Endpoint Connect Privacy Policy

Effective date: 19 September 2026

1. Scope and who we are

This Privacy Policy explains how Endpoint Connect (the “App”) handles information when you use it. Endpoint Connect is independently developed and operated by its developer (“we”, “us”, or “our”).

This Privacy Policy is intended to comply with the Personal Data Protection Act 2010 (Act 709) of Malaysia, as amended from time to time, to the extent applicable to the App and our processing of personal data.

2. The short version

Endpoint Connect is an Android application that lets you connect directly to AI providers and endpoints you choose. Endpoint Connect does not operate an inference proxy, relay, or hosted AI service. Your prompts, provider credentials, conversations, and attachments are not routed through an Endpoint Connect server.

3. Information handled by the App

3.1 Provider connection information

To connect a provider or endpoint, you may enter or authorize information such as API keys, access and refresh tokens, authorization codes, endpoint URLs, usernames, passwords, cookies, model selections, and connection preferences. The App stores connection secrets locally using Android security facilities and encrypted local storage where supported. We do not receive or store those secrets on an Endpoint Connect server as part of the App’s normal operation.

You are responsible for ensuring that the credentials, tokens and other authentication information you provide are valid, are used in accordance with the applicable provider’s terms, and are kept secure on your device. Endpoint Connect does not grant you any rights to access a provider or endpoint that you are not otherwise authorised to use. You should not provide credentials to us through support communications unless necessary.

3.2 Prompts, conversations, and generated content

The App handles prompts, conversation history, model responses, drafts, selected models, and related session information so that it can provide chat and restore your local history. This information is stored locally on your device.

When you submit a request, relevant conversation content is transmitted directly to the selected provider or endpoint as necessary to process your request. The provider or endpoint may retain, store, use or otherwise process that information in accordance with its own terms, settings and privacy policy.

3.3 Files, photos, camera, and microphone

If you choose to attach a document, PDF, photo, camera capture, audio recording, or other file, the App accesses that item as necessary to perform the action you requested. The selected content may be processed locally and transmitted directly to your selected provider or endpoint when required for that feature. Camera, photo, file, and microphone access is user-initiated and subject to Android permissions. Endpoint Connect does not use these permissions for advertising.

3.4 Optional device-local profile and settings

The App may store a display name, profile image, language, theme, accessibility, voice, streaming, endpoint, and other preferences locally on your device. If a Google profile is offered, using it is optional and does not create an Endpoint Connect cloud account.

3.5 Personal Context

If you enable the optional Personal Context feature, the App may store information you choose to include in your personal context on your device to help supported AI models provide more relevant responses. Personal Context is stored locally on your device and is not intended to create an Endpoint Connect cloud profile.

You can view, edit, disable, or delete your Personal Context through the App, subject to the features available in your version of the App.

When Personal Context information is included in a request, the relevant information is transmitted directly to the provider or endpoint you have selected. Once transmitted, that information is subject to the provider’s or endpoint’s terms, settings, and privacy practices.

3.6 Purchase information

Purchases are processed through Google Play. We do not receive your full payment-card details. Google Play may provide us with information relating to your purchase, such as purchase status, transaction or order information, and other information necessary to administer, support or reconcile the purchase, subject to Google’s own terms and privacy practices.

3.7 Support communications

If you contact us, we receive the information you choose to provide, such as your email address, message, screenshots, diagnostic details, or attachments. We use this information to respond to your request, investigate and resolve issues, prevent abuse, and maintain the App. If you voluntarily provide credentials or other sensitive information to us through support communications, we may receive and process that information as necessary to handle your request. You should remove provider keys, passwords, private prompts and other secrets before contacting support.

3.8 Analytics and diagnostics

The current release does not include advertising SDKs or developer-operated behavioral analytics. Google Play and the Android operating system may independently process installation, purchase, security, crash, and device information in accordance with applicable Google policies and your device settings.

4. How information is used

Information handled by the App is used to:

5. Direct transmission to third parties

5.1 Direct transmission and recipients

When you use a connected service, the App transmits the information necessary for your request directly to that service over your device’s network connection.

Depending on your choices, recipients may include:

5.2 Third-party services

The services described above are independent of Endpoint Connect. Their operators may collect, retain, use, disclose, transfer, or otherwise process information in accordance with their own agreements, settings, and privacy practices, including where applicable their policies regarding the use of submitted content for model training or service improvement. You should review the applicable terms and privacy policy before connecting to or using a service.

For a self-hosted or custom endpoint, you are responsible for knowing who operates it and how it handles data.

We do not control the privacy, security, availability, content, policies, or practices of any third-party provider, endpoint, or service you choose to connect to or use through the App, and we are not responsible for their acts or omissions.

Endpoint Connect does not sell personal data. Information that you choose to transmit directly to a provider or endpoint for a feature you request is transmitted at your direction and is subject to that provider’s or endpoint’s terms and privacy practices.

5.3 User responsibility

You are responsible for ensuring that any content you choose to submit through the App may lawfully be submitted to and processed by the provider or endpoint you select, including obtaining any necessary permissions or consents from other individuals where required.

Before submitting confidential, sensitive, or personal information, you should assess whether the provider or endpoint you have selected provides an appropriate level of confidentiality and security for that information.

You are responsible for reviewing the applicable provider’s terms and privacy practices before sending information to that provider.

6. Local storage, security, and backups

Endpoint Connect uses safeguards appropriate to an Android application, including secure transport for public internet connections, Android-provided credential protection, and encrypted local storage for sensitive connection material where supported. Private or local network connections may use HTTP where you explicitly configure or approve an eligible local endpoint.

No security method is completely secure. The security of locally stored data also depends on your device lock, operating system security, backups, root status, installed software, network security, and the security of the providers or endpoints you connect to. You should not use the App on a compromised device or connect it to an endpoint you do not trust.

Android or device-vendor backup and device-transfer features may copy some App data to cloud backup services or another device where those features are enabled.

Where required by applicable law, we will take appropriate steps in response to a personal data breach, including any notifications required by law.

7. Retention and deletion

Local conversations, drafts, settings, attachments, and connection information are stored on your device and may remain there until you delete them in the App, clear the App’s storage, remove the relevant connection, or uninstall the App, subject to device backups and other device-level storage or recovery mechanisms. You can delete chats and remove saved connections through the App.

Because Endpoint Connect does not operate an App account or inference server, we generally do not hold a server-side copy of this content. Deleting local data does not delete copies already transmitted to a provider or endpoint. To access or delete provider-held data, use that provider’s controls or contact its operator. Endpoint Connect cannot delete or control copies held by a provider or endpoint that you selected.

Support correspondence is retained only for as long as reasonably necessary to respond to your request, maintain appropriate support and security records, prevent abuse, establish or defend legal claims, and comply with applicable legal obligations.

8. Permissions and user choice

You control which providers or endpoints to connect, which model to use, what content to send, and whether to grant optional Android permissions. You may revoke permissions in your Android device settings. A feature may not work without the permission or provider or endpoint capability it requires. You may use the App without creating an Endpoint Connect account.

9. International processing

A provider or endpoint may process information in countries other than yours. The location of processing depends on the service you choose and its infrastructure. Endpoint Connect does not choose or control a third-party provider’s processing locations.

Before sending sensitive information, you should review the provider’s privacy policy and any applicable information about international transfers and transfer safeguards.

10. Your rights

Depending on where you live and subject to applicable law, you may have rights regarding your personal data, including rights to access, correction, deletion, restriction or objection to processing, data portability, withdrawal of consent, and to make a complaint to a regulator.

Most App content is held locally on your device and can be managed through the App or your Android device settings. For personal data held by a connected provider or endpoint, you should direct your request to that provider or operator, as applicable. For personal data that we hold through support communications or another direct interaction with us, you may contact us at endpointconnect@gmail.com.

We may need to verify your identity or request before responding, and may retain information where required or permitted by applicable law.

Where the Personal Data Protection Act 2010 (Act 709), as amended, applies to our processing of your personal data, requests relating to that processing will be handled in accordance with the applicable requirements of that Act.

11. Changes to this Policy

We may update this Privacy Policy to reflect changes to the App, applicable law, or provider integrations. We will update the effective date and provide additional notice where required by applicable law. The updated Privacy Policy will apply from its stated effective date.

12. Contact

Email: endpointconnect@gmail.com