Privacy Policy
Effective August 6, 2026
This policy says, in plain terms, what ASIS keeps about you, why, who processes it, where it lives, how long it stays, and how to make it go away. The short version has not changed: your voice is never recorded, your records are isolated to your account, and deleting your account deletes your data.
01Who we are, what this covers
ASIS is a voice-first life assistant for iPhone, and "ASIS" ("we") in this policy means the operator of the ASIS app and of asis.life. This policy covers the app, the service behind it, and this website. It is the data-handling half of an agreement whose other half is the Terms of Use.
For anything this policy leaves you wondering about — including who is responsible for your data and how to reach them — write to support@asis.life and a human answers.
02What ASIS collects
ASIS keeps a small number of record types, all of them text or numbers:
- Account. Signing in with Apple, Google, or an email link creates your account; ASIS keeps the account identifier plus the email address and name your sign-in provider shares. A random installation identifier, created on first launch and kept in your iCloud keychain, links the install to your account.
- Conversation. The text of what you said and what ASIS replied — transcripts — together with technical metadata such as the models used, token counts, and timing. Audio is never part of a transcript (section 04).
- Memories. The twelve-section dossier ASIS builds from what you tell it — the same entries you can read, edit, archive, or forget in the app — each with its source and, as evidence, a short quote of your own words.
- Plans. Your events, to-dos, and reminders, and any notes ASIS attaches to events from your calendars.
- Calendars. If you connect Google or Outlook, a mirrored window of those calendars (section 07). Apple Calendar events are read on the device and are not mirrored into the ASIS database.
- Subscription. Your plan and its state — active, expiring, renewed — connected to your App Store purchase. Payment details stay with Apple; ASIS never sees your card.
- Usage. A per-day measure of how much you used ASIS and per-session voice durations, so your plan's daily allowance can be applied.
- Device and diagnostics. The app's build number, your timezone and chosen language, a handful of setup-progress markers from onboarding, and crash or error reports if something breaks.
Just as deliberate is what does not exist: no advertising profile, no location history, no upload of your contacts or photos, no browsing data, no HealthKit access, and no tracking identifiers.
03How ASIS uses it
Each record type exists to do its job: transcripts and memories power a conversation that knows you; plan and calendar data let ASIS schedule real things; subscription and usage records apply your plan and its daily allowance; device and diagnostic data keep the service working and secure. That is the complete list of purposes — there is no advertising, no profiling for third parties, and no sale of data. ASIS also never uses your content to train AI models.
Where the GDPR or UK GDPR applies, the legal bases are: performance of a contract (running ASIS for you); consent (the microphone permission, calendar connections, notification permission, and health details you volunteer — each withdrawable at any time); legitimate interests (keeping the service secure, preventing abuse, fixing failures); and legal obligation where the law requires us to act.
04Your voice is never recorded
When you talk to ASIS, audio streams from your iPhone over an encrypted connection to the speech-to-text service, which transcribes it live. Then it is gone. ASIS has no recording infrastructure: no audio file is ever written, kept for training, or replayable — by you or by us. What remains is text you can see; the transcript on your screen is the complete record of the conversation.
Replies travel the other way: ASIS's answer is generated as text and synthesized into speech, and that audio is streamed to you, not stored. One detail worth knowing: to recognize the people in your life when you say their names, ASIS sends the first names from your People memories to the speech-to-text service as vocabulary hints.
05AI processing
ASIS thinks with large language models, and each model sees only what its task needs:
- Conversation and memory extraction run on Google's Gemini models: your current words, the conversation so far, the memories relevant to it, and a snapshot of your plans.
- Briefings, conversation openers, and memory judging — deciding what is worth remembering, and whether two memories are the same — also run on Google's Gemini models, which see the calendar, to-do, and memory text those tasks involve.
- A backup model from Anthropic steps in automatically when a primary model fails, receiving the same kind of content for that turn.
- Memory search uses Voyage AI, which turns memory text and search phrases into embeddings so ASIS can find what is relevant.
These providers process your content to produce their output for ASIS — nothing else is sent to them, and section 08 lists them all. ASIS never trains AI models on your content. And because ASIS is an AI system, its output can be wrong; the honest limits of that are in the Terms of Use.
06Memory and sensitivity
Memory is the point of ASIS, so it comes with controls. Every memory is visible in the app with its source and evidence, and every one can be edited, archived, or forgotten — one at a time, or all at once with "Clear all memories" in Settings.
Sensitivity is handled automatically and can only tighten, never loosen. Entries that look like credentials or financial identifiers are marked private on sight; health-related entries are always at least "sensitive". Private entries stay out of conversation unless you yourself raise the topic, and health memories exist only because you chose to share them — ASIS never infers your health from your calendar, your routines, or anything else.
One boundary stated plainly: clearing memories removes the dossier, but conversation transcripts remain until you delete your account (section 12).
07Calendar connections
Apple Calendar is read and written on your iPhone, with the calendar permission you grant iOS, and is not mirrored into the ASIS database. When you talk to ASIS or a briefing is composed, the relevant slice of your day — including device-calendar events — is sent to the server to do that work. You can turn Apple Calendar access off in ASIS Settings at any time without changing anything in iOS.
Google and Outlook connect through each provider's own sign-in page; your calendar password never touches ASIS. ASIS requests these scopes, exactly: from Google, openid, email, calendar.events, and calendar.calendarlist.readonly; from Microsoft, openid, email, offline_access, and Calendars.ReadWrite. With that access, ASIS mirrors a rolling window of your calendars — 60 days back to 400 days ahead — onto its server, keeping each event's title, times, location, and notes so it can plan around your life and write events back. The mirror follows the source: events deleted at the provider disappear from ASIS on the next sync, which runs about every 20 minutes.
The OAuth tokens that maintain the connection are encrypted at rest with AES-256-GCM. Disconnect an account in Settings and its mirrored events are deleted and its tokens destroyed; for Google, ASIS also revokes its own access at Google. Microsoft offers no per-app revocation, so destroying the tokens is the whole story on our side — you can additionally remove ASIS from your Microsoft account's app permissions.
ASIS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
08The services that process your data
ASIS runs on a small set of processors, each with a defined job. These are the active processors, and there are no others:
- LiveKit — voice transport. Carries the live audio between your iPhone and ASIS; nothing is recorded.
- Deepgram — speech-to-text. Receives your voice as you speak and returns text; the audio is not kept by ASIS. Also receives first names from your People memories as vocabulary hints (section 04).
- Google Cloud — the Gemini language models behind conversation, memory, and briefings, Chirp text-to-speech for the voice of ASIS, and the Google Calendar API if you connect Google.
- Anthropic — backup language model, used automatically when a primary model fails.
- Voyage AI — memory embeddings and ranking, so ASIS can find the memories relevant to what you just said.
- Neon Postgres — the primary database (United States) where your records live, encrypted at rest.
- Firebase (Google) — authentication only: verifying your Apple, Google, or email sign-in.
- Sentry — error monitoring for the app and the server. Receives crash and error reports — device model, OS and app version, stack traces — configured to exclude screenshots, message content, and personal detail.
- RevenueCat — subscriptions: connects your App Store purchase to your account. Sees your account identifier and purchase state, never your payment details.
- Fly.io — hosting for the ASIS servers (United States).
- Microsoft Graph — Outlook calendar access, only if you connect Outlook.
If a provider ever has to be replaced, a successor performing the same role under equivalent protections may take its place, and this list is updated with the change.
10Security
Everything moves over encrypted connections (TLS), and everything at rest sits in an encrypted database. Calendar tokens carry a second, application-level layer of AES-256-GCM encryption. Every record is keyed to the account identity proven by your sign-in token — never to anything the app merely claims — and row-level isolation enforces that boundary on every query. Server logs are deliberately content-free: they record technical events, not what you said. Sensitive actions, like deleting the account, require you to re-authenticate first.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your data, we will notify you and the authorities as the law requires. If you find a vulnerability, write to support@asis.life.
11How long data is kept
- Account, transcripts, memories, and plans are kept for as long as your account exists. ASIS does not auto-expire them — your assistant's memory is the product — and you can delete memories and plans at any time, or everything at once (section 12).
- Mirrored calendar events live inside the rolling sync window and leave it as time moves or events are deleted; disconnecting an account deletes its mirror immediately.
- Crash and error reports expire automatically on the monitoring service's schedule, about 90 days.
- Encrypted disaster-recovery backups of the database expire automatically within 30 days.
12Deleting your data
In the app, go to Settings and tap Delete Account. ASIS asks you to sign in again — deletion is worth being sure about — and then to type DELETE. One transaction then removes your records from the live database: memories and their observation history, transcripts and sessions, events, to-dos, reminders and calendar annotations, connected-calendar accounts with their mirrored events and tokens, subscription records, the usage ledger, and the account itself.
After the deletion commits, ASIS revokes its Google calendar access at Google; Microsoft offers no per-app revocation, so ASIS destroys its token copies and you can also remove ASIS in your Microsoft account settings. The app then deletes your sign-in identity at Firebase. Residual copies in encrypted disaster-recovery backups expire automatically within 30 days.
Two practical notes. Deleting your account does not cancel the subscription — billing lives with Apple, so cancel it in your App Store settings as well. And deletion is permanent: there is no undo, and once the backup window has passed, nothing remains to restore.
13Notifications
Briefings, reminders, and heads-ups are composed on the server, then scheduled and fired locally on your iPhone. ASIS runs no push infrastructure and holds no push tokens — the notification you see at 7:00 was already sitting on your device, waiting for its hour. Every notification type has its own toggle in Settings, and the iOS notification permission is always yours to grant or revoke.
14Where your data lives
ASIS's servers and database run in the United States, so using ASIS means your data is processed there. The processors in section 08 operate where they operate — all in the United States, except Microsoft Graph, which serves Outlook calendar access globally if you connect Outlook.
Wherever your data is processed for ASIS, it travels encrypted and is handled under this policy and our providers' data-protection terms. If you are in the EEA, the UK, or another region with data-transfer rules, transfers are made with the safeguards those rules recognize, such as standard contractual clauses where required.
15Your rights
Most rights are built into the product: every memory is readable, editable, archivable, and forgettable in the app; plans can be changed or deleted outright; the whole account deletes in section 12's one transaction. For anything else — a copy of your data in a portable format, a correction, a restriction, an objection — write to support@asis.life and we will respond within 30 days, verifying that the request really comes from you.
If you are in the EEA or UK, this includes your GDPR rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time — and if we let you down, the right to complain to your supervisory authority. If you are a California resident, you have the rights to know, delete, and correct; ASIS does not sell personal information and does not share it for cross-context behavioral advertising, and exercising your rights never earns you worse service.
If you are in Thailand, the Personal Data Protection Act gives you corresponding rights — access, correction, erasure, portability, objection, and withdrawal of consent — and the right to lodge a complaint with the Personal Data Protection Committee.
16Children
ASIS is for adults — the Terms of Use require users to be 18 or the age of majority — and it is not directed to children under 13. We do not knowingly collect data from children; if you believe a child has an account, contact us and it will be deleted.
17This website and the App Store
asis.life sets no cookies, runs no analytics, and makes no requests to anyone else's servers. Reading this site leaves no trace with anyone, including us. The only links out are the App Store and our own email address.
In the App Store, ASIS's privacy label is drawn from this policy, and the app's account-deletion requirement is met in full inside the app (section 12).
18Changes to this policy
If this policy changes, the new version is posted on this page with a new effective date at the top. For material changes we will give notice in the app or by email before they take effect.
19Contact
Questions about this policy, or about anything ASIS knows about you: support@asis.life.