Egoist Machines, Inc.
Terms of UseCookie Noticeprivacy@ego.ist

Privacy Policy

AI Passport is built around user control. This policy explains what information we collect, how we use it, when we share it, and what choices you have.

Effective date: August 21, 2026

Egoist Machines, Inc. ("Egoist," "we," "our," or "us") operates the AI Passport website, waitlist, card editor, developer pages, MCP tools, and related online services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Services or otherwise interact with us online.

State privacy rights notice: see Section 15 for important information about your rights under applicable U.S. state privacy laws. Notice to European users: see Section 16 for additional information for individuals located in the European Economic Area or United Kingdom.

1. Information we collect

We may collect the following categories of personal information:

  • Contact and account information, such as your name, email address, phone number, waitlist serial number, username, email confirmation status, and marketing consent records.
  • Social sign-in information, such as the sign-in provider, provider account identifier, name, profile image, and email address that Google, Apple, or Facebook makes available when you choose that sign-in method.
  • Waitlist, referral, and card information, such as referral codes, referral links, referral attribution, saved card designs, design tokens or token hashes, QR image uploads, and other content you submit through the card editor or MCP tools.
  • Developer-interest information, such as company or app name, role, app type, use case, requested context categories, call preference, and notes.
  • Communications, such as messages, support requests, survey responses, and other information you send to us.
  • Device and usage information, such as IP address, browser type, device information, referring pages, pages viewed, events, session identifiers, analytics identifiers, approximate location inferred from IP address, and error or diagnostic information.
  • Cookie and similar technology data, including data collected through analytics tools such as PostHog. For details, see our Cookie Notice.

We collect information directly from you, automatically when you use the Services, from service providers that help us operate the Services, from sign-in and connected-service providers you choose to link, and from referral links when someone refers you to the waitlist.

2. How we use information

We may use personal information to:

  • operate, maintain, secure, and improve the Services;
  • manage waitlist reservations, email confirmation, login codes, usernames, referrals, card designs, QR image uploads, and MCP design access;
  • create, secure, and let you access your account through the sign-in method you choose;
  • send waitlist, launch, product, marketing, transactional, and administrative communications by email, text message, or other channels you provide;
  • respond to questions, requests, and support inquiries;
  • review developer-interest submissions and contact potential partners;
  • screen submitted names, images, card designs, and related content for abuse, safety, rights, and policy issues;
  • understand site usage, measure performance, and debug errors;
  • protect against spam, fraud, referral abuse, unauthorized access, and security issues;
  • comply with applicable laws, lawful requests, and legal process;
  • enforce our agreements and defend legal claims.

We may create aggregated, de-identified, or anonymized data from personal information by removing information that makes the data identifiable to you, and we will not attempt to re-identify such data except to test whether our de-identification processes comply with applicable law. We may use and share this data for our lawful business purposes, including analyzing and improving the Services. We do not use your memories to train models.

If we need to use personal information for a purpose that is not compatible with the purposes described here, we will ask for your consent before doing so.

3. How we share information

We may share personal information with:

  • service providers that help us with hosting, email delivery, authentication, database and storage services, analytics, content moderation, security, communications, and website operations;
  • third-party services you choose to use or connect, such as MCP clients, agent tools, social sharing services, or websites reached through outbound links;
  • third parties you designate, where you have instructed us or provided your consent to share;
  • professional advisors such as lawyers, auditors, accountants, and insurers;
  • government authorities, regulators, or law enforcement where required by law or to protect rights, safety, and security;
  • a buyer, investor, or successor in connection with an actual or prospective merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, including prospective counterparties and their advisers.

Some features are designed to create shareable or visible content. For example, referral links can be shared with others, and images you upload for QR styling may be stored at a public URL so they can render on your card. Content you make publicly visible can be seen, collected, and used by others, including being cached or copied by search engines, and we are not responsible for such use. Do not upload or share information you do not want others to be able to access.

We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising or use it for targeted advertising. If our practices change, we will update this Policy and provide any choices required by law.

4. Health and fitness data from connected services

AI Passport can retrieve health and fitness information, but only from a service you choose to connect. If you link a fitness or health account such as Fitbit, Garmin, or Strava, or if you save a health-related note yourself, that information can become part of your Passport.

These categories can include activity and workout data, sleep, heart rate, and other body metrics from the service you link, along with any health-related note you choose to save. We use this information only to return it to the AI apps you have authorized so they can recall it on your behalf. We do not use it for advertising, and we do not use your memories to train models.

Access is user-linked and consent-gated. Connecting a service does not, by itself, let any app read it. An app can read a category of your data only after you approve an exact, revocable pass for that category, and you can withdraw a pass or disconnect a service at any time. We share this information only with the specific app you have granted a pass to and with the service providers that help us operate the Services as described in Section 3, and we never sell it.

Health and fitness data is sensitive. Where applicable law treats it as a special category of personal information, we process it only with your consent. We keep it until you delete it, disconnect the service, or close your account, and then delete it within a commercially reasonable period, subject to the retention needs described in Section 9.

5. Google user data

If you connect your Google account, AI Passport can retrieve the Google data you choose to share, such as calendar events, tasks, or your YouTube library. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We access Google user data read-only and on demand, only to return it to the AI apps you have authorized, and only after you approve an exact, revocable pass for that data category. We do not store Google user data, transfer it except at your direction, use it for advertising, or use it to develop, improve, or train generalized AI or machine learning models. Disconnecting your Google account deletes the OAuth credential.

6. Social sign-in

If you choose Google, Apple, or Facebook to sign in, that provider authenticates you and sends our authentication service the account information you agreed to share, such as your provider account identifier, name, profile image, and email address. We use this information to create, link, secure, and sign you in to your AI Passport account. We do not use social sign-in to post to your social account, read your friends, messages, pages, advertising data, or other content.

Social sign-in establishes account identity only. It does not connect the provider as a Passport data source, approve a memory, or grant an AI app permission to read your Passport. You can unlink a social sign-in method from your linked accounts without deleting your Passport, or follow our data deletion instructions to request full deletion.

If you choose to connect to the Services through a social or other third-party account, you may be able to use your settings with that provider to limit the information we receive from it. If you revoke our access, that choice will not apply to information we have already received.

7. Cookies and similar technologies

We use cookies and similar technologies to keep the site working, keep you signed in, remember your consent and referral choices, understand engagement, and improve performance. Some cookies are essential for the site to function. Others support analytics and session recording through PostHog and, in the EU and UK, run only with your consent. We also use local storage and similar browser storage to remember referral information, reservation state, and design-related preferences, and public passport pages count visits without cookies using a salted IP hash whose salt rotates daily and which we prune on a rolling basis, normally within 3 days.

For a full list of the cookies we set, what each one does, how long it lasts, and how to control them, see our Cookie Notice. You can also use browser settings to block or delete cookies, though some Services may not work properly.

8. Your choices

You can make the following choices:

  • Opt out of marketing emails. You can unsubscribe at any time by clicking the unsubscribe link in the email or contacting us. If you opt out, you may continue to receive service-related and other non-marketing emails.
  • Opt out of marketing text messages by replying STOP. For help with text messages, reply HELP. Message and data rates may apply, and message frequency may vary.
  • Access, correct, or delete your information. You can contact us to request access, correction, or deletion where applicable law provides those rights, and you can review and update certain account information by signing in to your account.
  • Submit a privacy request by emailing privacy@ego.ist from the address associated with your reservation or developer submission, or include that address in your request. We may need to verify your identity before acting on the request.
  • Unlink a social sign-in provider or request full account deletion by following our data deletion instructions.
  • Control cookies and similar technologies as described in our Cookie Notice, including through the consent banner where it is shown and through browser settings.
  • Decline to provide information. We need certain personal information to provide the Services. If you do not provide information we identify as required, we may not be able to provide them.

Do Not Track: some browsers can send "Do Not Track" signals. We currently do not respond to Do Not Track signals. Our treatment of Global Privacy Control signals is described in Section 15.

9. Data retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to manage the waitlist, referrals, card designs, developer-interest submissions, communications, security, legal obligations, disputes, and agreement enforcement. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and applicable legal requirements.

When we no longer require the personal information we have collected about you, we will either delete it, anonymize it, or, if that is not possible (for example, because it is stored in backup archives), securely store it and isolate it from further processing until deletion is possible.

10. Security

We use reasonable administrative, technical, and organizational measures to protect personal information. No method of transmission over the internet or method of storage is completely secure, and we cannot guarantee absolute security.

11. International data transfer

We are headquartered in the United States, and personal information may be processed in the United States or other countries where we or our service providers operate. Privacy laws in these countries may not be as protective as those in your state, province, or country. Users in Europe should read the important information about transfers of personal information outside of Europe in Section 16.

12. Children's privacy

Our website is not directed to children, and we do not knowingly collect personal information from children under 13, or under 16 where that is the age of digital consent (including the European Economic Area, the United Kingdom, and Switzerland). When you join the waitlist, we ask you to confirm that you meet this age. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us and we will comply with applicable legal requirements to delete it.

13. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the effective date above and posting the updated version here, or by other appropriate means. Any modifications will be effective when posted unless otherwise indicated.

14. How to contact us

EGOIST MACHINES INC
Unit 841, 1395 22nd St
San Francisco, CA 94107
privacy@ego.ist

15. State privacy rights notice

This section applies to residents of U.S. states with privacy laws applicable to us that grant their residents the rights described below, including California, Colorado, Connecticut, and Virginia (collectively, the "State Privacy Laws"). Not all rights listed below may be afforded to all users, and we may decline certain requests as permitted by law.

Subject to the State Privacy Laws, you may have the right to:

  • Information: request details about the categories of personal information we have collected, the sources, the purposes, and the categories of third parties with which we share it.
  • Access: request a copy of the personal information we have collected about you.
  • Correction: ask us to correct inaccurate personal information.
  • Deletion: ask us to delete the personal information we have collected from you.
  • Portability: request a copy of your personal information in a portable format.
  • Appeal: appeal our denial of any request validly submitted, by replying to our response or contacting privacy@ego.ist.
  • Nondiscrimination: exercise these rights free from discrimination as prohibited by the State Privacy Laws.

Sale, sharing, and targeted advertising: we do not sell personal information, and we do not share personal information for cross-context behavioral advertising or process it for targeted advertising within the meaning of the State Privacy Laws. Because we do not sell or share personal information, opt-out preference signals such as Global Privacy Control do not change our practices today; if our practices change, we will honor such signals as required by law.

Profiling and automated decision-making: we do not use your personal information for profiling or automated decision-making that produces legal or similarly significant effects.

Sensitive personal information: we process sensitive personal information, such as health and fitness data from connected services, only as described in Section 4 and only with your consent. We do not use or disclose sensitive personal information for purposes of inferring characteristics about you.

Consumers under 16: we do not have actual knowledge that we collect, sell, or share the personal information of consumers under 16 years of age.

How we collect, use, and disclose personal information: we collect the categories described in Sections 1, 4, 5, and 6 for the purposes described in Section 2, from the sources described in Sections 1, 4, 5, and 6, and we disclose those categories to the recipients described in Section 3.

Submitting requests; verification; authorized agents: to submit a privacy request, contact us at privacy@ego.ist. We may need to verify your identity before processing your request, for example by confirming control of the email address associated with your reservation or account, and we reserve the right to confirm your residency. Where permitted by law, you may use an authorized agent to make a request on your behalf; we may need to verify the agent's authority and your identity.

California Shine the Light: California residents may request the names of third parties to which we have disclosed certain personal information for their own direct marketing purposes during the preceding calendar year. We do not disclose personal information to third parties for their own direct marketing purposes. You may send questions about this to privacy@ego.ist with the statement "Shine the Light Request."

Nevada: Nevada residents have the right to opt out of the sale of certain personal information for monetary consideration. We do not engage in such sales, but you may submit a request to privacy@ego.ist.

16. Notice to European users

This section applies only to individuals in the European Economic Area ("EEA") or the United Kingdom (together, "Europe"). References to "personal information" in this Policy should be understood to include "personal data" as defined in the GDPR and UK GDPR.

Controller: Egoist Machines, Inc. is the controller of the personal information described in this Policy. See Section 14 for our contact details.

Legal bases for processing

For each purpose for which we process your personal information, we rely on a legal basis, as summarized below:

PurposeLegal basis
Providing the Services, including the waitlist, accounts, card designs, referrals, and MCP design accessContractual necessity: performance of a contract or steps taken at your request before entering a contract
Security, abuse prevention, and protecting the ServicesLegitimate interests: ensuring the ongoing security and proper operation of the Services; compliance with law where applicable
Service improvement and analyticsLegitimate interests: understanding and improving how the Services are used; consent, in respect of any optional cookies used for this purpose
Direct marketing, including email and text updatesConsent, including when you join the waitlist or opt in to receive email or text updates; legitimate interests where consent is not required
Retrieving connected-service data, including health and fitness data, and returning it to AI apps you authorizeConsent, granted through exact, revocable passes; explicit consent for special-category data such as health data
Compliance, legal claims, and responding to authoritiesCompliance with law; legitimate interests in participating in and supporting legal process and protecting rights, property, and safety
Corporate transactionsLegitimate interests: enabling an actual or prospective business transaction, with data minimized where possible

Your rights

Subject to applicable law, you may ask us to take the following actions in relation to your personal information:

  • Access: provide you with information about, and access to, your personal information.
  • Correct: update or correct inaccuracies.
  • Delete: delete your personal information.
  • Transfer: transfer a machine-readable copy of your personal information to you or a third party of your choice.
  • Restrict: restrict the processing of your personal information.
  • Object: object to processing based on legitimate interests, including processing for direct marketing.
  • Withdraw consent: where we rely on your consent, withdraw that consent at any time.

You may submit these requests by email to privacy@ego.ist or to our postal address in Section 14. We may request specific information to confirm your identity. If we decline a request, we will explain our grounds, subject to legal restrictions.

Complaints: if you are not satisfied with our response, you can lodge a complaint with the data protection regulator in your habitual place of residence. In the UK, this is the Information Commissioner's Office (ico.org.uk).

Data processing outside Europe

We are a U.S.-based company, and many of our service providers are also based in the U.S., so your personal information will be processed in the U.S. and may be processed in other countries outside Europe. The U.S. is not the subject of a general adequacy decision under the GDPR. Where we transfer your personal information to countries whose laws have not been deemed adequate, we use appropriate safeguards designed to give it effectively the same protection it has in Europe, such as standard contractual clauses approved by relevant authorities, or, in limited circumstances, we rely on a derogation such as your explicit consent. You may contact us for further information on the specific mechanism used when transferring your personal information out of Europe.

AI Passport by Egoist Machines, Inc.