configure) to generate a response. Do not submit secrets, regulated data, or others’ confidential information unless your organization has approved that use and the provider terms allow it.

We use AI processing to provide the feature you requested, to meter usage, and to maintain security and reliability. We do not use your prompts to train public foundation models for unrelated third parties, except as a provider’s own terms may describe for their platform (review those terms for your deployment).

5. Local-first and device data

Lowgear is designed so meaningful work can stay on your machine. Data that remains only on your device is under your control and is not collected by us unless you transmit it through a cloud feature (sign-in, sync, rooms, AI, support uploads, and similar). You are responsible for device security, backups, and organizational policies for local data.

6. How we share information

We may share information with:

  • Service providers that help us run Lowgear (for example cloud hosting, authentication, logging, and AI inference under Amazon Web Services or similar vendors), under contractual obligations to protect data
  • Sign-in providers you choose (for example Google), as needed to complete authentication
  • Organization admins in your workspace, who may see membership, usage, and workspace content consistent with your plan and settings
  • Authorities when required by law, or to protect the rights, safety, and security of Lowgear, our users, or the public
  • Successors in a merger, acquisition, or asset transfer, with notice where required

Connected third-party tools (including MCP servers your org enables) receive only what you or your organization authorize through that connection.

7. Cookies and similar technologies

The marketing site is primarily static. We may use essential cookies or local storage required for security, preferences, or hosting. We do not use the site to run invasive cross-site advertising trackers. If we add optional analytics later, we will update this policy and, where required, provide a choice.

8. Retention

We keep account, organization, and operational data for as long as your account or organization remains active and as needed to provide the Service. We may retain logs and records for security, dispute resolution, and legal compliance for a longer period. When you request deletion, we delete or anonymize personal data we control except where we must retain it (for example legal obligations or abuse prevention).

9. Security

We use industry-standard measures appropriate to a cloud-connected desktop product, including transport encryption, authenticated APIs, and access controls. No method of transmission or storage is perfectly secure. You are responsible for protecting your devices, credentials, and local workspace data.

10. International transfers

We currently operate infrastructure in the United States (including AWS regions such as us-west-2). If you access the Service from elsewhere, your information may be processed in the United States or other countries where we or our providers operate.

11. Your choices and rights

Depending on where you live, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Request deletion of your account and personal data
  • Object to or restrict certain processing
  • Export a copy of data you provided, where applicable

To make a request, email privacy@lowgear.ai or hello@lowgear.ai. We may need to verify your identity. Organization-owned accounts may require an admin to approve certain deletions.

You can disconnect Google or other sign-in providers through that provider’s account settings, and you can stop using the Service at any time.

12. Children’s privacy

Lowgear is a workplace tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

13. Organization customers

If you use Lowgear through an employer or customer organization, that organization may control your account, workspace content, and retention settings. In those cases, please contact your organization’s admin for access or deletion requests that they control. This policy describes how Lowgear processes data as a provider; your organization’s own policies may also apply.

14. Changes

We may update this Privacy Policy from time to time. We will change the effective date above and, for material changes, provide additional notice (for example by email or in the product) when appropriate. Continued use of the Service after an update means you accept the revised policy.

15. Contact

Privacy questions: privacy@lowgear.ai
General contact: hello@lowgear.ai