Privacy Policy
This policy explains what Necory collects — the web app at app.necory.com, the mobile apps, and the necory.com website — why, where it goes, how long it stays, and how you can take it out or erase it. It was written from what Necory actually does; if it doesn't do something, this policy doesn't claim it.
Necory is operated by LinavaSoft LLC, a limited liability company registered in Wyoming, United States ("we", "us"). LinavaSoft LLC is the data controller for the information described here. For anything in this policy, contact support@necory.com.
The short version: Necory stores what you deliberately save so its AI can recall it for you. Your content is encrypted in transit and at rest and isolated to your account — but it is not end-to-end encrypted, because the AI must read it to answer you. We don't sell your data and we don't show ads. You can export everything and delete everything, from inside Necory.
1. Information we collect
Account information
- Sign-in details: your email address and/or phone number, and — if you sign in with Google or Apple — the name, email, and profile photo those providers share.
- Profile settings: display name, profile photo, preferred language (English/Arabic/Spanish), theme, and your device's timezone (used to fire reminders at the right local time).
- Agreement record: which version of these terms you accepted, when, and that you accepted it by ticking the box — kept as proof of consent.
- Marketing preference: whether you opted in to product emails, and when. It is separate from accepting the terms, and you can change it at any time.
- Usage counters: how many items you have saved, how much file storage you use, and your daily AI message count — these enforce plan limits and are shown back to you.
- One-time codes: when you sign in or reset a password by email code, we store the code only as a SHA-256 hash for up to 10 minutes; expired codes are purged automatically. Phone sign-in codes are generated, delivered, and verified by Firebase Authentication — we never see or store them.
- Password safety check: when you set a password, we check it against the Have I Been Pwned breach database using its k-anonymity API — only the first five characters of a hash are sent, never your password.
Content you save (the point of the product)
- Notes, links, photos, documents (PDF, Word, Excel and similar), audio files you attach, and places (coordinates and addresses you choose to share).
- Your conversations with the AI, including attachments.
- Money-ledger entries: the people you name, amounts, currencies, and the wording you used.
- Explicit memories and relationships you ask Necory to keep (e.g., "Emma is my wife").
- Reminders: their text and schedule.
Information Necory derives
- AI-generated organization: titles, summaries, and tags for saved items, plus a record of edits ("revisions") when the AI updates an item.
- Search embeddings: numerical representations of your content that make meaning-based recall possible.
- Personalization you write yourself: the nickname, occupation, traits, and notes you enter under Settings → Customize, plus two switches controlling whether Necory may draw on your saved memories and your earlier chats. Necory no longer infers a profile about you — it used to guess at things like tone and active hours, and that was removed; what the AI is told about you is now only what you typed.
Usage and diagnostics
- Analytics events: which screens are used and product events like "message sent" or "item saved", with a session identifier, your subscription plan, and your account ID. These go to Google Analytics for Firebase and to our own database, where we keep the raw events for 90 days and derive from them a per-account summary (first and last seen, plan, platform) and day-by-day totals. Analytics events never contain the content of your notes, messages, files, search queries, or locations — we record that something happened, never what it said.
- Crash, error, and performance reports (Sentry): stack traces, a trail of app events leading to an error, and app performance and stability metrics (such as start-up timing and crash-free sessions), tied to your account ID only. We configure Sentry to not collect personal details, screenshots, or screen contents.
- Push token: a device registration token so we can deliver reminder notifications.
- Quality review snippets: when the system flags an AI answer as possibly wrong, a snippet of that exchange — with personal identifiers redacted before storage — may be queued for our review so we can fix the AI's behavior.
- Enforcement records: whether an account is suspended for Terms violations.
Device permissions (all optional, all user-triggered)
| Permission | Used for | When |
|---|---|---|
| Camera / photo library | Attaching photos to chat or saving them to your vault | Only when you attach or save |
| Microphone | Voice dictation — your recording is sent to Google's Gemini API, transcribed to text, and then discarded; we don't store the audio, and no on-device speech recognition is used | Only while you hold/tap the mic |
| Location | Sharing your current location in chat or saving a place | Only when you tap to share; never in the background |
| Files | Attaching documents or audio files | Only when you pick a file |
| Notifications & exact alarms | Delivering reminders on time, including when the app is closed | After you allow the prompt |
On your device (the web app at app.necory.com)
- The web app stores your signed-in session, your language and theme choices, and an offline cache of the app itself in your browser's own storage, so you stay signed in and it works with a poor connection. It is not used for advertising or tracking, and clearing your browser data removes it.
- If you turn on notifications, your browser issues a delivery token that lets us send your reminders. Turning notifications off revokes it.
On the website (necory.com)
- This website sets no cookies and runs no analytics or trackers. That's why there's no cookie banner.
- It is served by Firebase Hosting, which processes standard request logs (IP address, user agent) to deliver the site.
- Fonts load from Google Fonts, which receives your IP address as part of serving the font files.
2. Why we process it
- To provide the service: storing your content, generating AI replies, computing ledger balances, firing reminders, syncing across sign-ins.
- To secure it: authentication, abuse and rate limiting, app-integrity attestation, fraud prevention.
- To run the business: knowing your subscription status so the right limits apply.
- To improve quality: aggregate analytics, crash reports, and redacted AI-quality snippets.
- We do not: sell your data, share it for advertising, or use your private content to advertise to you.
If you are in the EU, UK, or another place with similar law, these are the legal bases we rely on:
| What we do | Legal basis |
|---|---|
| Running your account and the product you asked for — storing your content, answering with the AI, computing balances, sending reminders | Performance of a contract with you (Art. 6(1)(b)) |
| Keeping the service secure and preventing abuse and fraud | Our legitimate interests in a service that is not abused, balanced against your rights (Art. 6(1)(f)) |
| Understanding how the product is used, and fixing crashes and poor AI answers | Our legitimate interests in improving the product, using data that carries no content (Art. 6(1)(f)) |
| Sending you product emails, if you opted in | Your consent, which you can withdraw at any time (Art. 6(1)(a)) |
| Keeping records we are required to keep, and responding to lawful requests | Compliance with a legal obligation (Art. 6(1)(c)) |
Necory is a general-purpose place to keep things, so you may choose to save something that counts as sensitive — a health note, for example. We do not ask for it, we do not seek it out, and we do not process it to infer anything about you; it is stored and recalled only because you put it there and asked for it back. Please do not store what you would not want a service to hold in readable form, since Necory is not end-to-end encrypted.
3. Who processes your data
Necory is built on established infrastructure providers acting on our behalf:
| Provider | What it does | What it receives |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, file storage, server functions, push notifications, analytics, app-integrity checks. Hosted in the United States. | Your account data and content |
| Google Gemini API | Generates AI replies, transcribes voice recordings, creates search embeddings | The messages, attachments, and retrieved content needed for each reply |
| Sentry | Crash, error, and performance monitoring | Crash and error reports plus performance and stability metrics, tied to your account ID; configured to exclude personal details and content |
| Resend | Sends transactional email (sign-in codes, password reset, welcome) | Your email address and the email content |
| Apple App Store / Google Play + RevenueCat | Subscription billing and entitlement management | Purchase and subscription status. We never see your card number. |
| OpenStreetMap | Renders small map previews for saved places | Your IP address and the map area requested, when a preview loads |
| Have I Been Pwned | Password breach checking | Only the first five characters of a password hash (k-anonymity) |
| Google reCAPTCHA Enterprise | Checks that sign-in attempts and app requests come from a real person and a genuine copy of Necory, rather than automated abuse | Device and interaction signals from the page or app making the request, and your IP address |
| Apple / Google geocoding | Turning shared coordinates into a readable address | The coordinates you chose to share |
When you contact support@necory.com, your message is processed by our email provider like any email.
4. Where your data lives, and transfers
LinavaSoft LLC is based in the United States, and your data is stored and processed on Google Cloud infrastructure in the United States. If you use Necory from outside the US, your information is held and processed there.
Where information reaches us from the EU, UK or Switzerland, we rely on the safeguards our infrastructure providers maintain for those transfers, including the European Commission's Standard Contractual Clauses, which Google Cloud applies to the services we use. If you want to know exactly which mechanism covers a particular flow, ask us and we will tell you.
4b. You are talking to an AI
Necory answers you with an AI system. It is not a person, it can be wrong, and you should check anything that matters — we build the product so that the parts that must not be guessed, like your ledger balances, are computed by our servers rather than by the AI. The AI does not make decisions about you that have legal or similarly significant effects, and we do not use your content to build a profile of you or to train anyone else's model.
5. Security
- TLS encryption for all traffic; encryption at rest on Google Cloud.
- Server-side security rules bind every record to your account — no other user can access it, and AI operations are locked to your signed-in account.
- Sign-in codes stored only as hashes; single-use; 10-minute expiry; brute-force rate limits.
- Production apps attest integrity via Firebase App Check.
- Service credentials are kept in a managed secrets vault, never in code or client apps; raw error details go to internal logs, never to clients.
- Not end-to-end encrypted — the AI must read your content to answer you, so our systems process it in readable form. We say this everywhere it matters. See Security.
6. How long we keep things
| Data | Retention |
|---|---|
| Your content (vault, conversations, ledger, memories, reminders) | Until you delete it |
| Items you delete | 30 days in trash (restorable), then permanently erased |
| Conversations you delete | Removed along with their messages when you delete them |
| Data-export archives | Download links expire after 7 days; expired archives are deleted |
| One-time sign-in codes | 10 minutes, then purged |
| Deleted account | 30-day recovery window, then all content, files, and profile data are permanently erased |
| Analytics events (in our systems) | Raw events 90 days; the per-account summary and daily totals derived from them are kept while your account exists |
| Analytics and crash data (with Google and Sentry) | Held by Google Analytics and Sentry for their standard limited retention periods |
| Chat-recall index | A searchable copy of your own messages, so Necory can recall what you said in earlier chats: removed when you delete the conversation, and in any case after 2 years |
7. Your rights and controls
- Access & portability: Settings → Export gives you your entire dataset (readable HTML + JSON + media), on any plan.
- Correction: edit any item, memory, or profile field in Necory; tell the AI to update or forget things.
- Deletion: per item, per conversation, all data at once, or the whole account — see Account deletion.
- AI personalization control: edit or clear anything you told Necory about yourself under Settings → Customize, and use the two switches there to stop it drawing on your saved memories or your earlier chats.
- Restriction: ask us to pause processing while a dispute about accuracy or our legitimate interests is resolved.
- Objection: object to processing we base on legitimate interests, including analytics; tell us and we will stop unless we have compelling grounds that override your rights.
- Withdrawing consent: turn off product emails whenever you like — withdrawing does not affect anything done before you withdrew.
- Complaining: you can lodge a complaint with your local data protection authority. In the EU that is your national supervisory authority; in the UK it is the Information Commissioner's Office. You are welcome to raise it with us first, but you do not have to.
- Notifications: controlled by your device's system settings.
- Depending on where you live, you may have additional statutory rights (e.g., under GDPR or CCPA). Email support@necory.com from your account address and we'll honor the rights that apply to you.
8. Children
You must be at least 13 years old to use Necory, and if you are under 18 you need a parent or guardian's permission. Necory is not directed to children under 13, and we don't knowingly collect their data. If you believe a child under 13 has created an account, contact us and we will delete it.
9. Changes to this policy
If we change this policy in a meaningful way, we'll update the date above and inform you in Necory before the change takes effect. The current version always lives at necory.com/privacy.