Foyer Tech, Inc. ("Thine," "we," "us," or "our") provides privacy-first intelligence that helps you capture context across your life and work so you can reflect, decide, and act with clarity (the "Services"). We operate in the United States only and do not offer the Services in the EEA/UK. We do not sell your personal information and we do not use your data for third-party targeted advertising.
Consent to Recording and Processing
By creating an account or enabling recording features, you expressly consent to Thine collecting and processing audio captured by your device microphone (including always-on if you enable it), transcripts, summaries, speaker tags, and related usage data as described in this Policy. You may withdraw consent at any time by emailing [email protected]. If you do not consent, do not enable recording.
- Anonymization/De-identification. Where feasible, we apply masking, hashing, tokenization, aggregation, and removal of direct identifiers to create de-identified data for analytics and service improvement. We will not attempt to re-identify de-identified data and require the same of our processors.
- Your Controls. You can start/stop/pause recording, delete audio/transcripts, and disconnect integrations at any time.
- Bystander/Third-Party Consent. Recording laws vary by state. In "all-party consent" states, you must obtain consent from everyone recorded. Thine provides tools (e.g., visible/audible indicators, banners, consent links/QR, auto-pause) to assist, but you are responsible for compliance.
Scope
This Policy applies to Thine's U.S. mobile apps, websites, and any related devices or features that link to it (the "Services"). It covers information collected from you, from your devices and integrations you connect, and from our service providers.
- Account & Contact. Name, email, phone (optional), password hashes, and profile preferences.
- Contacts. If you grant contact access or link a contact to a speaker, we may process contact names, email addresses, phone numbers (including hashed values), and profile photos to label speakers and organize your content.
- Payments. Subscription billing is handled by our payment processor; we store limited billing metadata (not full card numbers).
- Support & Communications. Messages, attachments, and email engagement data (opens/clicks) to improve deliverability (opt-out of non-essential emails anytime).
Audio, Transcripts and Derived Content
- Always-On Listening (Mobile Mic). If you enable always-on, the app may access your device microphone 24/7 (or as configured) to capture ambient speech/sounds for features like memory, search, and reflection.
- Transcripts, Summaries & Insights. We generate transcripts, summaries, and derived insights from your recordings.
- Speaker Recognition/Tagging. With your consent, we create voice embeddings to tag speakers across your recordings for organization and search.
- Context You Provide. Titles, labels, notes, or tags you add.
- Facts, Memory, and Embeddings. Only with your explicit permission, we may store facts, entities, relationships, summaries, and embeddings derived from your recordings or connected services to support memory, personalization, and search.
Integrations You Authorize
Third-Party Apps and Composio. If you connect third-party accounts, such as Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets, Google Slides, Slack, Linear, Notion, LinkedIn, or X/Twitter, we may use Composio as a third-party integration processor to authenticate and operate those integrations. Depending on the service and action you request or authorize, Composio and Thine may process authentication information, connected-account metadata, and the content or metadata needed to search, read, create, update, send, or share items in the connected service.
Connected-app data may include calendar event details, Gmail messages or threads, files and document content, spreadsheet or slide content, Slack messages or channel metadata, Linear issues, Notion pages, LinkedIn information, and X/Twitter content, depending on what you connect and ask Thine to do. The AI assistant may use these connected-service tools to respond to your requests, including by reading relevant account data or taking actions in those accounts when requested or authorized. You can disconnect any time in Thine by reaching out to us at [email protected]. We request the scopes needed for the connected features and actions you authorize. Composio's trust and security information is available at trust.composio.dev.
Device, Web & App Usage
- Device/Log Data. IP address, device/OS, app version, crash logs, event timestamps, diagnostics, and coarse location inferred from IP.
- Location. If you enable location-based features, we may process precise latitude/longitude, inferred addresses, nearby places, and labels such as home, office, or usual places. We may use Google Maps and Google Places APIs for geocoding and place lookup.
- Cookies (Web). Essential, functional, and analytics cookies (no third-party advertising cookies).
We use information to:
- Provide and improve the Services (recording, transcription, summarization, search, reminders, organization).
- Enable always-on listening (if you turn it on) and safety controls (e.g., auto-pause by app/location, chime/LED indicators).
- Power LLM chats. Our contracts prohibit AI providers from training on your data and require prompt deletion (e.g., within 30 days).
- Speaker recognition/tagging to help you group and find content by speaker (opt-in; disable any time).
- Operate integrations and connected-app actions you request or authorize.
- Store and retrieve facts, memory, graph records, and embeddings only when you explicitly permit those features.
- Security, fraud, and abuse prevention, and to enforce our Terms.
- Analytics & product development (using aggregated/de-identified data where feasible).
- Legal compliance and responses to lawful requests.
Third-Party AI Services and What We Send Them
Some Thine features are powered by third-party AI providers. To transcribe your audio, generate summaries and insights, and answer your questions when you chat with Thine, we send the data needed for the specific feature you use to the following providers: OpenAI, L.L.C., Anthropic, PBC, and Google LLC.
What we send. Depending on the feature you use, we may send these providers:
- Audio recordings you capture, so they can be transcribed into text.
- Transcripts and summaries derived from your recordings, to generate summaries, insights, and answers.
- Calendar and email content from integrations you connect, and other connected-app content you request or authorize Thine to use, to prepare and enrich summaries or answers.
- Your chat messages — the questions and prompts you type when chatting with Thine, along with the relevant context needed to answer them.
- Facts, memory, profile context, and embedding source text only when you explicitly permit those features or ask Thine to use that context.
We ask before we send. Before Thine sends your audio, transcripts, connected-app content, chat messages, or explicit-permission facts/memory context to any of these AI providers, we tell you what will be shared and ask for your permission in the app. You can decline, and you can withdraw consent at any time by emailing [email protected]. If you decline, the features that rely on these providers will not be available, but you can continue to use the rest of Thine.
Equal protection. These providers process your data only as our service providers and under Data Processing Agreements that require protections at least equal to those described in this Policy. They are contractually prohibited from using your data to train their models, must retain it only as long as needed to deliver the requested feature (subject to time-bound deletion, e.g., within 30 days) and then delete it, and may not sell it or use it for advertising. You can review their data practices here:
Model Training
We do not use your personal data to train or improve AI models — neither our own models nor those of the third-party AI providers we work with. Your audio, transcripts, summaries, connected-app content, chat messages, facts, and memory context are used only to deliver the features you request, and our agreements with third-party AI providers contractually prohibit them from training on your data.
Cloud Storage and Locations
We store user data with Google Cloud Platform (GCP), located in the United States, and with Cloudflare, Inc. Cloudflare operates a globally distributed network, so data stored with Cloudflare may reside in the data center closest to you — typically within your country or a nearby country — rather than in a single fixed location. Backups and disaster-recovery replicas may also reside in the U.S. Data is encrypted in transit and at rest. These providers act only as our service providers, are bound by Data Processing Agreements, and do not train on or sell your data.
Graph, Memory and Embeddings
When you explicitly permit facts or memory features, we may use Google services, Neo4j graph database infrastructure, and turbopuffer vector search infrastructure to create, store, and retrieve facts, graph relationships, and embeddings needed for memory, search, and personalization. These providers process data only as our service providers, under contractual privacy and security obligations, and do not train on or sell your data.
Thine's speaker recognition may create a voiceprint/embedding derived from your recordings.
- Limited Use. Used only to identify speakers across your recordings.
- No Sale/Ads. We do not sell or use biometric data for advertising.
- Retention and Deletion. Request deletion of voice tags/embeddings by emailing support; we also delete them when you delete your account (subject to legal holds).
- Safeguards. Encryption, segmentation, and role-based access. Where state biometric laws apply, we follow applicable consent, retention, and destruction requirements.
We share information only as follows:
- Service Providers/Processors. Hosting and storage (Google Cloud Platform, Cloudflare, and Vercel), authentication and push notifications (Firebase/Google services), graph and embedding infrastructure (Google services, Neo4j, and turbopuffer), audio processing infrastructure (Modal), public web/profile enrichment providers (Firecrawl, Apify, and Parallel Web), analytics/observability (Google Analytics, Raindrop AI, PostHog, and Meta Business Tools), email communications (Mailchimp), customer support, and payments—bound to our instructions and prohibited from training on your data.
- Connector Infrastructure (Composio). When you connect third-party apps, we may share authentication information, connected-account metadata, and tool inputs/outputs needed to operate those integrations through Composio. See trust.composio.dev for Composio trust and security information.
- Third-Party AI Providers (OpenAI, Anthropic, Google). We share your audio, transcripts, summaries, connected-app content, chat messages, and explicit-permission facts/memory context with these providers only as needed to transcribe, summarize, or answer your chats, and only with your permission. They act as our service providers under Data Processing Agreements, do not train on your data, retain it only transiently (time-bound deletion, e.g., within 30 days), and do not sell it. See "Third-Party AI Services and What We Send Them" above for what we send and how we ask your permission.
- Mapping Providers. If you enable location-based features, we may share latitude/longitude and related place queries with Google Maps and Google Places APIs to infer addresses, nearby places, and location labels.
- Corporate Transactions. If Thine undergoes a merger, acquisition, or asset sale, data may transfer under this Policy.
- Legal and Safety. To comply with law or protect rights, property, or safety.
- With Your Direction/Consent. For example, when you share a clip or connect an integration.
We do not sell personal information and do not share it for cross-context behavioral advertising.
Retention and Your Controls
- Audio & Transcripts. You can delete any item at any time, or reach out to us at [email protected] for deletion.
- Facts & Memory. Facts, graph records, and embeddings are stored only when you explicitly permit memory features. You can withdraw permission or request deletion at any time.
- Account Deletion. Request full deletion by emailing [email protected]. We delete personal information unless retention is required for legal or security reasons.
- Withdraw Consent. Email us to withdraw consent for always-on mic processing, voice tagging, or memory features; we honor your choice going forward.
- Marketing Preferences. Unsubscribe from non-essential emails via footer links.
- Cookies/Analytics. Manage in your browser; essential cookies are required for core functions.
- Integrations. Email support to disconnect an integration from Thine, and you can also revoke access through the third-party account's security controls. Revoking access stops new data flows.
Your U.S. State Privacy Rights
Depending on your state (e.g., CA, VA, CO, CT, UT, OR, TX), you may have rights to access, delete, correct, obtain a portable copy, and opt out of sale/sharing/targeted advertising and certain profiling.
How to exercise: Email [email protected]. We will verify your request (we may need additional info). You may use an authorized agent where permitted. If we decline a request (e.g., cannot verify), you may appeal by replying to our decision; we'll respond with our final determination and how to contact your state AG if you disagree.
California "Shine the Light." We do not disclose personal information for third-party direct marketing. Children/Teens. We do not knowingly sell/share data of consumers under 16.
You are responsible for complying with federal and state recording laws. Do not record where prohibited (e.g., private areas or posted "no recording" zones). Do not record if involved parties do not consent to being recorded.
Security
We use administrative, technical, and physical safeguards, encryption in transit/at rest, role-based access, environment segregation, key management, and regular testing. No method is 100% secure. Report issues to [email protected].
Children's Privacy
The Services are not intended for children under 18. We do not knowingly collect data from children under 18. If you believe a child has provided data, contact [email protected] for deletion.
Third-Party Sites and Services
The Services may link to third-party sites/services. Their privacy practices are governed by their policies. Review those before sharing information.
State Law Disclosures (California)
We do not sell or share personal information for cross-context behavioral advertising.
| Category (Examples) | Sources | Purposes | Disclosed To |
|---|
| Identifiers (name, email, IP, device ID) | You; device | Account, security, support, analytics | Service providers; no sale/share |
| Contacts (names, emails, phone numbers, photos) | You; device contacts | Speaker labels, contact linking, organization | Service providers; no sale/share |
| Customer Records (billing metadata) | You; processor | Subscription & fraud prevention | Payment processor; accounting |
| Commercial Info (plan, purchase history) | You; systems | Provide Services & support | Service providers |
| Internet/Network Activity (usage, logs, cookies) | Device; apps | Operate, secure, debug, analytics | Service providers |
| Geolocation (coarse from IP; precise if enabled) | Device/IP | Security, localization, recording labels, place inference | Service providers; Google Maps/Places |
| Audio/Visual (audio, transcripts, summaries) | Device mic; integrations | Provide features; search/summarize | Cloud/AI processors; no sale/share |
| Biometric/Voiceprints (voice embeddings) | Derived from your audio | Speaker recognition/tagging (opt-in) | Processors under strict controls; no sale/share |
| Inferences, facts, memory, and embeddings | Your permission; Services | Memory, search, personalization, product improvement | Service providers; Google services; Neo4j; turbopuffer |
Third-Party Provider List
We use the following third-party providers to operate the Services. The provider used for a specific user depends on the features, integrations, and purchase channels that user chooses.
- OpenAI. AI transcription, summaries, chat, and context processing. Trust/security: trust.openai.com.
- Anthropic. AI summaries, chat, enrichment, and context processing. Trust/security: trust.anthropic.com.
- Google services. Google Cloud storage and compute, Vertex/Gemini AI and embeddings, Firebase authentication and push notifications, Google Maps/Places, Google Analytics, Google Play, and Google integrations you authorize such as Gmail, Calendar, Drive, Docs, Sheets, and Slides. Trust/security: cloud.google.com/trust-center.
- Cloudflare. Network, security, hosting, and storage infrastructure. Trust/security: cloudflare.com/trust-hub.
- Vercel. Website hosting and deployment for thine.com. Trust/security: security.vercel.com.
- Composio. Connected-app authentication and tooling for integrations you authorize. Trust/security: trust.composio.dev.
- Neo4j. Graph database infrastructure for facts, relationships, memory, and embeddings. Trust/security: trust.neo4j.com.
- turbopuffer. Vector and full-text search infrastructure for memory and embeddings. Trust/security: turbopuffer.com/docs/security.
- Modal. Hosted audio processing infrastructure for transcription, diarization, speaker embeddings, and related audio analysis. Trust/security: trust.modal.com.
- Firecrawl. Public web search and webpage extraction for profile/web enrichment. Trust/security: trust.firecrawl.dev.
- Apify. Public web and social-profile scraping for profile/web enrichment. Trust/security: trust.apify.com.
- Parallel Web. Public web search and enrichment. Trust/security: trust.parallel.ai.
- Raindrop AI. AI observability, diagnostics, and feedback tracking. Trust/security: trust.raindrop.ai.
- Mailchimp. Waitlist, newsletter, and non-essential email communications. Security/privacy: mailchimp.com/about/security.
- Slack. Slack integration you authorize. Trust/security: slack.com/trust.
- Linear. Linear integration you authorize. Trust/security: trust.linear.app.
- Notion. Notion integration you authorize. Trust/security: trustcenter.notion.com.
- LinkedIn. LinkedIn integration you authorize and public profile enrichment when directed or permitted. Trust/security: security.linkedin.com/trust-and-compliance.
- X/Twitter. X/Twitter integration you authorize and public social content enrichment when directed or permitted. Security/privacy: about.x.com/security-and-privacy.
- PostHog. Product analytics like clicks and views, on web or app. Privacy information: posthog.com/privacy.
- Meta Business Tools. Product analytics like clicks and views, on web or app. Privacy information: https://www.facebook.com/privacy/policy.
- Apple App Store. App distribution and purchase processing if you use Apple's app store. Privacy information: apple.com/privacy.
Changes to This Policy
We may update this Policy from time to time. We will post updates with a new "Last Updated" date. For material changes, we will notify you via the Services or email.