Privacy Notice
We hold what you tell your companion, because that is the product. We do not sell it, we do not train advertising models on it, and no member of staff can open a conversation, read a memory or see a mood value.
Every memory shows you where it came from, and you can correct or delete any of them individually — that control is the same screen as the transparency.
You can export everything as JSON, or delete your account and every memory in one action. No email loop, no thirty-day window, no offer to win you back.
Crisis sessions are never recorded against you, which is also why they cannot appear in your export.
What we hold
What you give us directly. Your name, email, date of birth, country and timezone; your companion’s name, voice and temperament; everything you write or say to them; your mood entries; and any health information you choose to record.
What the service generates. Replies, memories inferred from your conversations, and the vector embeddings that let them recall them. Every inferred memory is shown to you with the sentence it came from.
What we collect to keep the service running. Device and session records, error logs, and coarse usage counts. We do not run third-party advertising or tracking cookies.
Why we hold it
To be the companion you built. Continuity is the product. Without memory, Synora is a chatbot that makes you explain yourself twice.
To bill you, and nothing more than that. Payment data is handled by Stripe. We never see or store your card number.
We do not profile you for advertisers. There is no plan under which that changes, which is why the free tier is capped by message count rather than paid for by your attention.
Memory and provenance
Every memory carries where it came from. A memory is marked either “you told me”, for anything you typed or stated directly, or “I noticed this”, for anything inferred from a conversation. An inferred memory also shows the quote and the timestamp it came from.
Editing is allowed, not just deleting. A wrong inference is more common than an unwanted one, and correcting it is the point.
Deleting a memory deletes its vector too. The row and the embedding behind it are removed in the same transaction. They do not keep a copy elsewhere.
You can delete by category. All health facts, or all inferred facts, in one action — because someone withdrawing health consent should not have to delete memories one at a time.
Health data
Health information is special-category data. We ask for it separately from the Terms, we record what you agreed to, when, and under which jurisdiction, and we do not process it until you have.
Withdrawing consent deletes what it covered. Withdrawal takes effect in the same request, including the health-derived memories and their vectors.
Where a region is unknown, we apply GDPR. Nothing is pre-ticked, in any region.
Crisis sessions
Nothing you do in crisis mode is logged against you. Opening the breathing screen, reading a helpline list or working through a talk-down produces no analytics event and no record tied to your account, unless you explicitly ask us to keep a note of it.
This is why crisis sessions are absent from your export. There is nothing to include. We never recorded it.
Internally it exists only as a count. Our own staff see a seven-day aggregate with no ability to drill into it, and that limit is enforced in the API rather than hidden in an interface.
Who else touches it
Four processors, each with the minimum. Anthropic for the conversation model, ElevenLabs for their voice, Deepgram for speech recognition, and Stripe for payment. Each receives only what its job requires.
No staff member can read your conversations. There is no “view as user”, and no admin screen can open a conversation, read a memory or see a mood value.
Support access is yours to grant. If a support case needs context, you grant it explicitly, it is scoped to what is needed, it expires after 24 hours, and every grant and every read is written to an append-only audit log.
Taking a copy
Everything, as JSON plus your voice recordings. The export downloads straight to your device. We do not email it — a link in an inbox is a copy of your health data sitting somewhere else.
- Account, profile, your narrative
- Your companion — name, voice, temperament
- Every conversation and voice transcript
- All memories, with where each came from
- Conditions, allergies, medications, goals
- Mood history and health logs
- Goals, habits, tasks, journal entries
- Consent record, with dates and jurisdiction
- Subscription and payment history
- Notification settings and language
- Timezone and region
- Devices and sessions
- Support access grants and their expiry
- Voice recordings
Crisis sessions are not included, because we never recorded them.
Erasure
One action, and it runs immediately. No waiting period, no confirmation email, and no “you have 30 days to change your mind”.
What goes. Your companion, every conversation and voice transcript, every memory and its vector, your health profile, your mood and health history, your plans and journal, and your voice recordings.
What stays, and only this. Invoices, for seven years, because tax law requires it. They hold a name and an amount — nothing about your health or your conversations.
An active subscription is cancelled as part of it. We say so before you confirm, including that the current period is not refunded.
Security and retention
Encrypted in transit and at rest. Access to production data is restricted, logged, and reviewed.
Memory has a window, and it is enforced by a job. Free keeps 7 days, Companion 90, Inner Circle keeps it until you delete it. Rows past the window are pruned automatically rather than lingering.
Your rights and contact
Most rights you can exercise yourself. Access, correction, portability and erasure are all buttons in your account, not a request form and a wait.
For anything else, write to us. privacy@devoff.dev. You also have the right to complain to your local supervisory authority.