Privacy

Privacy policy

Last updated: 2026-07-04

The short version

Stonekept is a personal memory system, and we work hard to know as little about you as possible. Your recordings, transcripts, and extracted memories are created and kept on your device. We never see them. When you turn on Sync, those memories are backed up and moved between your devices as encrypted blobs sealed with a key only your devices hold, so at rest and in transit they are unreadable to us. Stonekept's servers cannot decrypt them.

What we collect

  • Free tier: no account, and none of your content (recordings, transcripts, memories) ever leaves your device. The only data we receive automatically is anonymous usage and crash analytics, designed to be content-free (feature usage, session counts, app version, device model, error and crash types), to fix bugs and improve the app. It is not linked to any identity, never includes your recordings, transcripts, or memories, is not used to track you or for advertising, and you can turn it off in Settings. Separately, if you ever choose to send us a diagnostic report, you see exactly what it contains before it leaves your device, it may include a short note you type, and we use it only to fix bugs.
  • Sync tier: an account email, a device list, and encrypted memory blobs. Server-side data is opaque to us.
  • Pro tier (AI access): the above, plus connection metadata for any MCP clients you authorize. Query contents are never stored, never logged, and never analyzed. The broker holds them in memory only for the seconds of an in-flight request, then forgets them.
  • Waitlist: email and platform you indicated. Used once, to notify you when that platform ships.

What we can see with AI access

Claude Desktop on Mac uses a fully local stdio bridge that never reaches our servers. Your queries and your memories stay on your machine. There is no broker in this path and no network traffic leaves your laptop for AI access.

claude.ai web and the Claude mobile app route through the Stonekept broker, so those queries and Claude's answers pass through our servers. This path cannot be end-to-end encrypted, because Claude has to read your query to answer it, so for those few seconds the content is readable as it passes through us. The protection here is a strict policy, not math: the broker holds it in memory only for the in-flight request and never stores, logs, or analyzes it. We can also see connection metadata (which device is talking, and how often). For maximum privacy on AI access, use Claude Desktop on a Mac, where everything stays local and nothing reaches our servers. Either way, Anthropic sees what Claude sees, since that is the connection you authorized.

What we never do

  • We never see your memories. Recording, transcription, and AI extraction all run on your device. Your recordings, transcripts, and memories are never sent to us, so there is nothing for us to read, store, or hand to anyone.
  • We do not train models on your memories. We could not if we wanted to. We never receive them, and your private life is never our training data.
  • We do not sell or rent your data to advertisers, data brokers, or anyone else.
  • We do not log AI query contents on our servers.

The point is not just that we won't. We built Stonekept so that we can't. The less we know about you, the better we have done our job.

Service providers we rely on

We keep the list of companies that touch any of your data deliberately short. Each one only ever handles the limited, mostly-encrypted data described above, under a data-processing agreement and only to operate Stonekept for you. We do not use third-party advertising or analytics networks; our usage analytics are self-hosted.

  • Google (Firebase and Google Cloud): paid-account sign-in, app-integrity checks, and push notifications (Firebase), and hosting for our API (Google Cloud Run). Handles your account email and display name and your devices' push tokens.
  • Supabase: our application database. Stores account and device metadata, the index of your encrypted blobs, subscription status, and the recording-consent log. It holds no readable recordings, transcripts, or memories.
  • Cloudflare (R2): encrypted object storage. Your Sync backups are kept here as ciphertext so you can restore and sync across your devices; your Desktop Assist audio only passes through briefly, until your Mac picks it up, and is then deleted. Everything here is ciphertext we cannot read.
  • Resend: sends our transactional email, such as replying to a message you send through the contact form. Handles the email address and message you give us there.
  • Apple (App Store): processes payments and subscriptions as merchant of record; it handles your payment details and we never see your card. (When the Android app ships, Google Play will do the same for that platform.)
  • Anthropic: only if you turn on AI access. Claude sees the queries and answers for the connection you authorize, as described above.

Recording and the law

You are the one recording, and you are responsible for following the recording laws where you are. The following is general information as of June 2026, not legal advice.

United States: federal law and 38 states plus DC follow one-party consent, so you can record a conversation you take part in. Twelve states require all-party consent, where everyone must agree: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington. Connecticut and Oregon treat in-person recording differently from phone or electronic. When a call crosses state lines, the strictest state's law applies.

Other countries: Canada and the UK allow one-party consent for personal use (the UK adds GDPR duties if you share recordings or use them for business). Much of the EU, including Germany and France, requires everyone's consent, and recording without it can be a crime. Australia varies by state. Elsewhere laws vary, and when a conversation crosses borders the strictest applicable law governs.

Because Stonekept processes everything on your device, we never receive or store the audio or the voices of anyone you record. This is general information, not legal advice. Verify the current law where you are.

Your rights (GDPR and CCPA)

Free tier: there is no account and no personal data on our servers, so there is nothing for us to access, export, or erase. Everything lives on your device, under your control, and you can export or delete it in the app at any time.

Paid tiers: the only data we hold is your account email, a device list, and end-to-end encrypted memory blobs we cannot read. We process it to provide the account and Sync you signed up for, on the lawful basis of performing that contract with you. You can access, correct, export, port, or delete it, and end Sync, at any time from the app or through our contact form. When you delete a memory it is removed from your devices and our active systems immediately; residual encrypted copies are purged from our backups within 7 days. California residents have the same rights under the CCPA. We do not sell or share your personal information, and we never train on your memories.

How long we keep data

On the free tier there is nothing to retain: your content lives only on your device. On paid tiers, we keep your account email, device list, and encrypted blobs for as long as your account is active. If you cancel Sync or delete your account, we remove that server-side data (a short grace period may apply on cancellation so you can resubscribe without losing your backup), and encrypted copies are purged from our backups within 7 days. The recording-consent log is kept while your account is active as a compliance record.

Where your data is handled

The service providers listed above may process data in the United States and other countries. For your encrypted blobs this is immaterial, because they are ciphertext neither we nor our providers can read. For the small amount of readable data (such as your account email), if you are in a region with data-transfer rules like the EEA or the UK, we rely on our providers' standard contractual clauses and on keeping that data minimal. Your on-device content is never transferred at all.

Children

Stonekept is not directed to children, and we do not knowingly collect personal data from children under 16 (or the minimum age of digital consent where you live). If you believe a child has provided us data, contact us and we will delete it.

If there is ever a data breach

If a security incident ever affects your personal data, we assess it and, where the law requires, notify you and the relevant authorities without undue delay. Because your recordings, transcripts, and memories are end-to-end encrypted and stored only as ciphertext we cannot read, a breach of our servers would expose unintelligible data rather than your content. The main readable data we hold is your account email.

Changes to this policy

If we materially change how we handle your data, we update this page. For changes to what leaves your device, what we can read, or our retention or deletion practices, we notify account holders before the change takes effect.

Who we are, and contact

Stonekept is operated by John Saxon, a sole proprietor based in Calgary, Alberta, Canada, who is the data controller for the limited personal data described above. For any privacy question, or to access, correct, export, or delete your data, use our contact form.