Legal

Privacy Policy

What Distilled collects when you use it, why, who else sees it, how long we keep it, and what you can ask us to do about it.

Last updated October 3, 2026

Who we are

Distilled is run by Distilled Systems LLC, a Wyoming limited liability company ("Distilled", "we", "us"). This policy covers distilled.cx, the Distilled console, our API, our MCP server and the cloud Android phones and agent features we run for you (the "Service"). It does not cover the apps and websites you use on a phone, which have their own policies.

For account and billing data we are the controller. For what happens on your phones, which is your content, we act as your processor and follow your instructions.

What we collect

Account. Your email address, and the sign-in codes we email you. A code is kept only as a hash and is good for 10 minutes. Your session lives in a cookie that is marked HttpOnly and Secure and lasts 30 days. We also keep your workspaces, their members and roles, and invitations.

API keys. We keep only a hash of a key. The key itself is shown to you once, when you make it.

Payments. Card payments are handled by Stripe, which collects your card details. We never see or store a card number. We keep a record of each payment: its amount, time, reference, and the Stripe customer it belongs to. Crypto payments are handled by OxaPay, and we keep the payment's reference, coin, network and amount. A crypto transaction is also public on its blockchain.

Usage. Which phones you run and for how long, the data each phone sends through the network (counted in bytes, not read), how much agent use you consume, and your balance and its ledger.

Requests to the API. For 30 days we keep a log of calls to the API: the method, the route and path, the response status, how long it took, and which key made it, so you can look back at what your own code did. We use client addresses to apply rate limits and to block abuse.

Your phones. What is on a phone is yours: its apps, accounts, files and what its screen shows. We run the phone and store its contents for you, and we do not read them except to run, secure and support the Service, or when the law requires it. Live views are sent to the people watching as they happen. A screenshot or short recording is made only when you or your agent ask for one, and it is returned to the requester.

Agent runs and the assistant. When you start a hosted run or chat with the assistant, the instructions you give, what the phone's screen shows at each step, and the model's replies are sent to an AI model provider to produce the next step. We keep each run's steps, including the screenshots the model was shown, for 30 days so you can look back at them, and then delete them. Assistant conversations and anything you ask the assistant to remember are kept with your workspace. You can delete a conversation or a memory yourself, and you can ask us to erase them completely.

Secrets, proxies and apps. Workspace secrets and the logins of proxies you bring are encrypted when you save them. A proxy login is never shown again. Apps you upload are stored so we can install them on your phones.

The website. Our public site and console use no advertising trackers. They count visits with Cloudflare Web Analytics, which records the page, the referring site, the country and the browser without cookies and without following you across other sites. Cloudflare, our host, also keeps ordinary request logs.

How we use it

  • To run the Service: create and run your phones, sign you in, carry out what you and your agent ask for, and bill you.
  • To keep it safe: detect abuse and fraud, apply rate limits, investigate incidents, and keep phones isolated from each other.
  • To support you, and to email you about your account: sign-in codes, invitations, receipts, balance and security notices.
  • To meet our legal, tax and accounting duties.

We do not sell personal data, and we do not use your phones' contents to train models.

Who else sees it

We use these providers to run the Service. Each receives only what it needs for its job.

  • Google Cloud: our API, database and file storage. Google Workspace handles our own email.
  • Cloudflare: our website, DNS, firewall, the edge that nodes report to, and a relay that carries live views.
  • Stripe and OxaPay: card and crypto payments.
  • Resend: sending our emails.
  • Vercel's AI Gateway and the model providers behind it: producing agent steps and assistant replies, as described above.
  • Proxy providers: when a phone uses an exit address we supply, the provider that owns it carries that phone's network traffic.
  • Server hosting providers: the physical servers our phones run on.

We also disclose information when the law requires it, to protect the Service and its users from fraud or abuse, and to a buyer if Distilled Systems LLC is sold or merged, who must honor this policy.

How long we keep it

  • API request log: 30 days. Agent run traces: 30 days, or sooner if you delete the run.
  • Sign-in codes: 10 minutes. Sessions: 30 days. Invitations: 7 days.
  • A phone's contents: for as long as the phone is in your workspace. When you release a phone, its storage is queued for wiping on our server and is deleted as soon as the server carries it out, waiting for the server if it is offline. A phone stopped for lack of balance is removed the same way after 7 days. The record that a phone existed, its history of starts and stops, and its charges stay with your billing records.
  • Account, payment and billing records: while your account is open, and afterwards as long as tax and accounting law requires.

Database backups are kept for 7 days, so deleted data leaves them within a week. Other logs age out on their own schedules.

Security

Traffic to the Service uses HTTPS. API keys are stored as hashes, and secrets and proxy logins are encrypted. Each phone runs in its own isolated environment. No system is perfectly secure, so we cannot guarantee that data will never be exposed. If a breach affects your data, we will tell you as the law requires.

Your choices and rights

You can ask us to give you a copy of your personal data, correct it, or delete it, and, where the law gives you the right, to limit or object to how we use it. Write to sales@distilled.cx from the email address on your account. We answer within 30 days, and we delete what we are not required to keep. An owner can delete a workspace once it holds no phones, which revokes its keys and removes its webhooks and alerts.

If you are in the European Economic Area, the United Kingdom or California, you have the rights those laws give you, including the right to complain to your regulator. We rely on these legal bases: performing our contract with you, our legitimate interest in running and securing the Service, your consent where we ask for it, and legal obligations.

Where data is kept

We are based in the United States, and our systems are mainly there. If you use the Service from elsewhere, your data is transferred to and processed in the United States and in other countries where our providers operate, under the safeguards the law requires for such transfers.

Children

The Service is for adults and businesses. It is not directed to anyone under 18, and we do not knowingly collect their data.

Changes and contact

When we change this policy we post the new version here and update its date. For a change that matters, we will also email the owners of workspaces. Questions go to sales@distilled.cx.

Distilled Systems LLC, a Wyoming limited liability company.