Ignea

Legal

Privacy policy

Last updated 5 October 2026.

Everything in this policy is checked against the running system: what is listed here is what the code actually stores. Your conversations are not sold, and they are not used to train models.

This deployment has no legal identity configured.

Set LEGAL_ENTITY and LEGAL_EMAIL (and optionally LEGAL_JURISDICTION) before taking payments. Until then the operator reads as a placeholder and these documents are not fit to rely on.

Who is responsible

the operator of this Ignea deployment is the controller of the personal data described here. Write to the contact address configured for this deployment for anything in this policy, including access and deletion requests you would rather make by email.

What we store, and why

Account: your email address, when the account was created, whether you have confirmed you are 18 or older, and the language you last wrote in.

Conversations: the messages you and the companion exchange, so a thread can continue on another device.

Memory: the lines the companion keeps about you, and the vectors we compute from them so relevant ones can be found. You can read, edit and delete every line.

Study material: the notes and lecture transcripts you upload, split into chunks, plus the timestamps of transcript chunks. Questions you asked in study mode, so a later hint can refer to them. Focus blocks and their lengths. Your weekly study report is computed from these, not stored separately.

Corrections: when you tell us a hint was wrong or unclear, we store the hint, your question, and the check result you were shown. This is how we find our own mistakes.

Usage counters: daily counts of voice notes, check-ins, photos, calls, stills and hints, so quotas work.

Mood: one aggregate score per companion per day, derived from your messages. Not the messages themselves.

Events you mention: dates like an exam, so a check-in can be timely.

Check-ins: push subscriptions if you turn them on (the browser endpoint and keys, plus your timezone offset), and a log of which check-ins were sent so you do not get the same one twice.

Billing: your subscription state, its identifier, and the user identifier we send to the payment provider. We never see or store your card details.

Safety: if your message needs a crisis or medical reply, that reply is generated without sending your message to the model.

What stays on your device

Your browser keeps a local copy of threads and memories so the page works before the server answers, a flag recording that you confirmed you are 18 or older, and a note of which product events happened on this device.

Clearing site data removes all of it. It does not remove what is stored against your account.

Who else processes it

Model providers. The text of your message, the recent conversation and the memories needed for a reply are sent to the model provider configured for this deployment so a reply can be generated. Voice notes are sent to a speech provider to be synthesised. If you photograph a question, that image is sent to be read and is not stored by us.

Email. Our email provider sends sign-in codes and billing notices, so it handles your address and the message contents.

Payments. Our payment provider handles checkout and subscription state. It receives an identifier and your email address, not your conversation.

Storage and hosting. Our database and object-storage providers hold the data described above. Voice audio may be stored as an object; otherwise it is returned inline and not retained.

Push. If you enable check-ins, your browser's push service delivers them.

Operations alerts. An internal alert channel receives short messages about payment events and service errors. Billing alerts include the account email or identifier. It is not used for conversation content.

How long we keep it

We keep your data until you delete it. Nothing you can see in the app expires on its own, and we do not run a scheduled purge — deleting your account is what removes it.

Daily counters and the check-in log are the only rows that age out on their own schedule.

If you want something removed without deleting the account, write to the contact address configured for this deployment.

Your rights

You can export everything we hold for you, or delete all of it, from your account page. Deletion is immediate and cascades across every table, including your messages, memories, notes, transcripts, corrections and events.

Depending on where you live you may also have the right to correct data, to object to processing, to restrict it, or to complain to a supervisory authority.

We do not sell your personal data, and we do not use your conversations to train models.

Security

Sessions are signed and stored in httpOnly cookies. Data is transmitted over TLS. Access to production systems is limited to the operator.

No system is perfect. If you believe your account has been compromised, write to the contact address configured for this deployment.

Children

Ignea is 18+ and is not directed at children. We do not knowingly hold data from anyone under 18. If you believe a minor has an account, write to the contact address configured for this deployment and we will remove it.