---
title: Security and privacy
group: Your account
order: 3
summary: How Escanor protects integration credentials, devices, phone pairing and voice, how long data is kept, and how to request or delete your data.
updated: 2026-10-07
---
This guide explains the security and privacy controls in Escanor and how to use them. The [Privacy policy](/privacy), [Security](/security) and [Terms](/terms) pages have the full details.

## Integration access

Keys and tokens for the services you connect are stored encrypted and used only to carry out actions you request. Agents and the assistant use your workspace connection for each operation instead of asking you to paste provider secrets. Provider permissions still determine what can be read or changed. Disconnect in Escanor and revoke at the provider when access must stop; these are separate controls.

Do not put secret values into prompts, attachments, logs or support requests. Model input and tool results can contain content from connected systems. Connect with the narrowest permissions that do the job.

## Device and session storage

The website stores session credentials in browser storage; use a trusted device and sign out on shared computers. The desktop app encrypts its stored session with your operating system's keychain when one is available; otherwise it uses a file only your user account can read.

Desktop models, files and editor data stay on your computer, but cloud assistant and integration requests still send the content they need to those services. Session renewal, revocation and inactivity policies can end access; see [Accounts](/docs/accounts-sessions).

## Phone pairing

Messages between your phone and a paired computer are end-to-end encrypted, with replay checks; the relay only forwards sealed envelopes. Other app requests are encrypted in transit (HTTPS). Protect paired devices and revoke/forget pairings you no longer use.

Shell, file, installation, job and OS-control capability groups are disabled for remote callers by default. The computer owner controls escalation. See [Permissions](/docs/permissions-approvals) before enabling access.

## Voice and phone permissions

"Hey Escanor" is recognised by an on-device model on Android. What you say after it is turned into text by the phone's speech service (or an on-device model on the desktop), and the text goes to the assistant like a typed message. Contacts are read on the phone only when you ask to call someone and are not uploaded. Phone control reads the screen on the phone; that text is not stored or sent to Escanor.

Allow microphone, contacts, camera, notifications or Accessibility only for the features you intend to use. Android phone control needs the separate phone-control build, your agreement in the app, and switching it on yourself in Android settings. Refusing a permission can limit that feature. Review [Voice](/docs/voice) and [Android](/docs/android).

## What we do not do

Escanor does not sell your data, does not use analytics or advertising trackers, and does not train AI models on your code, prompts or workspace content.

## Your choices

**Settings > Privacy & data** has two optional consents, both off unless you turn them on: **Product news and offers** and **Product update notices**. Neither is needed to use Escanor, and turning one off takes effect from then on.

## How long data is kept

| Data | Kept for |
|---|---|
| Account and workspace data | While your account is open |
| Terminal sessions | 90 days after they close |
| Commands run on your machines | 180 days after they finish |
| AI task runs and Autopilot runs | 1 year |
| Security and access logs | 1 year |
| AI conversations | Until you delete them or your account |

See [How long we keep it](/privacy#retention) in the Privacy policy for the rest.

## Privacy requests

You can ask for a summary of your data, a correction, erasure, to withdraw a consent, or to nominate someone to act for you. Make a request in **Settings > Privacy & data**, on the public form on [Grievances](/grievances), or by email to support@escanor.in from your account email. We acknowledge within 24 hours and answer privacy requests within 30 days. Never include passwords or provider secrets in a request. See [Privacy requests](/privacy/requests).

Complaints are resolved within 7 days. Requests to remove content that breaks our rules are handled within 36 hours, and content showing someone's private areas or nudity, or impersonating them, within 2 hours. The Grievance Officer is Lakshay Jain. If you are not satisfied with a decision, you can appeal to the Grievance Appellate Committee at [gac.gov.in](https://gac.gov.in) within 30 days.

## Deleting your account

Open **Settings > Privacy & data > Delete account** and type your account email (and a two-step verification code if you have it on). You are signed out everywhere and every key stops working at once. The account is deleted after 7 days unless you sign in and choose **Keep my account**. Your name, email and sign-up date are kept for 180 days, and payment records as long as tax law requires. If you cannot sign in, see [Delete your account](/delete-account).

Disconnecting an integration, revoking a key, signing out, cancelling a plan and deleting your account are separate actions; do the ones you need.

## Reporting a concern

Report vulnerabilities to support@escanor.in (see [Security](/security)), and get help with the product through [Support](/support). Include the affected version, approximate time, steps to reproduce and a redacted error. Do not send credentials or customer or project content.
