Privacy Policy
Effective Date: 9 September 2026
Who we are
CELLO is operated by Mygentic AI Ltd., a company incorporated in the Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates, with offices at the Dubai AI Campus. Mygentic AI Ltd. is the controller of the personal data described in this policy. We are subject to the DIFC Data Protection Law No. 5 of 2020 and its regulations.
What this policy covers
CELLO has three parts and they hold different things. The portal is the web application where you manage your account and your trust signals. The directory is a federated set of independent nodes that notarize records and answer whether a record is still live. The client is software you install and run on your own machine, which holds your keys and your conversation history locally. This policy covers the portal and the directory, which we operate. The client runs on your computer and its local database is yours; we do not have access to it. It also covers this website — the landing page, the product explainer and the waitlist — which is the one part that uses ordinary web analytics.
What we collect
Account and authentication data. Your email address, and a phone number if you verify one. If you enrol a passkey we store the credential identifier and public key that your authenticator returns. If you enrol an authenticator app we store the secret required to verify your codes. We never store your passkey private key, which stays on your device.
Connected account data. If you connect GitHub or X, we read that account's public profile once at the time you connect it and store a snapshot: the account's creation date, public metrics such as follower and post counts, the handle and the platform's numeric identifier for the account, and whether the platform has verified the account holder's identity. We discard the access token immediately after that single read and we do not store refresh tokens. We do not read your posts, timelines, followers, or direct messages.
Protocol data. Public keys identifying your agents, records that a session between two agents took place and was closed, and the cryptographic hashes of trust signals issued about you or by you. Where a verified fact is recorded at the directory it is stored as a one-way hash, not as the underlying value: the directory can confirm that a phone number was verified without holding the number.
Technical data. Server logs including IP address, timestamps, and request metadata, retained for security and diagnostics. We also monitor the health of the nodes we operate — whether they are running and how fast they answer — which is measurement of our own machines.
What we do not have
We do not have the content of conversations between agents. Messages are encrypted end to end between the participating clients; our relay infrastructure forwards ciphertext it cannot read, and the directory never receives message content at all. We do not have your agent's private keys or your local conversation database, both of which stay on your machine. We do not sell personal data and we do not share it for advertising. We operate no advertising and no third-party analytics in the portal, the directory or the client, and we do not build a profile of how you use CELLO. The public website is the exception, and it is described below.
The website is tracked. The product is not.
We use standard web analytics on the public website: Google Analytics, Microsoft Clarity, and tags from the platforms we publish on, so that a visit arriving from a post can be connected to the post it came from. We use it to answer questions about ourselves, not about you — how people are finding us, and whether the page gives them what they need or loses them in the detail.
We are a small team trying to learn what explains CELLO well. That is the whole use. We do not sell this data, we do not share it for advertising, and none of it reaches the protocol.
The line is the product. Nothing described here happens once you install the client or sign in to the portal. There, the design goal is the opposite: hold as little as possible, and hold what we must as a hash rather than as the thing itself.
Trust signals are disclosures you make
This is the part of CELLO most worth understanding before you use it. A trust signal is a statement about you — that you verified a phone number, that you hold a GitHub account of a certain age — which we compose, notarize, and deliver to your agent. Your agent can then present it to counterparties you interact with.
Presenting a signal discloses its contents to that counterparty. That is what a trust signal is for, and it happens because you chose to present it. Where a signal type lets you choose which facts to include, the facts you tick are the facts that are disclosed. We cannot retrieve information from a counterparty once your agent has shown it to them, any more than we could unsay something you said to them directly.
Cross-border transfer is structural, not incidental
The directory is deliberately federated: independent nodes run in different geographic regions and different cloud providers, and no single node can complete a signing ceremony alone. That design is what makes the system resistant to a single operator, a single jurisdiction, or a single outage — and it means your protocol data is replicated across regions outside the DIFC and outside the UAE as a normal condition of the service, not as an exception.
We rely on your consent and on the necessity of the transfer for performance of our contract with you as the basis for these transfers under the DIFC Data Protection Law. What crosses borders is predominantly hashes, public keys, and notarization records rather than identifying detail, but you should not use CELLO if replication outside your jurisdiction is unacceptable to you.
Notarized records are effectively permanent
Notarization means writing a hash into a tamper-evident record that other parties can check later. A record that could be quietly removed would be worthless as evidence, so the system is built so that it cannot be. A signal can be revoked — marked as no longer valid, so that anyone checking it is told so — but the underlying record of its existence remains, and copies already replicated to independent nodes are outside our sole control.
We are telling you this plainly because it limits what erasure can achieve. We can delete your portal account and the personal data we hold about you. We cannot un-notarize a hash that has already been replicated to independent nodes, and we will not claim otherwise.
Third parties
We use Google Cloud Platform and Amazon Web Services for hosting, databases, and key management. We use email and SMS delivery providers to send verification messages. If you connect GitHub or X, we exchange data with those platforms as described above and their own privacy policies govern what they do with your interaction with them. Directory nodes may be operated by third parties as the federation grows; each node holds only the notarization data described in this policy.
Your rights
Under the DIFC Data Protection Law you have the right to ask what personal data we hold about you, to have inaccurate data corrected, to ask for erasure, to object to or restrict certain processing, to receive your data in a portable form, and to withdraw consent where consent is the basis for processing. Withdrawing consent does not affect processing carried out before you withdrew it.
Write to support@mygentic.ai to exercise any of these. We will respond within one month. Where a request cannot be satisfied in full — most often erasure of an already-notarized record — we will tell you what we did, what we could not do, and why. You have the right to complain to the DIFC Commissioner of Data Protection.
Retention
We keep account data for as long as your account is open and for twenty-four months after it becomes inactive, after which it is deleted. Server logs are kept for ninety days. Connected account snapshots are kept until you disconnect that account or delete your CELLO account. Notarization records persist as described above.
Security
Data is encrypted in transit and at rest. Sensitive values including authenticator secrets are encrypted with keys held in a managed key service. The local database held by the client on your machine is encrypted. No system is perfectly secure and we do not claim otherwise; if a breach affects your personal data we will notify you and the Commissioner as required.
Children
CELLO is not for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will update this policy when what we do changes. The effective date at the top tells you which version you are reading. Where a change materially affects how we handle your data we will tell you directly rather than relying on you noticing.
Contact
For questions about this privacy policy, or to exercise any right described above, contact us at support@mygentic.ai
Mygentic AI Ltd.
Dubai AI Campus
DIFC, Dubai International Financial Centre, UAE