Security & data handling

Privacy-first, not "zero-retention." Here's the difference.

Your conversations live primarily on your device. The AI runs on hardware we operate ourselves. We keep a small amount of operational data for a short, defined period to keep the service safe and working — and we would rather tell you exactly what that is than round it down to zero.

The life of one request
You send it
Encrypted on your device, TLS 1.2+ with certificate pinning.
Our infrastructure answers
Our model, our hardware. No public AI service, no third-party provider.
A short excerpt is held
A preview plus timestamp and counts, for abuse prevention only.
≤ 30 days
Deleted
Your conversation stays on your device. Never sold, never used for training.

How inference works

Encrypted in transit

Your message and the context needed to answer it travel over HTTPS/TLS 1.2+ with certificate pinning, authenticated with HMAC-SHA256 session tokens.

Our model, our infrastructure

We run our model on infrastructure we operate and maintain ourselves. Your messages are not sent to any public AI service or third-party provider.

Encrypted at rest

On-device data is protected by iOS Data Protection; credentials live in the iOS Keychain. We minimize what we hold so there is less to lose.

What we retain, and for how long

Message excerpts & metadata
A short preview plus timestamp, model, counts, latency, status and the IP used for rate-limiting and abuse prevention.
up to 30 days
Safety review
Content flagged automatically or reported by users, where investigation or legal compliance requires it.
as needed
Account information
Your name and email (Firebase Authentication) and subscription status.
while active, then 30 days
Notification scheduling
Limited scheduling data, if proactive notifications are enabled.
purged within 7 days
Crash & performance
Diagnostics via Firebase Crashlytics, not linked to your conversation content.
up to 90 days

We do not sell your personal information, and we do not use your conversations to train, fine-tune or improve AI models. Content flagged by automated safety systems or reported by users may be reviewed and held longer where that is necessary to investigate abuse or comply with law.

Processed on your device

Read on the phone and included as context only when relevant. The raw data is not stored on our servers.

Conversation history and attachments
Health and fitness data (HealthKit) and Bluetooth device readings
Calendar and reminders, with sensitive details redacted
Approximate location and motion state, with permission
Only the contacts you choose to share

Controls in the app

Revoke health, calendar, email or location access at any time
Delete a conversation, or your whole account, from Settings
Account deletion requests server-side deletion within 30 days
Every real-world action asks first; file changes on your Mac can be undone

Questions about your data?

We answer privacy requests within thirty days.

Contact us