Privacy Policy
This policy explains how Comory handles your memories and temporary audio processing.
Last updated: August 25, 2026
Your Memories
Comory saves the text memories you create: transcripts, notes, and what it extracts (people, places, topics, reminders, decisions). Your original audio is deleted right after it’s transcribed and never stored, only the resulting text is kept. That text is stored on Comory’s server, encrypted at rest (AES-256, with a separate key for each account), which is what lets it sync across your devices. Deleting a memory removes its content from the server, not just from your device; deleting your account removes everything.
AI Processing
When you record or type a memory, ask Comory a question, or open your daily recap, that content is sent to Comory’s server and processed using OpenAI’s API to transcribe it, organize it, or generate a response. That’s the only AI provider your content goes to, and there’s no analytics or advertising SDK in this app. Per OpenAI’s API terms, data submitted through the API isn’t used to train their models by default; Comory doesn’t independently verify or override that setting. Traffic between the app and Comory’s server is encrypted in transit (HTTPS/TLS). AI results assist you and aren’t a replacement for your own judgment, since Comory can misread a name, date, or detail.
Account Data
Your account (email, name, and a bcrypt-hashed password, never stored in plain text) is stored on Comory’s server so you can sign in from any device. It’s never sold or shared with anyone outside the processing described in this policy.
Subscriptions and Payments
Comory Pro is currently purchased and managed entirely through Apple In-App Purchase on iOS. Apple handles your payment method and billing directly, and Comory never sees or stores your card details. Purchasing a subscription on the web isn’t available yet; the web app can show your plan and usage, but not a working checkout. If web purchasing is introduced later, this section will be updated first.
Notifications
Comory can remind you to journal or send a weekly recap reminder. These are scheduled locally on your device through your phone’s own notification system. No push-notification server or third party is involved, and Comory has no way of knowing whether or when you saw one.
Sensitive Information
Comory doesn’t have specialized handling for sensitive categories of personal information, like health, mental health, religious beliefs, or sexual orientation. If you record something like that, it’s treated the same as any other memory: processed by OpenAI’s API as described above and stored, encrypted, on Comory’s server. Use your own judgment about what you’re comfortable including.
Children’s Privacy
Comory isn’t directed to children and isn’t intended for use by anyone under 13. We don’t knowingly collect information from children under 13.
We Don’t Sell Your Data
Comory doesn’t sell your personal information, and doesn’t share it with data brokers, advertisers, or anyone else beyond the processing described in this policy.
Your Rights & Controls
You can export everything Comory has about you at any time, from You > Export Data on mobile, or Settings > Privacy and data > Download my data on web. You can also edit your name, delete an individual memory (which removes its content from Comory’s server, not just a local copy), or permanently delete your account and everything in it from the same Privacy and data settings. There’s no separate way yet to correct one extracted field on its own, like a misheard name; editing the memory’s text and letting Comory reprocess it is today’s way to fix that.
Changes to This Policy
If this policy changes in a meaningful way, we’ll update the “last updated” date above. Continuing to use Comory after a change means you accept the update.
Contact
Questions about your data? Contact us at hello@comory.app.
This policy is written in plain language to accurately describe what Comory does today, and will be updated as the app evolves.