Skip to content

Privacy notice · alpha

Your server is a real boundary.

Installing Nautilo does not quietly put Kentauros inside an independently operated server. Who runs the server, which providers you connect, and where you send the work determine who can process it.

Effective and last updatedAugust 12, 2026

01 · Scope

One app. More than one operator.

This notice explains how Kentauros, Inc., a Delaware corporation and the maker of Nautilo, handles personal data through the Nautilo apps, nautilo.ai, software downloads, support, and services Kentauros operates. We call those “Kentauros Services.”

Nautilo is also open-source software that other people and organizations can run on infrastructure they control. This notice cannot describe or control what an independent Nautilo Server operator does. That operator must explain its own practices to its members.

02 · Who handles what

Follow the data boundary.

Kentauros Services

Kentauros is responsible for data processed through services we operate, such as this website, our release infrastructure, support, and Nautilo Cloud when it becomes available.

Independent Nautilo Servers

The Server operator decides where the Server runs, who may join, which providers it connects, how long data remains, and who administers it. Kentauros does not receive Server content merely because the operator uses Nautilo.

Connected providers

When a person or operator connects a model, tool, hosting, storage, identity, or other provider, that provider processes the data sent to it under its own terms and privacy notice.

03 · Kentauros data

What Kentauros receives today.

  • Website and download delivery: Hosting, security, and content delivery systems may process an IP address, device and browser information, requested URL, timestamps, and similar connection records needed to serve and protect the site or deliver a release.
  • Messages you send us: If you contact Kentauros, we receive the contact details, content, and attachments you choose to send, plus the records needed to answer and protect against abuse.
  • Distribution records: Apple, Google, GitHub, and other distributors may give us aggregated or account-level installation, purchase, crash, or release information according to their own systems and your settings.
  • Kentauros-operated accounts: When Nautilo Cloud or another hosted account service becomes available, we may process the account, subscription, service, security, and operational records required to provide it. We will update this notice and the relevant in-product disclosures before general availability.
The central rule: Connecting a Nautilo app to an independently operated Server does not, by itself, send that Server’s Rooms, messages, files, memories, or Genie configuration to Kentauros.

04 · Server data

What your chosen Server may handle.

A Nautilo Server may store or process account and profile information, membership, Rooms and messages, files and artifacts, memories, Genie configuration, permissions, provider configuration, security and audit records, and operational logs. The exact data depends on the release, enabled features, and the Server operator’s choices.

Nautilo clients also keep local settings, secure session material, drafts, cached content, and other data needed to connect to and use the selected Server. Device and operating-system controls govern some of that local storage.

If you want access to, correction of, export of, or deletion of data held on an independent Server, contact that Server’s operator. Kentauros cannot delete data it does not possess or administer.

05 · Connected providers

You choose where intelligence crosses the line.

Nautilo can connect to external AI models, search services, voice services, apps, tools, and infrastructure. Content, instructions, files, identifiers, and related metadata may cross the Server boundary when a person, Genie, administrator, or configured workflow invokes one of those services.

The Server operator chooses which providers are available and is responsible for understanding their terms. The person using Nautilo chooses whether to use an available provider for particular work. A provider’s privacy promises do not become Kentauros promises merely because Nautilo can connect to it.

06 · Device permissions

Permission follows a feature.

The mobile app may ask for access only when you use the related capability:

  • Camera: scan a Server QR code or take a photo to attach.
  • Photos and files: choose material to share or work on.
  • Microphone: provide voice input or create audio you choose to send.
  • Notifications: receive alerts from the selected Server. Platform push services process a device token and delivery metadata to route those alerts.

You can deny or withdraw a device permission in operating-system settings. The related feature may stop working, but unrelated parts of Nautilo should remain available.

07 · Security

No imaginary encryption.

Nautilo is being designed around private infrastructure, explicit membership, scoped access, protected credentials, and strong cryptographic boundaries. We use technical and organizational safeguards appropriate to the service we operate, but no system is immune to compromise.

The current alpha does not promise universal end-to-end encryption. Some data is protected in transit and at rest, but Server administrators and connected providers may be able to access data within their systems. Work on device-held keys, group encryption, and scoped delegation is still landing. We will revise this notice and the App Store disclosures when those protections ship, not before.

08 · Retention and choices

Ask the party holding the data.

Kentauros keeps data from Kentauros Services only as long as reasonably needed to provide and secure the service, meet legal obligations, resolve disputes, and enforce agreements. Retention on an independent Server is controlled by that Server’s operator and configuration.

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or an objection to certain processing. We may need to verify the request, and some records may be retained where law permits or requires it. Requests about an independent Server belong with its operator. Requests about Kentauros Services belong with Kentauros.

09 · Contact and changes

Privacy questions should reach a human.

Contact Kentauros about this notice or data handled by Kentauros Services at [email protected]. Questions about an independent Nautilo Server should go to that Server’s operator.

We may revise this notice as Nautilo changes. Material changes will appear here with a new effective date and, when appropriate, an in-product or account notice.

Gateway and Cloud launch notifications

Effective and last updated: September 17, 2026

Kentauros controls the Gateway and Cloud launch list. When you enter your email and click Notify me, you consent to receive launch notifications for these two services. We store your email, signup time, source page and the consent wording shown to you. This does not subscribe you to a general newsletter.

Basin (Moonshot Ventures, Inc.) receives and stores submissions for us and filters spam. Connection information, including IP address and browser information, is used for spam processing; we have disabled retention of that submission metadata and contributions to classifier training. This form does not load a CAPTCHA. Basin and its service providers may process data in Canada, the United States and the EU.

Signup records are automatically removed from Basin after one year. You can withdraw consent or request access, correction or deletion by emailing [email protected]. Withdrawal does not affect processing before your request. We use consent for launch emails and our legitimate interest in preventing abuse for spam filtering.

Basin’s data processing and privacy information

Website analytics and cookie choices

Effective and last updated: September 16, 2026

We use Google Analytics on this public website to understand page visits, scrolling, outbound links, download and deployment-link clicks, and film plays. It is not installed by this website in your Nautilo app or Server. When enabled, Google receives browsing events and connection information and uses first-party Analytics cookies to distinguish visits. Outbound-link and download events include the linked public URL; download events also include the file name and link text. We do not intentionally send names, email addresses, form contents or site-search terms, and advertising features are disabled.

We ask before enabling Analytics in the EEA, UK and Switzerland and whenever we cannot determine your country. Elsewhere, Analytics starts automatically unless you have turned it off. You can refuse or withdraw permission at any time using Privacy choices in the footer. We also turn Analytics off when your browser sends Global Privacy Control or Do Not Track.

Your choice is stored in this browser for six months. Our Analytics cookies expire after 180 days without being extended on each visit. Country lookup runs on our server using your connection IP; this lookup does not send your IP to a geolocation service or save it in a country-lookup log. Hosting systems may separately retain connection logs as described above.

How Google uses information from sites that use its services