Catch
English简体中文

Data and privacy

Updated September 29, 2026

This notice describes how the current Catch app and this connection service handle information. You can use local imports only, or connect external accounts individually.

What Catch reads

Google connectors request read-only access for the source you choose: Gmail messages, Drive / Docs files, your primary calendar, or contacts. Account identifiers and email addresses are also used to verify identity. Other connectors read their respective authorized sources. The app lists each connection's current import scope and limits. Content import starts only after Confirm.

Only if you allow it in the assistant, Catch separately requests permission to send Gmail replies (gmail.send), Outlook replies (Mail.Send) or add Google Calendar events (calendar.events). These grants are kept apart from the read-only connections, are not used to read content, and are used only when you confirm one specific reply or event; recipients are taken from the original message. You can revoke them in the app at any time.

Granted permissions may be broader than the current import scope. For example, Drive read-only permission covers files your account can access, while the client imports only supported types. Review both the provider's authorization page and Catch's import description.

Where information is processed and stored

LocationStorage and processing
Your computerImported content, search indexes, summaries, chats, confirmed memories, suggestions, and the context folder. During sync, content travels directly from the provider to your computer. If you separately enable the Catch cloud model, analysis excerpts pass through its model service.
Connection serviceProvider authorization credentials, account identifiers, email or workspace names, granted scopes, and connection times. During Slack channel selection, channel names and membership are temporarily stored; message content is not read.
Analysis modelRule mode does not call a model. Local models process information on your computer. If you configure a cloud or other remote model, relevant excerpts, questions, personal settings, and memories are sent to that configured service as needed for the feature.
Paired phoneAccesses desktop information through pairing. Offline quick notes stay on the phone until they are synced to their assigned desktop workspace after reconnection.

Optional Catch cloud model

Only after operator configuration and your explicit consent in Settings does Catch forward questions, relevant source excerpts, profile settings and memories through the account service to the displayed model provider. Background context analysis also sends excerpts. Changes to the provider, endpoint or model require consent again. Catch does not persist these request bodies or answers on the server; it stores daily request counts per account for limits. The model provider has its own retention policy. Signing out on the desktop stops new managed-model requests.

Use and sharing

Information is used for your search, context analysis, personal memories, and action suggestions. Catch does not use connected information for advertising, sell it, or use it to train general-purpose models. Your selected remote model service's retention and use of requests depend on that service's policies and account settings; this is not entirely local processing.

Use and transfer of information received from Google APIs, including derived data, comply with the Google API Services User Data Policy, including its Limited Use requirements.

Retention and security boundaries

Authorization sessions expire after 10 minutes. While running, the service removes expired sessions approximately every minute. Confirmed connection credentials are retained until a successful disconnect. Credentials are encrypted in the connection database; the service must decrypt them to refresh authorization, so this is not end-to-end encryption.

The local content database and exported context files are not encrypted in full. Protect your computer with operating-system account permissions and disk encryption. Servers and reverse proxies may process network metadata needed for connections, such as IP addresses and request paths. Operators should avoid logging callback parameters, credentials, or source content.

Disconnecting, deleting, and revoking access

Disconnecting in the app first removes the corresponding server-side authorization record. By default, it also removes that source's local information and related derived records. If you choose to retain local information, it remains searchable. A network failure may leave disconnection incomplete; the client will prompt you to retry.

Disconnecting Catch does not automatically revoke the entire app authorization at the provider. Remove Catch in the provider's third-party app settings, such as Google's. You can forget individual records in Catch without affecting original cloud information. Separately exported files, device backups, and operator backups must be deleted separately. Restoring an older backup may restore its older records.

View instructions and contact the operator.