CoAPP
OverviewPrivacySupport

CoAPP Desktop / Privacy

Privacy policy.

What stays on your Mac, what goes to Microsoft, and the choices you have.

Effective and last updated:

1. About this policy

This policy covers CoAPP Desktop for macOS, developed by TSUGAS (“we”, “us”), and the CoAPP product and privacy pages on this website. CoAPP is an independent client for Microsoft 365 Copilot. You sign in with Microsoft; there is no separate CoAPP account.

CoAPP saves app data locally and connects to the Microsoft services you choose to use. Prompts and attachments you submit leave your device for processing by those services. CoAPP is not an offline language model.

The app does not send a routine copy of your conversations, attachments or Microsoft sign-in credentials to a TSUGAS server. It does not include advertising, a TSUGAS usage-analytics service or a TSUGAS model-training service.

2. Data the app handles

Data used to provide CoAPP’s features
DataHow it is used and stored
Microsoft sign-inMicrosoft handles authentication in its sign-in pages. Session cookies and related browser data are kept in CoAPP’s local app profile so the app can maintain your signed-in session.
Conversations and agentsPrompts, replies, conversation identifiers, selected agents and group settings are stored locally to display and continue your threads. Submitted prompts and relevant context are processed by Microsoft services. Aggregate sends the question to each selected agent.
Files and imagesFiles you attach are sent to the services handling your request. Retrieved files and images may be cached locally for display or preview. Downloads and exports are saved where you choose.
Preferences and diagnosticsAppearance, text size, connection settings and the Local API pairing token are stored locally. Local diagnostic records can include connection status, error details and file-retrieval status to help troubleshoot the app.

CoAPP does not automatically upload these local diagnostic records to TSUGAS. If you choose to send a report or screenshot for support, review its contents before sharing it.

3. Microsoft and your organization

Microsoft receives the information needed to authenticate you and provide the services you use, including submitted prompts and attachments. Microsoft’s own service pages may use cookies, diagnostics and other technologies under its policies.

Your license, account type and organization determine which agents and information you can access. An agent may use additional services configured by its publisher or your organization. Review those services’ terms before sharing sensitive information.

For work or school accounts, your organization may administer access and set retention, auditing and other data policies. Requests about information held in those services should go to Microsoft or your organization’s administrator. Processing and storage locations depend on the applicable service arrangements.

See the Microsoft Privacy Statement and Microsoft’s guidance on your organization’s privacy information. Apple’s distribution and diagnostic services are governed by the Apple Privacy Policy.

4. Optional Local API

The Local API is off by default. If you enable it, compatible tools on your Mac can connect using a pairing token and submit requests through your signed-in Microsoft session. The app’s managed API listens on the local loopback address.

A connected tool can receive the responses to its requests and may retain or transmit them under its own policy. Only give the pairing token to tools you trust. Disable the Local API in CoAPP when you no longer need it.

5. Retention and deletion

CoAPP retains history and preferences locally so you can return to them. Saved conversation history is limited to the most recent 100 conversations; export any records you need to keep separately. Sign-in data and cached previews may remain across app restarts. CoAPP does not promise a fixed automatic deletion period for these cached files.

  • Conversations: use the conversation’s delete control to remove it from CoAPP’s saved history.
  • Sign-in: sign out through the Microsoft account interface in the app. Signing out does not delete your saved CoAPP conversations or files.
  • All local app data: quit CoAPP and remove its application data, including its profile or sandbox container. The location depends on how the app was installed; contact us if you need help locating it. Deleting only the app may leave this data behind.
  • Downloads and exports: delete these separately from the folders where you saved them. Copies in backups or shared locations are managed separately.

Local deletion does not delete Microsoft’s copy. To remove service-side conversations or uploaded content, use Microsoft’s controls or contact your organization’s administrator. Removing a conversation from CoAPP also does not guarantee removal of separately cached previews or downloaded files.

6. Support and this website

If you email us, we receive your email address, message and any attachments you send. We use that information to handle your request and keep the correspondence needed to follow up. Our email provider processes the message to deliver and store it. You can request deletion of support correspondence using the contact address below, subject to any applicable retention obligations.

These CoAPP pages do not add analytics scripts, advertising trackers or third-party fonts, and do not set cookies. The website host may keep ordinary access and security logs, such as IP addresses, requested pages, browser information and request times. Following an external link takes you to a service with its own privacy practices.

7. Security

CoAPP uses HTTPS for Microsoft web services and stores app data within your macOS user environment. Local access controls do not amount to a separate encrypted vault: someone with access to your Mac account, backups or a trusted connected tool may be able to access the data available there.

Keep your device and account protected. Avoid sending passwords, session tokens or confidential documents in support requests. No storage or transmission method can provide an absolute security guarantee.

8. Children

CoAPP is a productivity tool and is not directed at children under 13. We do not knowingly collect their personal information through support. If you believe a child has sent personal information to us, contact us so we can address it. Microsoft account eligibility is governed separately by Microsoft’s terms.

9. Changes and contact

We will update this page when CoAPP’s data practices change and revise the date at the top. Any new processing that requires permission will be subject to the applicable consent requirements.

For privacy questions, requests about information you have sent to TSUGAS, or help removing local CoAPP data, contact:

TSUGAS — CoAPP support
benson.chuang@tsugas.com