Twin

What Twin does, and what it won't.

Twin can click, type and send for you, so here is exactly where it stops, and where your data goes.

How Twin decides what to do

Right away

Everyday things that are easy to undo, when you ask for them.

  • Opening a link, an app or a website
  • Switching tabs, going back, reloading
  • Clicking an ordinary button or menu item you named
  • Typing words you asked for (it never presses Return)

After your yes

Anything that closes or ends something waits for Do it, or a spoken yes.

  • Closing a tab or a window
  • Leaving or ending a call
  • Cancelling, archiving, unsubscribing
  • In your connected apps: sending, booking, posting, changing

Never

Twin points at the button and leaves the click to you.

  • Deleting or removing
  • Paying, buying, placing an order
  • Sending or submitting on screen, signing out, quitting
  • Typing a password, or granting a permission

A question that comes next, dictation, or the close button drops a waiting offer, and an unanswered offer lapses after 30 seconds. A new question also stops a task between steps.

Where everything goes

The short version of the Privacy Policy, one topic at a time.

Screen
Twin takes a screenshot of each display only when you ask: while you hold ⌃⌥, after you say “What's good, Twin” if you've turned that on, or when a step you started needs to see the screen again. When you speak any language, Twin's model on Microsoft Azure looks at it to answer; for Indian languages, Twin's server has Sarvam AI read the text on it. Twin doesn't store screenshots; the text read from a screen is kept for one minute so a follow-up question doesn't read it again.
Voice
While you hold the keys, your voice streams to be written down: to Deepgram when you speak any language, to Sarvam AI for Indian languages. With Wake Twin by voice on, your computer listens for the phrase itself and sends nothing until you say it. When you ask for meeting notes, the recording goes in pieces of about 25 seconds, each deleted from your computer once it's transcribed.
Answers
Twin's model on Microsoft Azure writes the answers when you speak any language, and Sarvam AI's models for Indian languages, through Twin's server; Cartesia or Sarvam AI speaks them. Agents that work in your apps, and cloud agents, also use models on Microsoft Azure, and TypeSafe picks the next step of a task on screen. When you're signed in, your conversation history syncs to your account.
Memory
What Twin remembers is stored by mem0 on Twin's own server, separately for each account. You can read it, edit it, pause it or wipe it in Settings, and deleting your account deletes it.
Your apps
Composio holds the sign-ins to the apps you connect. Twin's server holds the Composio key, so no app password or token is stored on your computer. Disconnecting an app revokes Twin's access.
Files
Compressing, resizing and converting pictures and PDFs happens on your computer, and the original is never changed. Video and audio jobs go to Twin's media worker, which deletes its copies after the job and anything left within a day.
Analytics
None. The apps' analytics code is switched off by design, and this website has no analytics or tracking either.
Keys
Twin's API keys live only on Twin's server, never in the apps. Your sign-in session is kept in the Mac's Keychain, or in Windows' protected storage.
Audits
Twin hasn't had a SOC 2 or ISO 27001 audit yet.

How it's built

  • Every account's data is kept apart in the database: each row belongs to one account, and the database itself refuses to show or change another account's rows.
  • Signing in uses Google or Facebook's own page with PKCE. Sessions refresh before they run out, and signing out ends them on the server.
  • Each account has its own rate limits, so nobody can run up requests in your name.
  • Deleting an account only works with a session from the last ten minutes, so an old, stolen session can't do it. It removes the account's synced data and its memories.
  • The Windows installer isn't code-signed yet, which is why Windows asks before running it the first time.