Heardo

Privacy policy

Your words stay yours.

What Heardo keeps, where it goes, and how to delete it.

Last updated:

The short version

  • We use what you say to make your to-dos, and for nothing else.
  • To do that, Heardo sends your recordings and their text to Amazon Web Services (Amazon Bedrock). Amazon doesn’t train AI on them or share them with the companies that make the models.
  • No ads, no analytics, no tracking. We don’t sell your information or share it for advertising.
  • Heardo knows a place only if you save it for a location reminder. Where you go stays on your iPhone.
  • You choose how long recordings are kept, and you can export or delete everything from the app.
  • AI apps you connect over MCP get only the access you give them, and you can disconnect them at any time.

Who we are

Heardo is provided by [Abhay: the legal name, country and postal address of whoever provides Heardo; it must match the App Store seller] (“we”, “us”).

This policy covers the Heardo app for iPhone, the Heardo web app, the Heardo server they talk to, connecting AI apps to Heardo over MCP, and this website. We are responsible for your information as this page describes. Our Terms cover the rest of the agreement between us.

Questions and requests go to help@graviti.inc.

What we collect

Your account

When you sign in with Apple or Google, we receive your name, your email address (your Hide My Email address, if you chose one) and an identifier Apple or Google gives us for you. We also keep your time zone and your settings.

Your recordings

Heardo records only while a recording you started is running. On iPhone, the audio streams to our server while you speak, so it can be transcribed as you talk, and the recording is uploaded when you stop. In the web app, the recording is uploaded when you stop. The settings it’s processed with (language, task style, default category and snippets) and the time and time zone it was made in are stored with it.

What Heardo makes from them

Transcripts, to-dos with their notes and checklists, due dates, repeats, priorities, reminders and alarms, your categories and their descriptions, and your Dictionary: the words you’ve taught Heardo, and the words it suggests along with the bit of transcript each suggestion came from. We also keep daily counts (recordings, words, to-dos) for your Stats screen, and a record of what each AI call cost us.

Images you attach

You can attach images, such as screenshots and photos, to a to-do. Heardo gets only the images you pick or paste, never the rest of your photo library. Before an image leaves your device, the app redraws it from its pixels and shrinks it to about 500 KB, which leaves its metadata behind: no location, camera details or time taken. We keep the image in our file storage with your account. Images are not sent to our AI provider.

About your work, if you choose to add it

“Make Heardo yours” asks where you work and what you do, and, if you like, for your LinkedIn address. With a LinkedIn address, your phone opens that public profile page itself and sends us the address along with the page’s title, summary and profile data. Our server reduces the page to a few lines (headline, employer, job titles, schools, location, About, recent post titles), removing your name, links, email addresses and past employers. The AI gets those lines and the address, which usually contains your name, so that it can look the profile up.

We use all of this once, to suggest categories and Dictionary words, and we don’t store it on our server. Your phone remembers the company and role you typed, but not the LinkedIn address.

Morning briefings, if you turn them on

On iPhone, Settings › Notifications › Morning briefings can send you a short briefing each morning, as a notification, an email, or both. We keep your choices (time, days and where it goes) and, for each morning, the briefing itself: what’s due or overdue, a few suggested places to start with the reason for each, recently added to-dos and deadlines coming up, and whether it was delivered. The email goes to your account’s email address. How the briefing is written is described under AI providers.

Your devices

When Apple gives the iPhone app a push token for your phone, the app registers it with our server. For each registered phone we keep that token, an identifier for that installation, that it’s an iPhone, which of Apple’s push services the token belongs to (the one for test builds or the one for the App Store), and when it last checked in. We use them to send push notifications through Apple’s push service. When a recording has been turned into to-dos, our server sends a silent push to each of your phones so that the app fetches the new to-dos straight away. It shows nothing on screen and carries none of your words, only the recording’s identifier. A morning briefing sent to your phone, if you turn that on, shows the titles of the to-dos it suggests, so those words pass through Apple’s push service to reach you. Reminders, alarms and location reminders are scheduled on your phone by iOS, not sent by us.

The web app, in your browser

The web app keeps some things in your browser, on your computer, so that it opens quickly and copes with a dropped connection:

  • A copy of your account’s data: to-dos, categories, Dictionary and transcripts, with any changes not yet sent. Signing out of that browser deletes it.
  • Recordings that haven’t reached our server yet, at most 30 of them or 50 MB. Each is deleted from the browser once our server has it.
  • That browser’s settings: appearance, pinned and folded sections, where you placed categories in Orbit, and your recording settings and snippets.
  • If you turn on browser notifications, a short list of the reminders that browser has already shown, so that none is shown twice. It holds identifiers and times, not titles.
  • One sign-in cookie. Scripts on the page can’t read it, the browser sends it only to our server’s sign-in addresses, and it lasts 30 days from the last time you used the web app.

Browser notifications are off until you turn them on in Settings › General and your browser asks your permission. Your browser shows them, only while a Heardo page is open, with the to-do’s title. They don’t go through a push service.

The web app sets no other cookies and has no analytics. If you sign in with Google, the sign-in page loads Google’s sign-in code from Google.

Signed-in browsers

For each browser signed in to the web app, we keep a short label such as “Chrome on Mac”, worked out from what the browser says about itself, along with when it signed in and when it was last active. Only the label is kept, not what the browser sent. You can see the list, and sign any browser out, in Settings › Privacy & About › Signed-in browsers on iPhone, and in Settings › Account on the web. The list has room for an approximate place, but Heardo doesn’t record one; if that changes, this page will say so first.

Crash and diagnostic reports

When the iPhone app crashes, hangs or is slow to start, iOS gives it a diagnostic report (Apple’s MetricKit). The app sends these reports to our server, which keeps them in our file storage, linked to your account, for 90 days, so that we can find and fix the fault. A report holds technical details: what went wrong and where in Heardo’s code, the app and iOS versions, the iPhone model, when it happened and, if a recording was running, that recording’s identifier. It holds none of your recordings, transcripts or to-dos.

Server logs

Each request to our server is logged with your IP address, your account identifier, a request identifier, the address requested, the time and the result. Some events add a detail, such as the domain of a waitlist address or your time zone. Logs are written to leave out your recordings, transcripts and to-dos.

Email to us

If you write to us, we get your message and anything you attach. Emails the app starts for you add the app’s version and your iOS version at the bottom.

The waitlist

If you leave your email address on this site, we keep the address, which form it came from and when. We use it to send you one email when Heardo ships.

This website

This website, at heardo.app, sets no cookies and loads nothing from anyone else. Cloudflare, which hosts it, sees your IP address in order to serve the page.

Location

Heardo uses your location for one thing: reminders that go off when you arrive at or leave a place you choose. They’re optional. Heardo asks for location access only when you add one, and every other kind of reminder works without it.

Choosing a place

On iPhone, you search for the place and give it a name, such as Home or Office. The search goes to Apple Maps, which finds the place. In the web app, “At this location” asks your browser where your computer is now and saves that as the place. Your browser asks your permission first, and may use its maker’s location service to work out where you are.

What we keep

For each location reminder we keep, with its to-do on our server: the place’s name, its map coordinates (latitude and longitude), the distance around it that counts as being there, and whether to remind you when you arrive or when you leave. It is synced to your phone and the web app, carried on to the next to-do when a to-do repeats, and shown to the AI apps you connect over MCP (see AI apps you connect). It isn’t sent to our AI provider.

Where you go stays on your iPhone

Your iPhone, not our server, watches for the place: iOS raises the reminder when you arrive or leave. Heardo asks for location access only “While Using the App”; iOS still raises the reminder when the app is closed. Your movements and your phone’s location are not sent to us. The web app doesn’t follow your location: it reads it once, when you choose “At this location”, and location reminders go off only on your iPhone.

Removing a place

Remove the reminder, or delete its to-do, and the place goes with it, as How long we keep it describes. You can turn off Heardo’s location access at any time in your iPhone’s Settings › Apps › Heardo › Location, or in your browser’s settings for the site. Location reminders then stop, and everything else keeps working.

What we don’t collect

Heardo doesn’t track where you go: it uses your location only for the places you save for reminders, as Location describes. It doesn’t ask for your contacts, calendar or camera, and it has no access to your photo library: the iPhone’s own picker hands it only the images you choose to attach. It doesn’t use Apple’s speech recognition. It has no advertising identifier. There is no advertising, analytics or tracking code, and no third-party crash reporting, in the app, the web app, on the server or on this site. Nothing tracks you across other apps or websites.

How we use it

  • To do what Heardo does: transcribe what you say, turn it into to-dos, file them, remind you, send the briefings you asked for, and keep your devices and our server in step.
  • To keep Heardo working and safe: finding and fixing faults, including from crash reports, and preventing abuse.
  • To answer you when you write to us.
  • To send the one launch email, if you joined the waitlist.

We don’t sell your information, we don’t use it for advertising, and we don’t use your recordings, transcripts, to-dos or images to train AI models. Nobody working on Heardo reads your recordings, transcripts, to-dos or images except when you ask us to (for example, to look into a problem you reported), when it’s needed to keep Heardo working (for example, to process again a recording that failed, and then only as much as needed), or when the law requires it.

If you are in the EU, the UK or somewhere with similar law: running Heardo for you, including sending your recordings to our AI provider, is how we carry out our agreement with you, and you agree to it when you sign in. “Make Heardo yours”, location reminders and morning briefings run on your consent, which you can withdraw by not using them. Logs, crash reports and fault-finding rest on our legitimate interest in a reliable, secure service. And we keep what the law requires us to keep.

AI providers

Heardo uses Amazon Bedrock, an AI service run by Amazon Web Services (AWS), to turn what you say into to-dos. AWS processes this information on our behalf, as our service provider, only to give us the result. Nothing is sent before you sign in.

What we send to Amazon Bedrock

  • Your recordings, to transcribe them.
  • Their text, to make to-dos from it, with what’s needed to file them: your category names and descriptions, your Dictionary, your task style and snippets, and the time and time zone of the recording, so that “tomorrow at 9” lands on the right day.
  • For morning briefings, if you turn them on: the titles of your open to-dos, short extracts of their notes and checklists, and their categories and dates. Not your recordings or transcripts.
  • For “Make Heardo yours”, if you use it: the company and role you typed and, if you gave a LinkedIn address, the address and the lines described above. The model may search the public web for your company and for that profile to find the words it uses.

Images you attach are not sent.

Which models

Today Heardo uses Amazon’s own Nova models on Amazon Bedrock, such as Nova 2 Sonic, in AWS’s United States regions. We may move to other models that Amazon Bedrock offers, including ones made by other companies, such as Anthropic’s Claude. They also run inside AWS, and the first two points below hold for every one of them. For a few of them, Amazon keeps what is sent for up to 30 days to detect abuse; we will say so here before we use one of those. If we ever send your information to an AI provider other than Amazon Web Services, we will update this page, and ask you again, before any of it goes there.

What Amazon does with it

  • Amazon doesn’t use what we send, or what comes back, to train or improve any AI model, and doesn’t share it with the companies that make the models (Amazon Bedrock FAQ).
  • Those companies have no access to it: Amazon runs the models in accounts they can’t reach (Bedrock data protection).
  • For the Nova models Heardo uses, Bedrock doesn’t keep what we send once it has answered, and Amazon’s staff have no access to it (Bedrock abuse detection).
  • It is encrypted on the way to Amazon and back.

AWS handles it under its data-processing terms with us, which require it to protect your information at least as well as this policy does.

How long it’s kept, and how to stop

With the Nova models Heardo uses, Amazon Bedrock keeps nothing. What we keep, your recordings, transcripts and to-dos, is kept for as long as How long we keep it says, and you can delete any of it at any time.

You agree to this when you sign in, as the sign-in screen says. To withdraw, sign out: nothing more is sent from that device. Or delete your account, which deletes your recordings, transcripts and to-dos from our server (see how). Heardo can’t make to-dos from your voice without sending it to its AI provider, so using it to record means this processing.

AI apps you connect

Heardo is an MCP server. When you connect ChatGPT, Claude or another app that speaks MCP, you choose read-only or read & write. Either way, that app can see your to-dos (including the places saved for their location reminders) and the images attached to them, your categories, transcripts and recordings. With read & write it can also change your to-dos and categories, and add words to your Dictionary. See every tool.

What the app then does with your information is up to its own privacy policy, not this one. You can disconnect any app in Settings › Tasks › MCP on iPhone, or Settings › MCP on the web. Deleting your account disconnects them all; signing out does not.

Connecting an app shows a sign-in page from our server. That page loads Apple’s and Google’s sign-in code and a font from Google, and it sets one cookie, used only to finish signing in.

Where it’s kept, and how

Your account, transcripts, to-dos and briefings are held in a database, and your recordings, images and crash reports in private file storage, both with Amazon Web Services in Mumbai, India. The AI runs in the United States, as described above. So your information is processed in India and the United States, whose data-protection laws may differ from yours. Where the law requires safeguards for this, we rely on our providers’ standard data-protection terms.

  • Everything between your devices and our services travels encrypted.
  • Recordings and images are encrypted in storage, and the storage is not public. The links our apps use to play or show them stop working after 15 minutes at most.
  • Your sign-in stays in your phone’s Keychain, or in the web app’s sign-in cookie; our server keeps only a scrambled form of it that can’t be used to sign in.
  • Your phone keeps its own copy of your to-dos, and of the images you’ve viewed or attached, so that Heardo works offline. It keeps each recording for 7 days after the recording has uploaded, or for up to 30 days if it couldn’t be uploaded, and leaves recordings out of device backups.
  • The web app keeps the copy described above in your browser. On a computer other people use, sign out when you’re done.

No system is perfectly secure. If a breach affects your information, we will tell you as the law requires.

How long we keep it

  • Recordings. By default, until you delete them, so that you can play them back. Keep recordings (on iPhone, Settings › Privacy & About; on the web, Settings › Data and privacy) deletes the audio after 7, 30 or 90 days, or, with Don’t keep audio, as soon as it has been turned into to-dos. Transcripts and to-dos stay either way.
  • Delete all recordings, in the same place, deletes every recording and its transcript from our server and your phone. Your to-dos stay. A recording still being processed at that moment is left, so delete it again once it has finished.
  • Transcripts, to-dos, categories and Dictionary. These stay until you delete them or your account. When you delete a to-do, category or Dictionary word, we keep it hidden for 90 days so that your other devices can drop it too, then remove it for good. A deleted recording loses its transcript at once; an earlier draft of it, kept when a recording is transcribed again, goes at the 90-day mark. A Dictionary suggestion you decline is kept, with the few words it was heard among, so that it isn’t suggested again. It goes when you delete your account.
  • Places for location reminders. With their to-do, until you remove the reminder or delete the to-do. The copies we keep so that your devices stay in step go within 90 days, as for a deleted to-do.
  • Images. Until you remove them, or delete their to-do, in which case they go with it at the 90-day mark. A removed image is deleted from our storage within two days.
  • Morning briefings. Each one is deleted 30 days after it was made.
  • Crash reports. 90 days.
  • Signed-in browsers. A browser’s sign-in ends when you sign it out, or after 30 days without use, and it then leaves the list.
  • Your devices. A phone’s push registration is removed when you sign out on it, or when Apple tells us its push token no longer works.
  • Your account. Deleting it removes everything above from our server at once, and wipes Heardo’s data from the phone or browser you delete it on.
  • Backups. A deleted recording or image can remain in our storage’s version history for up to 30 days. Database backups are kept for 7 days, and we take a snapshot before each server update, keeping the latest five. Deleted information disappears from those as they are replaced. If we ever restore a backup, we will delete again anything you deleted since it was made.
  • Server logs. These are kept by our host for a limited time, then discarded.
  • The waitlist. We keep your address until you ask us to remove it.
  • Email to us. We keep it for as long as we need it to help you.

Who else handles it

Amazon Web Services
Hosts our server, database, recordings, images and crash reports (India), and runs the AI on Amazon Bedrock (United States).
Apple
Sign in with Apple, and Apple’s push notification service, which carries our push notifications to your iPhone. Apple Maps finds the places you search for when you add a location reminder. Reminders, alarms and location reminders are scheduled by iOS on your phone.
Google
Sign in with Google, if you use it. Google Workspace receives and stores the email you send us, including at help@graviti.inc, and Google serves the font on the page for connecting AI apps.
Cloudflare
Hosts this website.
Email delivery
Sends morning briefing emails, if you turn them on. [Abhay: name the email provider before briefing emails are switched on]
LinkedIn
Only if you give Heardo your LinkedIn address. Your phone fetches the public page directly, so LinkedIn sees your phone’s IP address, as it would for any visit.
AI apps you connect
Only the ones you choose, as described above.

The companies that handle your information on our behalf do so under contract, only to provide their service to us, and must protect it at least as well as this policy does.

Otherwise we share your information only when the law requires it, when it’s needed to protect someone’s safety or our rights, or as part of a sale or transfer of Heardo. In the last case, this policy goes on applying to your information.

Your choices and rights

In the app:

  • See and correct. Your to-dos, images, categories, Dictionary and recordings are all in the app, and you can edit or delete them there.
  • Export. On iPhone, open the menu, then Account › Export my data; on the web, Settings › Data and privacy › Export my data. This makes a file of your account, categories, to-dos (with a list of their images), Dictionary and transcripts, plus, on iPhone, any crash reports your phone has kept. For your recordings, your images, or anything the file leaves out, email us.
  • Delete. On iPhone, open the menu, then Account › Delete account; on the web, Settings › Account › Delete account. It takes effect at once and can’t be undone.
  • Limit. Set Keep recordings, skip “Make Heardo yours”, leave morning briefings off, sign out browsers you don’t use, or disconnect AI apps.
  • Withdraw. Sign out, or delete your account, to stop your recordings going to our AI provider, as described in AI providers.

Depending on where you live, for example in the EU or UK, India or California, you may have the right to:

  • access, correct, delete or export your information
  • restrict or object to how we use it
  • withdraw your consent
  • complain to your data-protection authority

Email help@graviti.inc and we will answer within 30 days. Asking won’t change how we treat you. We don’t sell or share personal information as California law defines those terms.

Children

Heardo isn’t meant for children under 13, or under the minimum age your country sets. If you think a child has given us information, tell us and we will delete it.

Changes to this policy

When this policy changes, we will update the date at the top. If a change affects how your information is used, we will tell you in the app before the change takes effect.

Contact

Email help@graviti.inc. For help with the app, see Support.