Help you can understand.

Effective 2026-09-04. This Trust Charter is a plain-language summary for iPhone, macOS, and Windows. The formal Privacy Policy controls if this summary differs.

You choose what to share.

Operating-system screen access, feature enablement, AI-processing consent, Task acceptance, Step approval, and outbound action authority are different decisions. Permission to see a screen is not permission to send a message or carry out a task.

Use only accounts and content you are allowed to access. An image of the current conversation on your screen may include another person’s information. You are responsible for any notice or consent their content requires.

Context for the reply you request.

In iPhone Draft mode, a fresh image of the current conversation on your screen and selected personalization can be sent through Krewva to a third-party AI service after AI-processing consent. You review three drafts and choose one to insert. Krewva never sends the iPhone reply for you. ABC mode sends no conversation data to an AI service.

On desktop, capture is user-triggered and limited to the active top-level window. It is not continuous monitoring and never falls back to a full-desktop capture. Denied, revoked, protected, or changed targets fail closed.

Three desktop screen flows.

  • Draft a Reply: after enablement and AI-processing consent, a fresh image of the active window may go through Krewva to a third-party AI service for reviewable suggestions. The capture itself never sends.
  • Do a Task local OCR: semantic text is tried first. Where needed, bounded local OCR keeps raw pixels on the device. Selected derived text may support a Task after your choice.
  • Do a Task visual discovery: a separate enabled and AI-consented upload to a third-party AI service proposes Task candidates only. Task acceptance and Step approval remain separate.

Local context and online processing are different.

iPhone history, writing samples, Contacts, Objectives, and AI Impressions can be stored locally. Selected context may still be sent for a permitted draft. Voice audio goes directly to a transcription service, not to the Krewva backend. Ordinary Voice Input is dictation and requires microphone permission. In the updated iPhone Intent preview, available depending on your build, an image of the current conversation on your screen and your transcribed meaning are used together to generate one message for insertion into the active app’s text box. It then returns to Voice / Intent; you review, edit, and send. Intent is one-off, not a global or Contact instruction, and separate from the three-suggestion Draft. One-off use does not mean zero data or provider retention.

Raw image pixels are request-scoped and excluded from Krewva account history, ordinary logs, Sentry, and support bundles. Permitted derivatives such as drafts, review evidence, selected Task evidence, plans, outcomes, audit facts, and a one-way fingerprint can have separate lifecycles.

Providers have their own retention rules.

Third-party AI processing can involve default abuse-monitoring logs kept for up to 30 days, with longer retention where legally required or reasonably necessary for safety. This is not an absolute maximum. Krewva does not promise zero provider retention.

Cloudflare handles website hosting, waitlist processing, KV storage, and rate limiting. The sub-processors list names the formal operational providers. Selected request context is shared for the feature you choose.

Keep the controls specific.

On iPhone, Reply History has 7-day, 30-day, 90-day, or Forever retention choices. The writing-sample window holds up to 20 recent samples. You can pause learning and delete local samples, Contacts, or memory. Pausing learning does not erase existing records.

Contacts and Objectives are not automatically age-pruned. Changing an Objective or its pace can clear the associated AI Impression. Clearing local personalization is not account deletion, and it does not erase messages from other apps.

Desktop message bodies, cards, and voice samples have 30/90/365-day plan-based inactivity windows. Those windows do not apply to raw images or local iPhone Contacts. Consent-gated redacted improvement records and audit records have separate lifecycles.

You can ask for a change.

Use available app controls to withdraw permissions, change local context, or request account deletion. Account deletion has a 30-day cancelable grace period before the implemented purge. Third-party revocation is best effort. Legal, security, billing, and separately governed records may need to remain for their required lifecycle.

Subscription cancellation is separate. Read Your data. Your choices. for access, correction, export, deletion, and complaint options. Contact founders@krewva.com if the app does not cover your request.

If a permission check fails.

The relevant operation fails closed. Krewva does not silently substitute a broader capture or new permission. Retry after the feature can safely use a permitted target. You can disable a feature or contact support.