SlyOS
Privacy Policy
Last updated: June 2026
The short version: SlyOS runs on your phone and stores your messages, memory,
and keys locally on your device. Belto does not run a server that collects your personal data — but
SlyOS is not fully on-device: when you use AI, email, backup, voice-cloning, or the bot, the relevant data
is sent to the third-party providers whose keys/accounts you connect (listed in section 5), under your own
keys. SlyOS also sends anonymous usage counts to Belto's analytics backend (section 6).
1. Who we are
SlyOS is an Android launcher application made by Belto ("we", "us"). This policy explains what happens
to your data when you use it. Questions: support@belto.world.
2. Data stored on your device
SlyOS keeps your imported chats, contacts, learned facts, voice profile, notes, checklist, drafts, papers,
settings, and your API keys in local storage on your phone. This data is not transmitted to Belto. Clearing
the app's data or uninstalling it removes this data; you can also reset memory inside the app.
3. Data sent to AI model providers
To generate replies, summaries, papers, and other AI output, SlyOS sends the relevant prompt and context
(which may include your messages, memory, and profile) to whichever model provider you've added a key for,
using your own API key. Depending on what you connect, that can be
Anthropic (Claude), Google (Gemini), OpenAI (GPT), Groq, Cerebras, Mistral, or GitHub Models.
Each request is governed by that provider's terms and privacy policy. We do not receive or retain a copy of
those requests. If you download the on-device model/embedder, that processing stays on your phone.
4. Permissions we use, and why
- Notification access — to read incoming messages and reply to them on your behalf.
- Accessibility / "Total Recall" (optional) — to read on-screen text into your private,
on-device memory and to let the screen agent operate apps for you. It never reads or stores password
contents, but it can type into password fields to complete logins/sign-ups you
initiate. Off by default and gated by toggles.
- One-time codes / 2FA (opt-in, OFF by default) — if you turn on "Read 2FA codes to
auto-fill logins," SlyOS reads one-time verification codes from your notifications and Gmail so the screen
agent can get past "enter the code" screens. Nothing reads codes unless you enable this.
- SMS, Contacts, Calendar, Camera, Microphone, Location — to send texts, find people,
check availability, answer visual questions, take voice input, and (if you enable it) share live location.
Each is requested only when used.
- Face recognition (opt-in, biometric) — if you choose to "teach" SlyOS a person, it
creates a face template so it can recognize them in your photos. This is biometric data
(subject to laws like BIPA and GDPR). It is processed and stored only on your device,
never uploaded, is entirely opt-in (you teach each person), and is deleted when you remove that person or
clear app data. SlyOS does not identify strangers — only people you explicitly add.
All permissions are granted by you and can be revoked in Android settings at any time.
5. Third-party services & what is sent
If you choose to use them, SlyOS connects to the services below using your accounts/keys. Each is
optional and governed by that provider's own terms and privacy policy. SlyOS does not add advertising or
third-party trackers.
- AI models (Anthropic, Google Gemini, OpenAI, Groq, Cerebras, Mistral, GitHub Models) —
prompts + relevant context, under your key.
- Google — Gmail (reading/ingesting and sending email on your behalf), Google Drive
(encrypted-at-rest brain backups you initiate), Gemini (above). Under your Google account.
- OpenAI / Google — image generation & semantic-memory embeddings, under your key.
- ElevenLabs — if you enable cloned voice, your voice sample + text are sent to synthesize
speech, under your key.
- Telegram — if you connect a bot, messages to/from your bot pass through Telegram's Bot API.
- Supabase — the app store's review/ratings wall and anonymous usage analytics (see section 6)
are stored in Belto's Supabase project.
- Live location (optional): if you enable location sharing, your device location is served
through a live-location endpoint so the people you share with can see it. Off unless you turn it on.
- Website hosting (Netlify / Vercel): when the agent builds and "ships" a website for you,
it publishes it using your own Netlify or Vercel token, which you add in Settings, so the site
lives in your account and stays yours. Anything you publish this way is served publicly on the internet.
- Others (optional): Zenodo (publishing papers), X/Twitter (posting), Finnhub (market data),
AudD (song identification).
5a. Google user data — Limited Use
SlyOS's use and transfer of information received from Google APIs to any other app adheres to the
Google API Services User Data Policy, including the
Limited Use requirements.
Concretely, for the Google scopes SlyOS requests — Gmail (reading your recent mail so it can
draft replies, and sending mail you have approved), Calendar events, Docs, Sheets, Slides, and
Drive files this app itself creates:
- Google user data is used only to provide the features you asked for, and is
processed on your device or sent to the AI provider you configured to answer your request.
- It is never sold, and never transferred to anyone except as needed to provide
those features, to comply with the law, or as part of a merger or acquisition.
- It is never used for advertising, ad targeting, or personalisation, and SlyOS
contains no advertising or third-party tracking.
- Humans do not read your Google user data, except with your explicit consent
for a support issue you raised, where required by law, or on aggregated anonymised data for
security and abuse prevention.
- It is not used to train generalised AI or machine-learning models. Your mail
and calendar shape SlyOS's answers to you on your own device; they do not train anyone's model.
Revoke SlyOS's access to your Google account at any time at
myaccount.google.com/permissions,
or by tapping Disconnect inside SlyOS.
6. Anonymous usage analytics
To understand what SlyOS is used for and improve it, the app sends anonymous event counts
(e.g. "a Home query happened", the general category such as "remember" or "schedule", feature used, success/
failure) to Belto's Supabase backend. Events are keyed to a random per-install ID and, if you're signed into
a SlyOS account, your account email — never the content of your messages. You can turn this off in the app.
7. The website
This site is static and does not set tracking cookies. Our host (GitHub Pages) may log basic technical
request data (such as IP and user-agent) as part of serving the page and file, per their own policies.
8. Children
SlyOS is not directed to children and is intended for users 16 and older.
9. Your control
You control your data: reset the memory in-app, remove your keys, clear app storage, turn off analytics, or
uninstall. Because the data lives on your device, you hold and manage it directly.
10. Changes
We may update this policy; the "last updated" date will change. Continued use after an update means you accept
the revised policy.