Version: draft 0.1 | Effective date: [DATE] | Controller: [LEGAL ENTITY NAME], [ADDRESS] | Privacy contact: [PRIVACY EMAIL]
1. Plain summary #
- Your conversations, files, memories, and settings live in your own data store on our servers. Staff cannot read them in ordinary operation.
- Optional things are off until you turn them on in the first-run privacy prompt or in Settings: telemetry, screen-watching memory, the daily export to your Google Drive, quality sharing, and predictive text. Each choice is recorded in a consent log you can read.
- We do not sell your personal information and we do not share it for cross context advertising. We use no third party analytics in the apps.
- We do not use your content to train models unless you opt in later.
- You must be 18 to hold an account. Parents can create managed child profiles with strict defaults.
2. What we collect and why #
| Category | Examples | Purpose | Basis (GDPR, counsel to confirm) |
|---|---|---|---|
| Account | Email, name, sign-in credentials (passkey public key, Google subject id), persona settings | Run the account | Contract (Regulation (EU) 2016/679, 2016, Art. 6(1)(b)) |
| Content | Conversations, prompts, outputs, files, artifacts, memories, projects | Provide the Service | Contract |
| Usage and billing | Credits, usage events, invoices, plan | Billing, fraud, margin control | Contract; legal obligation; legitimate interests |
| Device and diagnostics | Version, platform, crash info; system summaries only if you opt in | Reliability | Consent for optional items; legitimate interests for security |
| Screen-watching memory (opt-in, desktop only) | Text extracted from your screen, app name, hashed window title, time | Build memories you can see and delete | Consent (Art. 6(1)(a), Art. 7) |
| Connected services | Tokens for Google or others you connect, data you let us read | Do what you ask | Consent; contract |
| Support and safety | Messages to support, abuse reports, moderation records | Safety, legal duties | Legitimate interests; legal obligation |
| Health related content | Anything you type or upload about health | Only to answer you | Consent where Art. 9 applies (Regulation (EU) 2016/679, 2016, Art. 9(2)(a)) |
3. Where data is held, and the daily export #
Operational data is stored with our infrastructure provider in per user and per organization stores. Conversation content is encrypted under keys we manage; counsel and security to confirm the exact statement we may make about staff access. If you turn on the daily export, we write a copy to a folder in your own Google Drive using access you granted; revoking the grant stops it. We do not copy your content outside our production account except the disaster recovery arrangements in section 9, and what you export.
4. Screen-watching memory (opt-in) #
Off by default. Desktop only. Never for child profiles. When on, your device recognizes text on screen, removes patterns such as card numbers and one-time codes (best effort, not perfect), skips apps on your exclusion list, and shows a visible indicator. In the recommended mode no image leaves your device. In the separate enhanced mode a reduced size image is sent, read for text, and deleted within 30 minutes at most. Extracts become memories you can view and remove, kept 7, 30, or 90 days or never (default 30) and then summarized. Screens can show other people's information and employer or school material. Do not turn this on for work or school devices without permission, and do not capture conversations where people have not agreed. See the DPIA draft for the risk assessment (Regulation (EU) 2016/679, 2016, Art. 35).
5. Children #
We do not knowingly allow accounts for under 13 and we delete one when we learn of it (Children's Online Privacy Protection Act of 1998, 15 U.S.C. § 6502; Federal Trade Commission, 2025, 16 C.F.R. § 312.2 and § 312.3, actual knowledge; counsel to confirm the deletion authority). Child profiles are created and managed by a parent or guardian, who gives consent and can review and delete the child's information (16 C.F.R. § 312.5, § 312.6). Child profiles have no screen-watching memory, no calling, no ad or analytics use, and limited AI features. Counsel to confirm the parental notice content (16 C.F.R. § 312.4).
6. Who we share with #
Service providers acting on our instructions (see the Subprocessor List): infrastructure, model and media providers, payments, email, telephony (if enabled), push services, error tracking if added. Law enforcement or other requests that meet legal standards. A buyer in a business transfer, with notice. Anyone you tell us to share with. We do not sell or share personal information for cross context behavioral advertising (California Consumer Privacy Act of 2018, § 1798.120, § 1798.135).
7. Retention (proposed; counsel to confirm) #
| Data | Kept |
|---|---|
| Conversations, messages, artifacts, files | Until you delete; trash 30 days |
| Account | 14 day cancel window, purge within 30 days after, backups age out within 35 days |
| Memories | Until you delete |
| Connector tokens | Until revoked |
| Recordings and raw meeting audio | 30 days (organization setting); audio deleted after transcription by default |
| Screen extracts | 7, 30, or 90 days or never (default 30); images at most 30 minutes |
| Usage archive | 25 months |
| Ledger and invoices | 7 years (finance to confirm), pseudonymized after deletion |
| Audit records | 400 days active; 7 years archived with opaque ids |
| Logs and telemetry | 7 days platform logs, 90 days shipped logs; telemetry 3 months, diagnostics 180 days |
| Safety evidence | As the law requires, including one year preservation for certain child safety reports (REPORT Act, 2024) |
A legal hold can pause deletion; we tell you when that happens. Counsel to confirm the GDPR Art. 17(3) exceptions we rely on.
8. Your rights #
Access, correction, deletion, portability, objection, restriction, withdrawal of consent, and limiting use of sensitive data, as the law of your place gives them (Regulation (EU) 2016/679, 2016, Arts. 15 to 22; California Consumer Privacy Act of 2018, §§ 1798.105 to 1798.121). Use Settings, or write to [PRIVACY EMAIL]. We answer within one month, extendable by two (Regulation (EU) 2016/679, 2016, Art. 12(3)), and within 45 days, extendable once by 45 (California Consumer Privacy Act of 2018, § 1798.130(a)(2)). You may complain to a supervisory authority. We do not discriminate for using rights.
9. Security, transfers, and breaches #
We use encryption in transit and at rest, access controls, audit logs, and a security program (see the threat model). Disaster recovery copies are held in a separate account and encrypted. Data may be processed in the United States and elsewhere; for EU and UK users we will use [DPF certification and/or standard contractual clauses] (Commission Implementing Decision (EU) 2021/914, 2021; Commission Implementing Decision (EU) 2023/1795, 2023). An EU residency option is planned for organizations. We notify authorities and users of breaches within the legal deadlines, which include 72 hours to a supervisory authority where feasible (Regulation (EU) 2016/679, 2016, Art. 33, Art. 34).
10. Cookies and device storage #
The web apps use only essential storage (sign-in, preferences). No advertising or analytics cookies. Counsel to confirm the exemption wording (Directive 2002/58/EC, 2002, Art. 5(3)).
11. Health and sensitive information #
We are not a health care provider. HIPAA does not apply to the consumer Service as designed; if we ever receive records from a provider for you, that changes and a separate notice applies (U.S. Department of Health and Human Services, n.d.). State consumer health data laws may apply (Washington My Health My Data Act, 2023). Counsel to confirm. Sensitive personal information is used only to provide what you ask (California Consumer Privacy Act of 2018, § 1798.121).
12. Changes and promises #
We will post changes and notify you of material ones. We treat the statements in this policy as promises we must keep; misleading privacy claims can be an unfair or deceptive practice (Federal Trade Commission Act, 1914; counsel to confirm). If users in the United Kingdom are admitted, UK data protection law applies as well (Data Protection Act 2018, 2018; counsel to confirm).
Open questions for counsel (this document) #
- Basis table and Article 9 consent wording for incidental health content.
- Statement about staff access to encrypted content that is accurate and not overclaiming.
- Consent ledger rows retained after deletion (BQ-18, Q23).
- EU and UK representative, transfer mechanism, and DPO need (Regulation (EU) 2016/679, 2016, Arts. 27, 37).
- Whether the Washington and other state health data laws require a separate consumer health data policy.