Privacy Policy

Last updated: 2026-07-26

Summary

  • Many retained personal text fields are encrypted on your device and stored as ciphertext.
  • The service cannot decrypt that ciphertext without the key held on your device. Some account, relationship, timing, completion, preference, and delivery data remains readable so the service can function.
  • If you ask for an optional AI response, the moment you submit is sent over TLS for that response. When Memory context is on, a small selection of recent, active things you chose to retain is sent with it. Nothing new is added to your vault unless you choose Keep.
  • Voice capture, provider-backed playback, and journal summaries are separate, optional actions. The app shows what will be sent before a user-authored recording or text leaves your device for one of those requests.
  • No data brokerage. We don’t sell or rent your personal content.
  • Account deletion removes active service data; residual backup copies expire under our infrastructure provider's rolling retention policy. The signed-in Data sovereignty screen shows whether the current maximum has been operator-verified.
  • After active account and product data is removed, a raw account/origin sweep locator has an application-enforced 48-hour use deadline and a matching TTL index, solely to remove writes or exact provider-owned Customers that finish late. A separate digest-only receipt has a 96-hour use deadline and TTL index so delayed signed billing events can be reconciled. Mongo TTL removal is asynchronous, so the application stops using an expired record even if physical removal has not run yet. The digest-only receipt contains no raw account, registration, email, credential, product-content, or payment-provider identifier.
  • Exception for an unresolved provider erasure: if automatic payment-provider cleanup cannot finish before that normal receipt expires, an operations issue can retain only the exact purpose-separated cleanup digest, deletion time, and accepted or rejected relationship digests while it remains open, for no more than 24 months. It contains no raw account, email, Customer, subscription, or product-content identifier, is used only to finish the requested deletion, and is removed from the issue when cleanup succeeds; the resolved issue then expires within 30 days.
  • During checkout, a separate automatic recovery issue can retain one exact purpose-separated cleanup digest and one random, non-identifying attempt digest for up to 30 days. It bridges a Customer-creation request to the local Customer-id commit, contains no raw account id, email, Customer id, or product content, and cannot be manually acknowledged. The exact digests are removed when recovery resolves.
  • A purpose-limited, pseudonymous marker can remain for up to 24 months after a trial or account deletion to prevent repeated introductory trials. It contains neither your raw email address nor a raw payment-method fingerprint.

Data We Process

Account basics: email, password hash (never your passphrase), subscription status.

Operational service data: timestamps, relationships between records, completion events, preferences, push-delivery state, subscription state, and minimal security and reliability logs.

Registration and trial-abuse data: a network address used transiently for challenge verification and rate limiting, persisted secret-derived IP/email rate-limit keys, registration timing, verification attempts, Cloudflare Turnstile verification results, Stripe customer/subscription history, and keyed HMAC digests used to recognize a previously redeemed trial and the exact subscription relationship that redeemed it. The pending-registration record and application logs do not retain the raw network address. We do not store a full card number, raw card fingerprint, or raw email address in the trial-redemption ledger.

Client-encrypted content: many user-authored note, focus, memory, pattern, and Continuity Thread text fields are encrypted on your device before storage. This includes Thread titles, anchors, future-self markers, saved source context, decision notes, and closure reasons. The operational fields described above are not all client-encrypted.

Optional AI response content: when you deliberately submit a moment for a response, we process that text in readable form. If Memory context is on, we also process a small selection of your recent active companion Direction, Chapter, Memory, or Pattern records. Older companion records labelled Thread can also be part of that selection. The new client-encrypted Continuity Threads and deterministic Return Brief are not sent to an AI provider by opening or invoking them. You can turn Memory context off. AI response processing is separate from your encrypted vault, and the response remains transient unless you choose Keep.

Optional voice and summary content: when you start provider-backed voice capture, microphone audio is processed for transcription. When you deliberately generate a journal summary, that entry text is processed in readable form for that request. Provider-backed speech may also process the text selected for playback. These actions are separate from saving or opening a note, journal entry, room, or Wisdom card.

How We Use Data

  • Provide and secure the service (account creation, auth, billing, support).
  • Prevent automated registration and enforce one introductory trial per person and payment method without using those signals for advertising, psychological inference, or product personalization.
  • Maintain security and reliability using minimal operational logs, without sending in-app pageviews or what you write to marketing analytics.
  • Measure whether the user-invoked Continuity Thread and Return experience is useful without recording Thread text, titles, topics, source IDs, Thread IDs, linked-product record IDs, or inferred psychology. This first-party evidence uses bounded choices such as fit, usefulness, agency, days-away range, and disposition; it is kept separate from advertising conversions and is not dispatched to advertising providers.
  • Run aggregate analytics on public pages only after you allow it; the analytics container is not loaded before that choice and is excluded from the authenticated app.
  • If you explicitly allow advertising measurement, we may retain an ad click identifier long enough to connect a public campaign visit to aggregate outcomes. We do not use personalized advertising, remarketing, cross-site profiling, or inferred sensitive traits.
  • Compose an optional, finite AI response when you deliberately ask for one.
  • Transcribe, summarize, or speak selected content when you deliberately start the corresponding optional action.

Storage & Retention

Account and service data is retained while your account is active and as needed to provide the service. Account deletion removes active records associated with your account. Residual copies in protected backups expire through rolling retention windows, subject to security, fraud-prevention, and legal obligations. We do not publish a fixed backup maximum unless current provider evidence has been recorded and is visible in the signed-in Data sovereignty screen.

To enforce the one-trial rule after an account or Stripe customer is deleted, we can retain an HMAC of the normalized trial identity and, when Stripe provides it, an HMAC of the payment-method fingerprint. We also retain an HMAC of the accepted Stripe subscription id so duplicate event delivery is idempotent and a different subscription cannot claim a second trial. The marker records only redemption status and bounded timestamps. Its default automatic expiry is 24 months. It is not joined to your private product content or used for marketing.

Account deletion uses a write fence, a delayed final sweep, and two purpose-limited records. A raw account/origin locator supports additional database and exact provider cleanup and has an absolute 48-hour application use deadline plus a TTL index. A digest-only receipt supports delayed signed billing-event reconciliation and has an absolute 96-hour application use deadline plus a TTL index. TTL removal is asynchronous, but expired records are rejected by the application. The digest-only receipt contains no raw account, registration, email, credential, product-content, or payment-provider identifier.

If payment-provider erasure remains unresolved beyond the normal receipt window, an exceptional operations issue can retain the exact purpose-separated cleanup digest, deletion time, and accepted or rejected relationship digests only while retrying that erasure, for no more than 24 months. It contains no raw account, email, Customer, subscription, or product-content identifier and is not used for product analytics or marketing. Verified cleanup removes the actionable digest and shortens issue expiry to no more than 30 days.

A checkout Customer-binding recovery issue can retain one exact purpose-separated cleanup digest and one cryptographically random, non-identifying attempt digest for no more than 30 days. It is used only to recover or safely compensate a Customer creation whose local binding may be ambiguous. It contains no raw account id, email, Customer id, or product content; resolution removes both actionable digests.

Original microphone audio is not written to the Macrofocus product database. During streamed transcription, audio chunks can remain in server memory while the capture is active and are scrubbed when the session finishes or after ten inactive minutes. The resulting transcript is returned to your device.

Third-Party Processors

We use trusted providers for infrastructure, analytics, and payments (e.g., hosting, error tracking, Stripe). Cloudflare Turnstile processes registration challenge data to help distinguish legitimate use from automated abuse. We also use AI and voice providers only for actions you deliberately start, such as an optional companion response, voice transcription, journal summary, or provider-backed playback. Processors receive only the information needed for their role. For a companion response, the AI provider receives the submitted moment and, when Memory context is on, a small selection of recent active things you chose to retain, not your encrypted vault as a whole.

OpenAI states that API inputs and outputs are not used to train its models by default. Unless our account has a separately approved stricter retention mode, OpenAI may retain content in abuse monitoring logs for up to 30 days. ElevenLabs standard API mode can retain request history and may use newly submitted data to improve models unless the account has opted out; zero-retention mode is available only to eligible accounts. The signed-in Data sovereignty screen reports which stronger controls have actually been operator-verified. We do not describe a control as active merely because a provider offers it.

Security

  • Client-side encryption for covered personal text fields; key custody remains with you and lost keys cannot be recovered by the service.
  • TLS in transit and infrastructure encryption at rest, in addition to client-side ciphertext for covered fields.
  • Strict access controls, logging, and regular security updates.

Your Choices

  • Delete your account and associated active service data from Settings. The raw deletion sweep locator with a 48-hour use deadline, digest-only billing receipt with a 96-hour use deadline, bounded pseudonymous trial-redemption marker, and processor records required for fraud prevention, tax, payment, or legal obligations are exceptions described above.
  • Download a readable JSON copy of your user-authored product records from Settings. Covered fields are decrypted on your device, and the downloaded file is not automatically encrypted.
  • Use the rooms and encrypted memory without asking for an AI response.
  • Turn Memory context off to exclude retained records from future AI responses while leaving those records encrypted in your vault.
  • Choose whether an AI response is kept in encrypted memory.
  • Use text entry and original journal entries without starting voice transcription, provider-backed playback, or an AI summary.
  • Keep optional public-site analytics off, allow it, or change that choice later from the site footer.

Contact

For privacy questions or requests: [email protected]