Privacy Policy
Last updated July 5, 2026
This Privacy Policy describes how Almanack (operated by Fabio Jonathan Arifin via EchoForge, the "Operator") handles information when you use the Almanack iOS application and web application. The short version: your recordings are transcribed by our transcription provider over an encrypted connection and are not kept afterward, or, if you turn on Transcribe on Device, on your phone so the audio never leaves it. Your memory (the text) syncs encrypted so it works on your phone and at your desk, it is isolated to your account, never used to train anything, and you can export it anytime or request permanent deletion.
Operator
Fabio Jonathan Arifin (EchoForge). Email support@echoforge.to.
Where your memory lives
On your phone, entries, decisions, commitments, tasks, and transcripts are stored in a local database encrypted at rest with SQLCipher, keyed from the iOS keychain, with an optional Face ID lock. So Almanack works on your phone and at your desk, your memory also syncs to a database we operate (hosted on Supabase, encrypted at rest and in transit). Row-level security enforced by the database itself isolates your rows to your account: queries from any client can only ever return your own data. Files you attach (screenshots, documents) are stored in a private Cloudflare R2 bucket, accessible only through short-lived signed links generated for your authenticated session. We do not read your memory, and it is never used to train any model.
Voice and transcription
By default, recordings are sent to our transcription provider (DeepInfra) over an encrypted connection, which transcribes them and does not retain the audio afterward. If you turn on Transcribe on Device in Preferences, quick notes are transcribed on your phone with a local Whisper model and that audio is not uploaded (this is also the fallback when you are offline). Recordings are deleted after transcription unless you turn on Keep Recordings, in which case a compressed copy is stored in your private attachment storage. In every case the resulting text becomes part of your memory, which syncs encrypted to your account (see Where your memory lives).
AI processing of transcript text and attached images
Two features require a network call: structuring your spoken notes into decisions, commitments, and tasks, and answering questions about your own history. For these, transcript text (and the relevant stored text needed to answer a question) is sent from your device to a Cloudflare Worker proxy we operate, which forwards it to AI model providers accessed through OpenRouter (an AI routing service), currently Google's Gemini models, solely to generate the structured output or answer. If you choose to attach a photo or screenshot to a capture, that image is sent the same way, once, to be read into the structured note; the image itself is stored in your private attachment storage. The proxy does not store your content. These providers process text under their API terms. We do not use your content to train models, and these API providers state that API inputs are not used to train their models. See OpenRouter and Google privacy policies.
If you turn on Write in your voice and paste a writing sample, that sample is sent the same way, once, to distill a short style descriptor used to match your tone. The sample and the descriptor are stored with your account so the feature works across your devices, and both are erased when you delete your account.
Accounts
You sign in with Apple or Google (handled by Supabase Auth). From your provider we store only the email address and authentication identifiers they share. You can optionally add a display name and a profile photo; if you do, they are stored with your account, the photo in the same private storage as your attachments, and you can change or remove them in Settings at any time. The account exists so your memory can sync between your phone and the web app and so your data can be isolated to you. Your subscription is tied to your Apple ID through the App Store and can be restored on any device signed into that Apple ID.
Connecting your AI (MCP)
You can connect an AI assistant (such as Claude or ChatGPT) to your memory so you can ask it questions from inside that assistant. There are two ways to connect. Most people sign in to Almanack from the assistant and approve access through a standard OAuth sign-in and consent step; no key changes hands, and you can disconnect from the assistant or from Almanack at any time. Developers can instead create a personal API key in Settings, of which only a hash is stored and the key itself is shown to you once. Either way the connection is read-only: the assistant can search and read your memory to answer you, but it cannot create, change, or delete anything. Anything the assistant retrieves flows to the assistant you connected, under that provider's terms. Entries you mark personal are never returned through this surface. You can revoke access or any key instantly in Settings.
Purchases and subscriptions
On iPhone, purchases are processed by Apple through the App Store; on the web, purchases are processed by Stripe. We never receive or store your payment card data. Subscription status is managed via RevenueCat, which receives a pseudonymous app user identifier and your entitlement status, not your name or payment details. See RevenueCat's privacy policy and Stripe's privacy policy.
Analytics
Almanack may collect optional anonymous product analytics via PostHog (for example, which features are used and in-app errors) to fix bugs and prioritize improvements. Analytics events never include your entries, decisions, commitments, or transcripts, and are not linked to your real-world identity. See PostHog's privacy policy.
Advertising measurement (iOS)
Almanack does not show ads. To understand which ad brought a new user to the app, so we can spend our marketing budget wisely, the iOS app uses a measurement provider (Singular) together with Apple's SKAdNetwork. When you first open the app, iOS asks whether you allow tracking (App Tracking Transparency); only if you allow it does Almanack use the Apple advertising identifier (IDFA) to attribute your install, and if you decline, that identifier is not used. What is shared for this purpose is limited to your install and a small set of app events (such as finishing onboarding, creating an account, and starting a subscription), never your entries, transcripts, or answers. See Singular's privacy policy.
What we do not do
- We do not sell your data. Ever.
- We do not show ads, and we never share your memory (your entries, transcripts, or answers) with advertisers. For install measurement we share only limited install and app-event data, and only with your permission (see Advertising measurement).
- We do not keep your audio unless you ask us to. By default recordings are transcribed and then deleted, and our transcription provider does not retain them either. If you turn on Keep Recordings, a copy is stored in your own private attachment storage.
- We do not read your memory or mine it for any purpose.
- We do not use your content to train AI models.
- We do not hold your data hostage: export everything as markdown anytime.
Export and deletion
You can export your entire memory as a markdown file anytime from Settings. Deleting your account in Settings (Delete all data) permanently erases everything, on your device and on our servers: every entry, transcript, attachment, and API key, with no retention window and no recovery. To also remove anonymous analytics events or RevenueCat purchase records, email us at support@echoforge.to.
Security
On device, your memory is encrypted at rest with SQLCipher, keyed from the iOS keychain, and protected by your device's own security (passcode, Face ID, Secure Enclave). On the server, your data is encrypted at rest and in transit, isolated to your account by database-enforced row-level security, and administrative credentials never ship to any client. No system is perfectly secure, but every layer here is designed so that a failure in one does not expose your memory.
Children's privacy
Almanack is not directed to children under 13 and children under 13 are not permitted to use it. We do not knowingly collect any data from children under 13. If you believe we have, email us and we will delete the records.
International transfers
Our third-party service providers are located primarily in the United States. By using the AI structuring and question-answering features outside the United States, you acknowledge that transcript text may be processed in the United States.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the app and reflected in the effective date above.
Contact
Questions or requests: support@echoforge.to.