Privacy Policy

How Engram handles conversation and contact data

Engram helps you remember conversations by recording sessions you explicitly start, preparing notes from those sessions, and saving editable contact cards and follow-up reminders.

Effective date: May 3, 2026

Review note: this page should be rechecked when Engram's providers, retention settings, or launch data practices change.

Information We Collect And Use

Account Information

If you create an account, Engram uses your email address and Supabase account identifier for sign in, password reset, email confirmation, account deletion, and cloud contact-card sync.

Audio And Transcripts

Engram records audio only after you explicitly start a session. Audio may be sent to Engram's backend and OpenAI to create transcripts and conversation notes. Engram's backend does not intentionally store raw audio after processing. The app stores local recordings, session history, transcripts, summaries, notes, and evidence snippets locally on your device while the session remains saved.

Contact Cards And Follow-Ups

Engram stores saved people, names, companies, titles, LinkedIn URLs, notes, tags, follow-up suggestions, follow-up reminders, and related conversation context locally on your device. If you are signed in and cloud sync is available, Engram syncs saved contact cards to Supabase so they are tied to your account.

Profile Context And Profile Lookup

You may provide profile context such as your name, school, major, company, role, LinkedIn URL, and goals. Engram uses this context to improve conversation notes and profile matching. When profile lookup is enabled, Engram may send names, companies, roles, schools, and related context to Engram's backend, OpenAI, and SerpApi-backed search to find likely public profile matches.

Notifications

Engram can schedule local follow-up reminders and live insight notifications if you allow notifications. Reminder content may include a saved person's name or an AI-generated live cue. Engram does not currently collect push notification tokens for a server-side push service.

Diagnostics And Service Logs

Engram's backend records request metadata needed to operate and protect the service, such as route, status code, latency, provider, operation, token counts when available, API request counts, and error type. Source-level backend logs are designed not to include raw audio, full transcripts, request bodies, access tokens, service-role keys, or provider API keys. Production hosting providers may also generate infrastructure logs such as IP address, timestamp, and request metadata.

How We Use Information

Engram uses information for app functionality: account access, session transcription, contact-card creation, profile matching, live conversation cues, follow-up reminders, cloud contact-card sync, account deletion, rate limiting, fraud and abuse prevention, reliability, and support.

Engram does not use your data for third-party advertising and does not sell your data. Engram does not currently use data for tracking as Apple defines tracking for App Store privacy labels.

Third-Party Processors

Engram uses:

Before publishing this policy, verify the production accounts, regions, data processing terms, and retention settings for each provider.

Storage And Retention

Local Data

Session history, transcripts, local recording files, saved people, plans, settings, profile context, reminder state, and profile lookup cache are stored locally on your device unless a future release explicitly adds cloud backup for those data types.

Cloud Data

At launch, Engram cloud sync is contact-card-only. Signed-in users may have contact cards stored in Supabase. Engram does not currently market or provide full cloud backup for recordings, transcripts, session history, planned conversations, settings, or personalization context.

Provider Retention

OpenAI API platform data handling is governed by OpenAI's API data controls and applicable account settings. SerpApi and Supabase processing is governed by their applicable terms, privacy, security, and data processing documents. Verify current provider retention settings before publishing this policy.

Deletion Choices

Clear History removes saved sessions, tracked local recording files, people, profile options, and reminders from the device. It does not delete your Engram account or cloud-synced contact cards.

Reset Local Data clears local sessions, tracked local recording files, people, plans, settings, profile context, and reminders on the device. It does not delete your Engram account or cloud-synced contact cards.

Delete Account permanently deletes your Supabase Auth account and cloud contact cards, then clears local app data on that device. Some provider or infrastructure logs may remain for security, abuse prevention, legal, or backup purposes according to provider retention policies.

Security

Engram uses HTTPS for backend requests, Supabase Auth for user authentication, backend service-role credentials only on the server, row-level security for cloud contact-card tables, backend rate limits, upload safety limits, and source-level logging controls that avoid raw request bodies and secrets.

Children

Engram is not intended for children under 13. Do not use Engram to record or process a child's personal information.

Changes

We may update this privacy policy as Engram changes. The effective date above will be updated when the policy changes.

Contact

Privacy contact: seharrington@wm.edu

Support URL: https://sammyharry.github.io/noted/support.html