Calmbu
Back to Calmbu
Local-first privacy

Privacy Policy

Calmbu Pty Ltd operates Calmbu from Melbourne, Victoria, Australia. The Windows product protects supported local AI agent work in a destination you choose. Your supported agent sessions, prompts, instructions, code, workspace details, and backup contents are not uploaded to Calmbu for backup storage.

Calmbu Pty Ltd Last updated August 1, 2026
01

Who we are

Calmbu is provided by Calmbu Pty Ltd from Melbourne, Victoria, Australia. References to Calmbu, we, us, and our mean Calmbu Pty Ltd unless the context says otherwise.

Public self-service documentation is available through the Calmbu support site. General product help is provided by an AI support agent inside an authenticated customer account. Billing enquiries use [email protected], and urgent privacy requests use [email protected]. Please do not send private agent sessions, code, backup archives, recovery codes, licence keys, passwords, or secrets through any channel.

02

What the app protects

The Windows product protects supported local AI agent state such as sessions, history, instructions, settings, skills, memory, and other user-created workspace context. Supported providers and current coverage are shown in the app and website. Known credentials, private-key material, and unsafe or disposable runtime data are excluded from standard protection.

Backups are created by the local Calmbu installation and stored in the destination you choose. The same verified recovery point may be used for safe-folder recovery or supported migration to a new Windows PC. If you choose an external drive, synced folder, network location, or third-party storage provider, that provider's privacy, security, and data-location terms also apply.

03

Information Calmbu does not upload

  • Supported agent sessions, prompts, instructions, memory, or generated responses
  • Code, worktree contents, or backup contents
  • Filenames, folder paths, repository names, usernames, or other sensitive workspace metadata
  • The measured logical size of your supported local AI workspace
  • Recovery codes or private recovery material
  • Credential values, licence keys stored inside backups, or private keys
04

Local security and recovery data

Backup data is protected with AES-256-GCM authenticated encryption before destination writes. Local unlock material uses operating-system security facilities where practical. A machine-independent recovery code is shown to you during setup and is not escrowed by Calmbu Pty Ltd.

Local operational logs contain coarse events and privacy-safe error codes. They are designed not to include workspace content, sensitive workspace details, recovery codes, credentials, or private configuration values.

05

Safety Check and capacity measurement

The CalmBU Safety Check and plan-capacity measurement run locally on your computer. They inspect the supported protection scope after required exclusions and calculate combined logical bytes before compression, encryption, deduplication, or retention. Paths, filenames, workspace contents, and the measured byte total are not sent to Calmbu's licensing service, Paddle, or Keygen.

The result is used on the device to recommend Starter coverage up to and including 1,073,741,824 logical bytes, Standard coverage through 26,843,545,600 logical bytes, or larger-workspace guidance. You may deliberately provide relevant information to support, but Calmbu does not transmit the local measurement automatically.

06

Licence and billing data

Paddle is Calmbu's merchant of record and processes checkout, contact, billing, tax, invoice, receipt, refund, chargeback, fraud-prevention, and payment information under Paddle's own terms and privacy policy. Calmbu receives the subscription and customer references needed to provide and administer your purchase.

Keygen provides server-side licence issuance and device-seat enforcement. Licence validation may use a licence key, privacy-safe install or device identifier, app version, protection level, capacity band, seat quantity, and activation status. Calmbu does not send agent content, measured workspace size, sensitive workspace details, backup contents, or diagnostic summaries to Paddle or Keygen.

07

Website, downloads, and infrastructure

The website does not include advertising trackers. Hosting and security providers may process ordinary technical request data such as IP address, user agent, requested URL, referrer, timestamp, and error details for delivery, abuse prevention, reliability, and security.

Calmbu Pty Ltd intends to host controlled website and service infrastructure in Australia where practical. Public installers, checksums, static assets, and release files may be distributed globally through a content delivery network. Private Calmbu backup contents are not distributed through that public download network.

08

Privacy-safe campaign attribution

When you follow an approved Calmbu campaign link, the website may retain allowlisted campaign labels and a random opaque attribution identifier in first-party browser storage. If you later choose a paid plan, the signed identifier and campaign labels may pass through Paddle Checkout to Calmbu's licensing service solely to measure non-identifying aggregate purchase and activation results.

Campaign attribution does not include your email, name, IP address, device fingerprint, readable licence, workspace, prompts, code, backup contents, or recovery data. Calmbu does not send customer or conversion data to advertising platforms under this initial measurement design. Raw attribution is retained for no more than 90 days and is then reduced to aggregate campaign totals. Missing or invalid attribution never blocks a download, purchase, activation, backup, or recovery.

09

Release alerts

If you ask to hear when Calmbu for Windows, macOS, or both becomes publicly available, we collect your email address, optional first name, selected platform, form source, consent record, and delivery reference. We use those details only for the release alert you requested. Joining does not promise a release date.

At this stage, the request is delivered to Calmbu through our server-side SendGrid service and retained in our protected business email rather than a separate waitlist database. The form is rate limited and includes spam protection. You can withdraw before release or opt out by replying to the release email.

10

Support and diagnostics

If you use the authenticated AI support agent, send billing email, submit a privacy request, or provide optional product feedback, Calmbu may process your account reference, message, purchase reference, app version, licence status, and a diagnostic summary you choose to provide. Review anything you send and remove private material that is not needed.

We use support and contact information to provide the requested route, investigate problems, improve safety, administer licences, and meet legal obligations. We do not use support messages to train AI systems without a separate explicit consent process. The AI support provider, retention, region, and account integration will be identified before that feature is enabled.

11

Retention, rights, and choices

Local backups remain in your chosen destination until you delete them or Calmbu retention settings remove them. Calmbu Pty Ltd cannot access or delete a local backup that was never uploaded to us.

We retain website, licence, purchase, interest-list, support, and security records only as long as needed for their purpose, security, billing, tax, accounting, fraud prevention, dispute handling, and legal compliance.

You may request access to, correction of, or deletion of personal information we hold, subject to legal, billing, security, and fraud-prevention limits. You can also uninstall the app, change backup destinations, delete backups you control, and unsubscribe from optional communications.

12

Changes and contact

We may update this policy as Calmbu changes. Material changes will be reflected by updating this page and, where appropriate, by notice through the app, checkout, or support channels.

Use [email protected] for urgent privacy requests or complaints. Use [email protected] only for billing matters; its response target is within five business days. General product help is available through the authenticated AI support agent, not a public support email.