Privacy Policy
Version of 11 September 2026. Continental Guild — website, account portal, applications and web remote
This policy covers the edition for individuals. Continental Guild Enterprise is supplied under a separate agreement with Continental LLC that governs its data processing
Who processes the data
Data controller — Yaroslav Andreyevich Morozov, sole proprietor, OGRNIP 320732500040475, INN 732985644172, Ulyanovsk Region, Cherdaklinsky District, Russia. Contact: guild@morozov.digital, telephone +7 (937) 274-79-65
Software rightsholder — Continental LLC, OGRN 1237700914725, INN 9721223401, Ryazansky prospekt 10, building 18, office 4.1, Moscow, 109428, Russia. Business enquiries: guild@continental-c.com
What we receive
Scroll the table to see all columns
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account sign-in and access-related messages | While access lasts, plus one year |
| IP address and connection times | Connection log: who connected to your computer and when | 90 days |
| Device name and role | Identify the linked computer and phone and manage access | While the device is linked |
| Crash report, if you submit one | Investigate and fix a crash | 90 days; removable earlier under Reports |
| App build number | Identify the installed version and available updates | While the device is linked |
| Apple push token | Deliver notifications when an agent asks a question | While the device is linked |
| Telegram bot token, if connected | Send agents’ messages on your behalf | While the integration is connected |
| Yandex.Disk access, if connected | Upload files to the Apps/Continental Guild folder and obtain links | While the integration is connected |
| OpenRouter key, if connected | Generate images using your key at your expense | While the integration is connected |
| GitLab and GitHub repository tokens, if connected | Verify access and deliver tokens to your computer for repository operations, CI and pushes | While the repository is connected |
| Name, contact, enquiry, attachments and consent record | Answer your enquiry and provide access or support | Until the enquiry is resolved, up to one year after the last interaction; contractual and mandatory records follow their respective legal basis |
| Notion integration key, selected pages and requests, if connected | Verify the connection and read or edit materials you have authorised | Key and settings: while the integration is connected |
| Yandex Cloud service account key, if connected | Verify access, list available resources and deliver the key to your computer for infrastructure tasks | While the cloud is connected |
| Server addresses and passwords for password-based access | Prepare the SSH configuration on your computer; it connects to your servers from your network | While the server is configured |
| S3 storage key, if connected | Verify access and deliver the key to your computer for file operations | While the bucket is connected |
Integration credentials are encrypted at rest, with the encryption key kept separately from the database. Telegram, Yandex.Disk, Notion and OpenRouter credentials are shown only in masked form. Disconnecting an integration removes its stored credential. Yandex.Disk access is limited to the application folder. Public file links can be opened by anyone who receives them and expire after one week by default
Some keys are delivered to your computer. GitLab and GitHub operations run on your Mac, where a copy of the repository token is kept in the macOS keychain. Repository tokens are not displayed in the account portal, even in masked form. Removing a repository or revoking a device removes its local copy at the next sync; until then it may still work
Yandex Cloud and S3 credentials and server access settings may also be delivered to your computer for agent tasks. Guild verifies connected integrations and retrieves necessary information about available resources. Disconnecting an integration in Guild does not replace revoking its key with the provider when all copies must stop working immediately
S3 uploads can produce signed links usable by anyone who receives them, lasting up to seven days when supported by the storage provider. The link appears in your agent conversation; you decide how to share it
Private SSH keys remain on your Mac and are not stored on the Guild server. The account portal stores the local file path. That path does not provide access to the key on another computer
GitHub commits made by an agent use your name. Guild supplies a hidden …@users.noreply.github.com address so your personal email does not appear in repository history, while authorship remains yours. GitLab uses the project bot
The integration activity log records the time, agent, destination and outcome. It does not include message texts or file contents
Integration calls differ from the encrypted remote channel. Telegram messages, image-generation requests and Notion request and response data are processed in decrypted form by the Guild server to communicate with the selected service. They are not included in the activity log, but technical access during processing is possible. Files uploaded to Yandex.Disk go directly from your computer to Yandex; Guild supplies a one-time upload address
OpenRouter and Notion requests leave Russia and pass through an intermediate node in Kazakhstan to reach those services. This includes image descriptions and reference images for OpenRouter, and selected pages, requests and responses for Notion. The node forwards the data without storing it. Do not send personal data or information that must remain in Russia through these integrations
The remote-control channel is encrypted between devices. Conversations are encrypted on the computer and decrypted on the phone or in the web remote. The relay forwards ciphertext without receiving the decryption key. Using the remote alone does not upload project files to Guild for storage. Separately submitted enquiries, reports and integration calls are processed as described above. For the lock-screen summary, the server sees counts of working and waiting agents, not names, projects or conversation content
We do not sell data or use it for advertising profiling. Apple receives technical data needed to deliver notifications. A connected integration receives the information needed for its requested function and processes it under its own policy. AI providers receive requests through your selected agent engine and connection; this policy does not replace their terms
Website, account portal and web remote
This policy covers website visitors, account holders, app and web-remote users, and people contacting support. Ordinary access does not require biometric data, special categories of personal data or personal identity documents. Do not include unnecessary personal data in enquiries or agent tasks
The account portal uses a technical guild_session cookie lasting up to 30 days. The web remote stores an access ticket and sound preference in the browser; notifications require browser permission. The remote link contains a key in the fragment after # and should be kept private. Details are in the cookies and browser data document
Public pages contain no advertising trackers or web analytics. The server receives connection information to deliver pages and protect the service. Advertising messages require separate, optional consent; unsubscribing does not terminate Guild access
After a manual RU / EN selection, the site stores only the language code in the technical guild_language cookie for up to 365 days, with no user identifier or advertising purpose. When a page opens, it uses your saved choice or browser language preferences. Switching languages does not change the page address. You can manage the preference using the switcher and your browser’s site data settings
Subscription, payments and receipts after billing launches
Billing is not connected yet. After launch, subscription processing will use the account email, order and payment identifiers, amount, period, payment, refund and renewal status, and records of accepted terms and consents. YooKassa receives the information required for payment and receipts. For recurring payments Guild uses a saved payment-method identifier; Guild does not store full card numbers or card security codes
These data enable automatic access, payments, receipts and support. Payment documents and records needed for tax obligations are retained for the statutory period, including after the subscription ends. Withdrawing recurring-payment permission stops new charges and does not require deleting records of past transactions. See payments and refunds
Where data is stored
Databases are hosted in Russia, in Yandex Cloud, Moscow. Recording, organisation, accumulation and storage of Russian citizens’ personal data take place in Russia
Legal basis and processing
Data needed to arrange and provide a subscription are processed to perform the agreement or take steps to enter it at your request. Payment and fiscal records are processed to comply with the law. Where consent is the basis, it is obtained separately from other documents. Visiting the site and reading this policy do not themselves constitute consent
Processing includes collection, recording, organisation, accumulation, storage, updating, retrieval, use, disclosure within the stated purposes, restriction, deletion and destruction, using automated and manual methods. Authorised personnel and infrastructure providers receive only necessary access, subject to confidentiality and protection obligations. Measures include access controls, protected connections and encrypted integration secrets
Data are deleted or anonymised once their purpose is fulfilled unless the law or another applicable basis requires retention. Consent concerning an enquiry can be withdrawn by email; advertising consent can also be withdrawn through unsubscribe. Advertising stops immediately upon receipt of the request. Consent texts are in the documents section
Demo mode
With code TEST-TEST-TEST the app displays a fictional guild. In this mode it makes no network requests and does not collect or transmit data
Your rights
You may request information about your data, correction, restriction or deletion, and withdraw consent by writing to guild@morozov.digital. Processing information is provided within 10 working days, inaccurate data are corrected within 7 working days of receiving supporting information, and data processed on consent are deleted within 30 days of withdrawal unless another lawful retention basis applies. Mandatory payment records are not used for unrelated purposes. You can remove devices and review the connection log in your account portal
Include your account email and the substance of your request. If necessary, we request proportionate information to confirm that the data concern you. You may complain to Roskomnadzor or a court. Requests to stop processing are handled within the time limits of Article 21 of Russian Federal Law No. 152-FZ
Children
The application is intended for professional work and is not directed at children
Changes
New versions appear on this page. Significant changes are emailed to the address used for activation
This is a translation. In case of a discrepancy the Russian version prevails