Exactly who handles your family's data
Hearthsay works with a small number of named service providers. This page names every one, what data they receive, how long it is kept, and what leaves Hearthsay for each AI mode.
Effective June 2026 · Hearthsay is in invite-only Early Access. We may add or change subprocessors as the product grows; significant changes will be noted here.
Named service providers
Supabase Auth
Sign-in, session tokens, Google and Apple OAuth relay
Data shared
Email address, OAuth provider token, session metadata
Processing region
US / EU
Vercel
Web and edge function hosting, CDN delivery
Data shared
Encrypted HTTP requests and responses; IP addresses in transit (not stored long-term). No family vault content.
Processing region
US / EU
Supabase (Postgres + Object Storage)
Primary vault database; audio file and attachment storage
Data shared
All vault data: recordings, transcripts, loved-one profiles, consent records, future messages, memory metadata
Processing region
US
Firebase Analytics (Google)
Anonymous page-view and crash analytics
Data shared
Anonymous event names and crash traces. No family vault content, recordings, or transcripts.
Processing region
US / EU
None during Early Access
Billing is not yet active. No payment processor is connected.
Data shared
N/A
Processing region
—
Not yet live (kill switch off)
Voice recording transcription will be added before General Availability.
Data shared
Future: audio clip (no names or identifiers) sent to transcription service for text conversion.
Processing region
—
Not yet live (kill switch off)
Source-backed memory answers. When live, Hearthsay sends anonymized memory excerpts to an AI provider to answer questions.
Data shared
Future: selected memory text excerpts only. Raw audio, consent records, billing, and auth tokens are never sent to the LLM.
Processing region
—
User's own provider (OpenAI / Anthropic / Google / compatible)
When you connect your own AI provider, selected memory excerpts are sent to your provider endpoint to answer your questions. You control which provider and which memories.
Data shared
Selected memory text excerpts, per the scopes you approve. Your provider's own privacy policy applies to that use.
Processing region
Determined by your chosen provider
None during Early Access
Hearthsay does not clone or generate audio in a loved one's voice during Early Access. Original recordings you saved can be played back; no synthesis provider is used.
Data shared
N/A
Processing region
—
Retention windows
| Data category | Retention window | Notes |
|---|---|---|
| Active vault data | Until deleted by you | Recordings, transcripts, memories, profiles, and future messages are kept as long as your account is active. |
| Deleted memory or loved-one profile | Purged within 30 days | Deletion removes the recording, transcript, generated messages, and source memory links. Confirmation is required before deletion. |
| Deleted account | Purged within 30 days | All vault contents are deleted. Only the minimum billing or legal record we are required to keep is retained. |
| Server and edge logs | 90 days | Request logs (timestamp, endpoint, anonymized identifiers) are used for reliability and abuse prevention, then purged. |
| Billing records | As required by law | Typically 7 years for tax and accounting purposes. No full card numbers are stored by Hearthsay. |
| Supabase database backups | 30 days rolling | Automated point-in-time backups are retained for 30 days for disaster recovery, then overwritten. |
| Analytics events | 14 months (Firebase Analytics setting) | Anonymous page events and crash data only. No family vault content. |
What leaves Hearthsay, by AI mode
Hearthsay has three AI modes. Here is exactly what each sends outside the service. Raw recordings never leave in in-app or bring-your-own-AI modes; in MCP mode an approved assistant can receive a short-lived signed audio link only with verified consent and the sources scope.
| Data type | In-app AI(not yet live) | BYO-AI(your provider) | MCP(external assistant) |
|---|---|---|---|
| Raw voice recordings (audio files) | Stays inside Hearthsay | Stays inside Hearthsay | Short-lived signed link — only with consent + the sources scope |
| Selected memory text excerpts (to answer questions) | When live — sent to Hearthsay AI provider | Sent to your chosen provider | Returned by approved tool calls |
| Loved-one profile names and metadata | Stays inside Hearthsay | Stays inside Hearthsay | Only within scopes you approve |
| Consent Passport records | Stays inside Hearthsay | Stays inside Hearthsay | Stays inside Hearthsay |
| Auth tokens and session cookies | Stays inside Hearthsay | Stays inside Hearthsay | Stays inside Hearthsay |
| Billing and subscription details | Stays inside Hearthsay | Stays inside Hearthsay | Stays inside Hearthsay |
| Future message drafts | Stays inside Hearthsay | Stays inside Hearthsay | Only if future-messages scope is approved |
| MCP tool responses (memory answers, lists) | Stays inside Hearthsay | Stays inside Hearthsay | Returned to the connected assistant |
What never leaves Hearthsay in in-app and BYO-AI modes
- Raw voice recording files in in-app AI and BYO-AI modes (MCP can return a consent-gated, short-lived signed audio link only under the sources scope)
- Consent Passport records and verification status
- Auth tokens, session cookies, and login credentials
- Billing details and subscription status
- Vault contents outside the scopes you explicitly approve (for MCP)
- Memories you did not select for a specific AI query
- System audit logs and access history
- Loved-one profile data outside the tools you approved