Corybycratesystems
Back to Cory

AI usage policy

Effective 3 September 2026 · Last updated 3 September 2026

The short version. Cory is built on Claude, from Anthropic, and runs on your Claude account. Only the context needed for the request you made is sent. Your content is not used to train any model, ours or anyone else’s. It gets things wrong, so read anything you are going to act on.

This policy sits alongside our privacy policy and terms of service. It exists because “we use AI” is not a disclosure, and because you cannot judge whether to trust an assistant that has access to your machine unless you know what it does with what it sees.

1. What the system is

Cory is a background service on your Mac. When a message addresses it, Cory assembles the context for that request and sends it to Anthropic’s Claude models over the API, using your Claude subscription or API credentials. The model returns text; Cory decides what to do with it — reply in the conversation, write a Notion page, create a file, or run a command you asked for. There is no other model, no model of ours, and no intermediary service operated by Crate Systems.

2. What gets sent, and what does not

Sent to the model, for the request you made:

  • the message that addressed Cory;
  • enough of the surrounding conversation to make it make sense, including a follow-up like “make it vegetarian” that amends what came before;
  • the participants’ display names or handles, so it knows who is speaking and what they are allowed to ask for;
  • results Cory gathered on your instruction — the contents of a file you asked it to read, output from a command you asked it to run, search results from your message history when you asked it to search;
  • data from an account you connected, when the request needs it — the calendar events in the window you asked about, or the Notion page you asked it to update. Only the part the request needs, never the whole calendar or workspace.

Not sent:

  • conversations you did not involve it in, unless you explicitly asked it to search your history;
  • your files at large. It reads what a request requires, not the disk;
  • your Claude credentials or third-party authorization tokens, which stay on your Mac.

3. Training

  • Crate Systems does not train, fine-tune or evaluate any model on your content. We do not have your content.
  • Content submitted through Anthropic’s API under its commercial terms is not used to train Anthropic’s models. Your account’s own settings and the terms you accepted with Anthropic govern that relationship, and you can check them directly.
  • Data obtained from a connected Google account is never used to develop, improve or train generalized AI or ML models. See the Google user data section of the privacy policy.

4. What it is not good at

The failure modes are predictable, so they are worth knowing:

  • It can be confidently wrong. A name, a date, a price or a citation can be invented and will not look invented. Anything factual that matters should be checked against the source.
  • It is not a professional adviser. Nothing it produces is legal, medical, financial, tax or safety advice, and it should not be relied on as such.
  • Recommendations are not verified availability. It cannot see a restaurant’s book, a flight’s seat map or a shop’s stock. A suggestion is a place to start calling, not a reservation.
  • It can misread an instruction. On a machine where it can change files, that has consequences. Keep backups.
  • Prompt injection is real. Text in a file, a web page or a message from someone else can contain instructions aimed at the model. Cory constrains what non-owners can ask for, but no current system is immune. Do not point it at content you do not trust and then let it act unsupervised.
  • It can be biased or stale. Model output reflects its training data, which has a cutoff and is not neutral.

5. Where a person stays in the loop

Cory is designed so that the consequential step is yours. It replies, drafts, writes the page, and generates the file. It does not send an invoice to a client, spend money, sign anything, or make a decision on your behalf. When it is asked to do something on the machine, that comes from the owner of the machine, in an instruction the owner typed.

Before you act on Cory’s output in a way that is expensive, public or hard to reverse, read it.

6. Speed, and why we tell you the number

A reply typically takes 40 to 60 seconds. Roughly half of that is noticing the message, and roughly half is the model thinking. Cory sends an acknowledgement straight away so you know it heard you. We publish the number rather than implying it is instant, because an assistant you are unsure heard you is worse than a slow one.

7. Permissions, and who can ask for what

  • The owner of the Mac can direct Cory to read and write files, run commands, and search the full message history on that machine.
  • Everyone else in a conversation gets a restricted version: it can answer, search within what it is permitted to see, and write to Notion. It cannot run commands, and it cannot reach the machine’s files.

An assistant with a shell should not take orders from whoever is in the group chat.

8. Prohibited uses

You must not use Cory to generate or assist with material that is unlawful; to impersonate a person or organization in order to deceive; to produce content that sexualizes minors; to harass, defraud or discriminate against anyone; to generate disinformation for distribution; to develop weapons or malware; to make an automated decision about a person’s employment, credit, housing, insurance or legal rights without meaningful human review; or in any way that breaches Anthropic’s usage policies. These sit on top of the acceptable-use terms in the terms of service.

9. Disclosure to other people

Cory replies in your conversations, which means other participants read its output. It identifies itself: its acknowledgement is written in its own name, and it does not pretend to be a person. If you use it in a professional context where the other party needs to know they are reading machine-generated text, telling them is your call and your responsibility.

10. Changes and questions

Model providers change, and this policy will be updated when the facts do. The date at the top reflects the last change. If something here is unclear, or you think we have described the system inaccurately, write to hello@trycrate.net — that is a correction worth making.

Corybycratesystems

An assistant that lives in your Messages app and can do things on your Mac.

Contact usBack to top

Occasional notes on what Cory can do. For the installer, use the button at the top of the page.

Privacy policyTerms of serviceAI usage policyhello@trycrate.net
Powered by crate systems

© 2026 Crate Systems. Apple, macOS and iMessage are trademarks of Apple Inc. Cory is not affiliated with Apple, Notion Labs or Anthropic.