This is the policy the front page points to. It is written to be checked, not to reassure. Every statement below describes behaviour that is either enforced by an automated check, or labelled as a commitment where no check can prove it.
When you press the key, the text Geeze AI reads is sent to our server, which passes it to OpenAI to write the description. On the few screens it has to look at, one picture of the window goes the same way. Neither is stored on our server. Captures are kept on your Mac for as long as your retention setting says, and our server holds no database of them.
OpenAI receives the capture in order to produce the description, and their handling of it is governed by their own API terms. We send it with our own account credentials, so you do not need an OpenAI account.
Geeze AI asks for Screen Recording once, on one setup card, and never again. It reads text the way a screen reader does. On the few screens that cannot be read as text it takes one picture of the window you pressed on, and that picture goes the same way the text does — to our server and on to OpenAI to be read. It is not stored at either end, and you can decline at setup or switch it off later.
If Geeze AI cannot reach our server, it does not send anything. Depending on what failed you either get the full text with a plain factual header, or nothing at all and your clipboard left as it was. Geeze AI never silently replaces what you had copied.
Per request, and nothing else:
| Recorded | What it is |
|---|---|
| token id | Which account made the request. Not your email; an identifier for the session token. |
| timestamp | When the request arrived. |
| token counts | How much text went in and came out, as a count. Not the text. |
| latency | How long the request took. |
| status | Whether it succeeded, and if not, the class of failure. |
Never recorded: the content of your capture or the description that was generated. No request body appears in any log, error message, or trace.
This is not only a policy. All output from the server passes through a single piece of code, an adversarial test suite tries to force capture content into a log line through several different failure routes, and an automated check refuses the build if any other code path can write output directly. If someone changed the server so that it logged your screen, the build would fail.
We keep that usage record for 12 months, then delete it. After that we keep only anonymous totals — counts with no account attached — and those we keep indefinitely.
Why we keep it at all, plainly: to understand how the product is actually used, and to investigate abuse. Those are the only two reasons, and neither needs to know what your screen said.
Each capture is saved on your own machine so you can look at it again, and is deleted automatically. The default is one day. In Settings you can change it to seven days, or to never saving anything at all. These files are never synced, uploaded, or backed up by us.
Geeze AI cannot write anywhere else on your Mac. That is enforced by an automated check on the app's build: a single directory for captures, a single file for timing figures, and nothing else. The timing file records app names and durations, never capture content.
You sign in with Google, Apple, or an email address we send a link to. Those are the only three.
We hold, for your account:
Nothing about what you capture is attached to your account.
We keep nightly backups of account records for seven days so we can recover from a failure. They contain your name, email and sign-in provider, and never anything you captured. Each night one copy is kept on our server and a second in separate storage, both in the United States. Both are encrypted at rest by our hosting provider; we do not add encryption of our own.
Signing in stores two tokens on your Mac, in the system Keychain: a short-lived one that lasts an hour and is renewed automatically, and a longer-lived one valid for up to 180 days that is replaced every time it is used. Each device you sign in on gets its own. You can see your devices and revoke any of them from Settings, which signs that device out immediately. If a longer-lived token is ever presented twice — which is what happens if one is stolen and replayed — every token for that device is revoked automatically.
Geeze AI is not yet released. Today the service runs for our own testing and holds no accounts but our own. The companies below will handle your details in this way once you can sign up.
Four companies are involved in running Geeze AI. None of them is sent anything you captured except OpenAI, and only for as long as it takes to write the description.
There is a Delete account button in Settings, under Account. It removes your account record and unlinks every usage row from it, so what is left cannot be traced back to you. Deleting your account removes it from the live service straight away. It leaves our backups as older copies are replaced, normally within seven days.
Being straight about timing: that button ships before launch, and if you are reading this before it does, email support@geezeai.com and we will do it by hand within seven days and confirm when it is done.
If you connect an AI assistant to Geeze AI over MCP, it can ask Geeze AI what is on your screen. You approve each assistant yourself and issue it a token. Every request shows a visible flash and is written to your local activity log, so you can see what asked and when. The connection is local to your machine; Geeze AI never reaches out to the assistant.
Worth understanding: a token you have issued is as powerful as your own account on that machine. Any program already running as you could read it. Approve assistants you trust, and revoke any you no longer use.
If this policy changes in a way that affects what we record or how long we keep it, we will say so here and tell account holders by email before it takes effect, not after.
Last updated 4 October 2026. Questions: support@geezeai.com