Privacy
Last updated 23 September 2026
Robin has no accounts, no telemetry and no analytics, and this website sets no cookies. The only thing we keep about anyone is the email address of a person who joined the early-access list, for as long as it takes to tell them Robin is ready.
The early-access list
When you put your email address into the form on this site, this is exactly what happens.
What we store
- Your email address, as you typed it, in lower case.
- The date and time you joined, in UTC.
- A fingerprint of your removal code. The code itself is in the removal link you are shown once, after joining; we keep only a one-way hash of it, so the link works and nobody here can rebuild it.
Nothing else: not your IP address, not your browser, not where you came from, not a cookie. To stop one connection sending hundreds of addresses, a one-way hash of your IP address is held in memory for one minute to count attempts; it is never written to disk or kept with your address.
Why
To send you one email when Robin can be downloaded, with the launch price. We ask for your address for that and only that, and it is your choice to give it. We do not add you to a newsletter, share the list, sell it, or use it to advertise to you anywhere.
Where
In a database at Cloudflare (Cloudflare D1), which hosts this site and processes the list on our behalf. The database is kept in Western Europe.
How long
Until the launch email has gone out, and then no more than 30 days: the list is deleted once it has done its one job. If Robin has not launched 18 months after you joined, your address is deleted automatically anyway.
The launch email will be sent by Joydle Interactive LTD from hello@getrobin.app. No email service is used today; if one is used, it will be named on this page before it receives any address.
How to be removed
- Use your removal link. After you join, the page shows a link that removes your address immediately. It is the only copy, so keep it.
- Or write to us at hello@getrobin.app from the address you signed up with, and we remove it within a few days.
- The launch email itself will carry a link that does the same.
This website
getrobin.app is a set of static pages served by Cloudflare. There are no cookies, no analytics, no advertising and no third-party scripts; the pages load nothing from anywhere but this site.
Like any web host, Cloudflare sees the IP address and browser details of each request in order to deliver the page and protect the site from attacks, under its own privacy policy. We have not switched on request logging or visitor analytics, so we do not have a record of who visited.
The Robin app
Nothing is sent to us by the app: not your prompts, not your files, not your usage, not your API keys, not a count of how often you open it. There is no server on our side to send it to.
The app does talk to the internet, but only to services you chose: the model provider whose key you entered, a generation service when you ask for an image or a voice, an MCP server you connected, a web search when you asked for one, and the licence merchant when you activate your key. That is the whole list, and it is spelled out below.
What the app sends, and to whom
Model providers
These receive your prompt and whatever context you attached — the conversation, selected text, files or screenshots you added, and tool results — only when you send a message to a model from that provider, with your own key.
| Host | What it is | What is sent | When |
|---|---|---|---|
api.anthropic.com | Anthropic (Claude) | Your prompt, conversation context, attached files and images, tool definitions and results; your Anthropic API key | When you send a message to a Claude model |
api.openai.com | OpenAI | The same, with your OpenAI key; also audio you record, if you use dictation or speech | When you send a message to an OpenAI model, or use OpenAI speech |
generativelanguage.googleapis.com | Google Gemini | The same, with your Gemini key. Larger attachments go to the Gemini files endpoint first | When you send a message to a Gemini model |
openrouter.ai | OpenRouter | Your prompt and context, with your OpenRouter key; OpenRouter forwards it to the model you picked | When you send a message through OpenRouter |
| An address you enter | Any OpenAI-compatible server | The same as above | When you send a message to that server |
If you enter a custom address for a provider, Robin sends to the address you typed; it is up to you to know what is at the other end.
Generation and media services
Used only when you ask for something to be made, each with the key you entered for that service.
| Host | What it is | What is sent | When |
|---|---|---|---|
fal.run, queue.fal.run | fal.ai — images, video, audio, upscaling, background removal | Your prompt and any source image; your fal key | When a generation, upscale or background removal routes to fal |
api.elevenlabs.io | ElevenLabs — speech and sound | The text to be spoken, or audio you supplied; your key | When you ask for speech or a sound effect |
api.dev.runwayml.com | Runway — video | Your prompt and any source image; your key | When you ask for a Runway video |
api.lumalabs.ai | Luma Dream Machine — video | Your prompt and any source image; your key | When you ask for a Luma video |
MCP servers you connect
Which ones, and whether any at all, is your choice. A connected server receives the tool calls the assistant makes and their arguments, and may hold its own data about you under its own policy. Sign-in is between you and that service; the token is kept in your Keychain and never comes to us.
| Host | What it is | When |
|---|---|---|
mcp.slack.com | Slack | Only if you connect it and the assistant uses it |
mcp.notion.com | Notion | Only if you connect it and the assistant uses it |
mcp.linear.app | Linear | Only if you connect it and the assistant uses it |
mcp.sentry.dev | Sentry | Only if you connect it and the assistant uses it |
api.githubcopilot.com | GitHub, with your GitHub token | Only if you connect it and the assistant uses it |
| Any server you add | Yours, or a third party’s | Only when you connect it and it is used |
Everything else the app reaches
| Host | What it is | What is sent | When |
|---|---|---|---|
html.duckduckgo.com | Web search | Your search query and nothing else | When the assistant searches the web for you |
| A page you asked it to read | That site | An ordinary request for the page | When it fetches a URL you gave it, or one from search results |
api.github.com | GitHub’s public API | The repository and path of a skill you are installing | When you install a skill from GitHub |
| The licence merchant | The seller of record. Nothing is on sale yet; the merchant will be named here and on the checkout page when sales open | Your licence key and a random per-Mac ID; nothing about what you do in the app | When you activate or release a seat, and when the app checks the key is still valid |
The per-Mac ID is a random number minted on first launch, so two-machine activation can be counted and a seat released. It is not a hardware identifier and is not tied to anything you do.
Links to documentation and “get your key here” pages open in your browser only when you click them; they carry no data. When a model, an MCP server or an engine runs on your own Mac (localhost), nothing leaves the machine. Run everything locally and the app makes no outbound requests at all beyond licence checks.
Crash reports
Robin does not collect crash reports. If a crash reporter is offered in a future release, it will be off until you turn it on, and will say plainly what a report contains.
What the app keeps on your Mac
~/Library/Application Support/Robin/— conversation and run history, the activity log, boards, what was made, and installed skills. An ordinary folder you can open, back up or delete.- The macOS Keychain — your API keys and any tokens for connected services, protected by your login.
- Preferences — which model you chose, your hotkey, window state. Settings, not content.
- History — kept for 1, 7, 30 or 90 days, as you choose, or not at all. Anything older is deleted automatically.
None of it is synced or uploaded anywhere unless you run your own backup. To remove all of it, quit Robin and delete that folder; revoke keys at your provider’s dashboard at any time.
Your rights
For the one thing we hold — a waitlist address — you can ask what we have, have it corrected, or have it deleted, and you can withdraw your consent at any time with the removal link. Depending on where you live, you may also complain to your data protection authority. We would rather you wrote to us first.
Robin is not directed at children and the list is not for them.
If this page changes, the date at the top changes with it.
Who we are
Robin is made by Joydle Interactive LTD, a company registered in England and Wales (United Kingdom) under company number 17233012, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
Write to us at hello@getrobin.app. There is a person on the other end of it.