Overview
DIMUL (working name) is a local agent application developed by Obscyra Technologies L.L.C-FZ. This policy covers the application, its companion and company-operated relay and account services, and the website at dimul.obscyra.app. Features vary by build and configuration. Account-based access, account-protected downloads and remote push are implemented in the source but are not yet generally available; the descriptions below apply when those features are enabled and used.
We process information needed to operate the features you use, respond to support requests, protect the service from abuse, and meet applicable legal or platform obligations. We do not sell personal information or use it for advertising. DIMUL and its website have no integrated advertising trackers or analytics service. Local usage and diagnostic records are described below.
Information stored on your devices
Conversation history, prompts, model replies, task and tool records, permissions, project settings, memory, skills, file snapshots and media job records are stored on your computer in DIMUL's data folder. Project files and isolated project copies remain on your computer. Uploaded media and downloaded results can also be stored locally. The companion receives information from the computer you connect to so it can display tasks, conversations and approval requests.
Provider credentials may be kept in memory and, where supported and selected, the operating system credential store. The supported persistent vault for model and media credentials is currently macOS Keychain. QR relay identities can be stored in a restricted local file; the experimental Mac account flow migrates them to Keychain. Native account refresh sessions are stored in device-only Keychain items. This does not mean all local conversation history or project files are encrypted by DIMUL. Keep your devices, backups and connected accounts secure.
Models, media and connected services
When you choose a cloud model, DIMUL sends that provider the information needed for the task. This can include your prompt, relevant conversation context, instructions, selected or tool-read file contents, attachments, and tool results. Automatic summarisation and helpers can also send context to the models configured for those operations. Local model inference processes its input on your computer when you use a local runtime; using external tools or services still involves network requests.
Media generation sends the prompt and supported generation settings to the selected service after the required approval. The current fal.ai adapter sends text and settings for text-to-image or text-to-video; it rejects reference attachments before making a generation request. Importing an attachment into the local media studio does not itself upload it to fal.ai. Other enabled image or video flows send the inputs their supported operation requires. The provider and its delivery infrastructure receive generation, status and result-download requests.
Official Claude Code or Codex connections use your separate provider account. Connected mail, browser, MCP and other tools communicate with the services you authorise and may send task information or perform approved actions. Your provider credentials authenticate those connections. Provider policies govern their retention, training use, processing locations, subscriptions and charges. Relay encryption does not encrypt a request against the model or media provider that must process it. Review the provider's terms and privacy policy before sending confidential or personal information.
Remote access and end-to-end encryption
Internet relay access begins when you enable or start that connection. The company-operated relay uses Cloudflare infrastructure. An alternative relay or tunnel you configure is operated under its operator's policies.
Communication between paired DIMUL devices through the relay is end-to-end encrypted. The relay routes encrypted packets and does not receive the device keys needed to read their conversation, file or command contents. Pairing and device approval remain necessary; signing in alone does not approve a new phone or authorise an agent action.
The relay can process desktop and phone identifiers, public registration keys, device access permissions, connection times, packet sizes, request identifiers, sequence numbers, expiry times, delivery receipts and rate-limit counters. Its network infrastructure receives IP addresses and connection information. Registration uses hashed IP values for rate limits; account admission uses salted hashes in its rate-limit buckets. These are operational protections, not anonymity. Pending encrypted relay packets have an expiry of no more than 24 hours and are removed on delivery, expiry or applicable revocation.
Encryption does not hide all metadata or protect content on a compromised endpoint. It does not make DIMUL anonymous or guarantee uninterrupted or risk-free communication.
Push notifications
When supported and enabled with your iOS notification permission, remote notifications use Apple Push Notification service (APNs). The relay stores the APNs device token, delivery environment and device association to deliver notifications. Apple receives the token, delivery timing, a generic notification such as “Done” or “Approval needed”, and an encrypted payload. The relay additionally sees the desktop and phone identifiers.
The chat and project destination is encrypted with a separate key kept on the paired devices, not given to Apple or the relay. Any configured notification preview is also encrypted; previews are not enabled by default. Notification content becomes visible on the phone after decryption, subject to your device notification settings. Push queue entries expire after five minutes; revocation or an invalid device token removes the associated token and queue. Turning notifications off while offline takes effect on the computer after reconnection. Notifications already accepted by Apple cannot be recalled. Push delivery is best effort, and tapping a notification does not approve an action.
Sign-in and account information
The experimental account implementation currently supports Sign in with Apple only. Sign in with Google and email-code sign-in are not implemented or accepted by the current account service. DIMUL therefore does not currently collect a Google identity or an email address for an email-code account.
The Apple flow does not request your name or email address. It receives an Apple identity token and verifies its signature, application audience, expiry and one-time sign-in proof. The verified Apple subject is converted into a service-specific SHA-256 hash. The ordinary account record does not retain the raw Apple subject or identity token. The hash is a pseudonymous personal identifier, not anonymous data.
The service stores that hashed identity and provider label, a random internal account ID, account creation and revocation state, device IDs, device types and names, public signing and encryption keys, key revisions, approximate last-activity times, approved device links and session expiry and token hashes. Private device keys remain on the devices. These records support sign-in, device discovery, session renewal and access control; device names and activity are not proof of trust or availability. Accounts are not merged by email address.
Downloads, updates and operational records
When account-protected downloads are enabled, issuing a download link creates a record containing the internal account ID, device ID, build version, file SHA-256 and issuance time. It is scheduled for removal after 90 days and is also removed during account deletion. This records issuance of a link; it does not prove a completed download or identify who later copied a file. The application also associates installation authority and its expiry with the device and account session to authorise updates and, where enabled, cloud features.
Download and update servers and their hosting infrastructure receive request information, including network addresses, timing and requested resources. A download ticket contains signed account and device metadata and may remain in browser history or infrastructure logs. Treat download links as private. Application code does not add raw sign-in tokens or download tickets to the issuance journal. Infrastructure logging and retention can differ from that journal.
DIMUL keeps local execution, usage, error and diagnostic records to display progress, costs and outcomes and support recovery. These are not an automatic upload of your conversation history to us. If you send a diagnostic export or support email, we receive what you choose to include; review it before sending. Support messages may include your email address, attachments and other information you provide.
Website privacy
The public website is informational. It stores language and theme preferences in your browser's local storage. It has no analytics service, advertising trackers or tracking cookies. Hosting infrastructure necessarily processes requests and may keep operational or security logs. Visiting the site does not send it your local DIMUL conversations or project files. Email contact is handled by our email provider.
Sharing and service providers
We use infrastructure, hosting, email, notification and distribution providers where needed to operate DIMUL. This includes Cloudflare for the company relay and website and Apple for Apple sign-in and APNs. Model, media and other services you connect receive the information described above under their own policies. Information may be processed outside your country, including in the United Arab Emirates and in locations used by the relevant providers.
We may disclose information where required by applicable law, legal process or platform obligations, or where reasonably necessary to protect users and the integrity of the service. We do not sell personal information.
Retention and deletion
Local conversations remain until you delete them. Deleting a chat, disconnecting a provider, deleting an account and uninstalling an application are different operations. Local backups, exported histories and project files may remain after a chat is deleted or the application is uninstalled. DIMUL does not remotely erase files from your computer when an account is deleted. Some temporary tool archives expire separately; file snapshots and user-created files have their own lifecycle.
Account deletion, where the account feature is enabled, requires a recent sign-in and a fresh Apple authorisation code. It disables account sessions and links and queues removal of associated relay access, push registrations and download issuance records. The code or resulting Apple revocation token is stored encrypted temporarily for retrying Apple's token revocation. If revocation cannot be completed, deletion remains pending and may require a new Apple authorisation; it is not reported as completed simply because you pressed Delete. Apple consent-revocation and account-deletion notifications also trigger access removal.
The implementation retains a minimal deleted-account marker keyed by the hashed account identifier to prevent old access from becoming valid again; it does not erase every server-side byte immediately. If you subsequently sign in again, the new account can retain old random account IDs for up to 30 days for deletion-status checks. Revocation retry secrets are discarded on success or when a fresh authorisation is required. Support communications and infrastructure or security records may be retained as reasonably needed for support, security, legal obligations and dispute resolution. Copies held by third-party providers follow their policies.
Your choices
You can choose local models, limit the files and tools available to a task, change approvals, disconnect services, disable remote access or notifications, remove device links and delete local chats or account data where those controls are available. Back up files you want to keep. Signing out does not erase project files or cancel a separate provider subscription.
Depending on your location and applicable law, you may have rights to access, correct, delete or restrict personal information, object to processing, obtain a copy, or complain to the relevant authority. Contact us to make a request; we may need to verify your authority to act on the account. We do not hold a central copy of your local history that we can recover or delete on your behalf.
Changes to this policy
We may update this policy as DIMUL develops, features become available or legal requirements change. The updated version will be posted on this page with a revised effective date. Material changes to how information is handled will be described before the changed processing applies where required by law.
Contact
Obscyra Technologies L.L.C-FZ, Meydan Free Zone, Dubai, United Arab Emirates.
Privacy and support: hello@obscyra.app.