Information We Collect And Use
Account Information
If you create an account, Engram uses your email address and Supabase account identifier for sign in, password reset, email confirmation, account deletion, and cloud contact-card sync.
Audio And Transcripts
Engram records audio only after you explicitly start a session. Audio may be sent to Engram's backend and OpenAI to create transcripts and conversation notes. Engram's backend does not intentionally store raw audio after processing. The app stores local recordings, session history, transcripts, summaries, notes, and evidence snippets locally on your device while the session remains saved.
Contact Cards And Follow-Ups
Engram stores saved people, names, companies, titles, LinkedIn URLs, notes, tags, follow-up suggestions, follow-up reminders, and related conversation context locally on your device. If you are signed in and cloud sync is available, Engram syncs saved contact cards to Supabase so they are tied to your account.
Profile Context And Profile Lookup
You may provide profile context such as your name, school, major, company, role, LinkedIn URL, and goals. Engram uses this context to improve conversation notes and profile matching. When profile lookup is enabled, Engram may send names, companies, roles, schools, and related context to Engram's backend, OpenAI, and SerpApi-backed search to find likely public profile matches.
Notifications
Engram can schedule local follow-up reminders and live insight notifications if you allow notifications. Reminder content may include a saved person's name or an AI-generated live cue. Engram does not currently collect push notification tokens for a server-side push service.
Diagnostics And Service Logs
Engram's backend records request metadata needed to operate and protect the service, such as route, status code, latency, provider, operation, token counts when available, API request counts, and error type. Source-level backend logs are designed not to include raw audio, full transcripts, request bodies, access tokens, service-role keys, or provider API keys. Production hosting providers may also generate infrastructure logs such as IP address, timestamp, and request metadata.
How We Use Information
Engram uses information for app functionality: account access, session transcription, contact-card creation, profile matching, live conversation cues, follow-up reminders, cloud contact-card sync, account deletion, rate limiting, fraud and abuse prevention, reliability, and support.
Engram does not use your data for third-party advertising and does not sell your data. Engram does not currently use data for tracking as Apple defines tracking for App Store privacy labels.
Third-Party Processors
Engram uses:
- Supabase for authentication and cloud contact-card storage.
- OpenAI for transcription, conversation intelligence, speaker attribution, live insights, and profile lookup.
- SerpApi for profile-search candidates when the SerpApi-backed profile search feature is enabled.
- Apple and the device operating system for local notification prompts and scheduled notifications.
- The production hosting provider for running Engram's backend and collecting infrastructure logs.
Before publishing this policy, verify the production accounts, regions, data processing terms, and retention settings for each provider.
Storage And Retention
Local Data
Session history, transcripts, local recording files, saved people, plans, settings, profile context, reminder state, and profile lookup cache are stored locally on your device unless a future release explicitly adds cloud backup for those data types.
Cloud Data
At launch, Engram cloud sync is contact-card-only. Signed-in users may have contact cards stored in Supabase. Engram does not currently market or provide full cloud backup for recordings, transcripts, session history, planned conversations, settings, or personalization context.
Provider Retention
OpenAI API platform data handling is governed by OpenAI's API data controls and applicable account settings. SerpApi and Supabase processing is governed by their applicable terms, privacy, security, and data processing documents. Verify current provider retention settings before publishing this policy.
Deletion Choices
Clear History removes saved sessions, tracked local recording files, people, profile options, and reminders from the device. It does not delete your Engram account or cloud-synced contact cards.
Reset Local Data clears local sessions, tracked local recording files, people, plans, settings, profile context, and reminders on the device. It does not delete your Engram account or cloud-synced contact cards.
Delete Account permanently deletes your Supabase Auth account and cloud contact cards, then clears local app data on that device. Some provider or infrastructure logs may remain for security, abuse prevention, legal, or backup purposes according to provider retention policies.
Security
Engram uses HTTPS for backend requests, Supabase Auth for user authentication, backend service-role credentials only on the server, row-level security for cloud contact-card tables, backend rate limits, upload safety limits, and source-level logging controls that avoid raw request bodies and secrets.
Children
Engram is not intended for children under 13. Do not use Engram to record or process a child's personal information.
Changes
We may update this privacy policy as Engram changes. The effective date above will be updated when the policy changes.
Contact
Privacy contact: seharrington@wm.edu
Support URL: https://sammyharry.github.io/noted/support.html