Skip to content
Hearthsay
Subprocessors & data flow

Exactly who handles your family's data

Hearthsay works with a small number of named service providers. This page names every one, what data they receive, how long it is kept, and what leaves Hearthsay for each AI mode.

Effective June 2026 · Hearthsay is in invite-only Early Access. We may add or change subprocessors as the product grows; significant changes will be noted here.

Named service providers

AuthenticationLive

Supabase Auth

Sign-in, session tokens, Google and Apple OAuth relay

Data shared

Email address, OAuth provider token, session metadata

Processing region

US / EU

Hosting & edgeLive

Vercel

Web and edge function hosting, CDN delivery

Data shared

Encrypted HTTP requests and responses; IP addresses in transit (not stored long-term). No family vault content.

Processing region

US / EU

Database & storageLive

Supabase (Postgres + Object Storage)

Primary vault database; audio file and attachment storage

Data shared

All vault data: recordings, transcripts, loved-one profiles, consent records, future messages, memory metadata

Processing region

US

AnalyticsLive

Firebase Analytics (Google)

Anonymous page-view and crash analytics

Data shared

Anonymous event names and crash traces. No family vault content, recordings, or transcripts.

Processing region

US / EU

PaymentsNot yet live

None during Early Access

Billing is not yet active. No payment processor is connected.

Data shared

N/A

Processing region

TranscriptionNot yet live

Not yet live (kill switch off)

Voice recording transcription will be added before General Availability.

Data shared

Future: audio clip (no names or identifiers) sent to transcription service for text conversion.

Processing region

LLM & embeddings (in-app AI)Not yet live

Not yet live (kill switch off)

Source-backed memory answers. When live, Hearthsay sends anonymized memory excerpts to an AI provider to answer questions.

Data shared

Future: selected memory text excerpts only. Raw audio, consent records, billing, and auth tokens are never sent to the LLM.

Processing region

LLM & embeddings (BYO-AI)Live

User's own provider (OpenAI / Anthropic / Google / compatible)

When you connect your own AI provider, selected memory excerpts are sent to your provider endpoint to answer your questions. You control which provider and which memories.

Data shared

Selected memory text excerpts, per the scopes you approve. Your provider's own privacy policy applies to that use.

Processing region

Determined by your chosen provider

Voice synthesisNot yet live

None during Early Access

Hearthsay does not clone or generate audio in a loved one's voice during Early Access. Original recordings you saved can be played back; no synthesis provider is used.

Data shared

N/A

Processing region

Retention windows

Data categoryRetention windowNotes
Active vault dataUntil deleted by youRecordings, transcripts, memories, profiles, and future messages are kept as long as your account is active.
Deleted memory or loved-one profilePurged within 30 daysDeletion removes the recording, transcript, generated messages, and source memory links. Confirmation is required before deletion.
Deleted accountPurged within 30 daysAll vault contents are deleted. Only the minimum billing or legal record we are required to keep is retained.
Server and edge logs90 daysRequest logs (timestamp, endpoint, anonymized identifiers) are used for reliability and abuse prevention, then purged.
Billing recordsAs required by lawTypically 7 years for tax and accounting purposes. No full card numbers are stored by Hearthsay.
Supabase database backups30 days rollingAutomated point-in-time backups are retained for 30 days for disaster recovery, then overwritten.
Analytics events14 months (Firebase Analytics setting)Anonymous page events and crash data only. No family vault content.

What leaves Hearthsay, by AI mode

Hearthsay has three AI modes. Here is exactly what each sends outside the service. Raw recordings never leave in in-app or bring-your-own-AI modes; in MCP mode an approved assistant can receive a short-lived signed audio link only with verified consent and the sources scope.

Data typeIn-app AI(not yet live)BYO-AI(your provider)MCP(external assistant)
Raw voice recordings (audio files)Stays inside HearthsayStays inside HearthsayShort-lived signed link — only with consent + the sources scope
Selected memory text excerpts (to answer questions)When live — sent to Hearthsay AI providerSent to your chosen providerReturned by approved tool calls
Loved-one profile names and metadataStays inside HearthsayStays inside HearthsayOnly within scopes you approve
Consent Passport recordsStays inside HearthsayStays inside HearthsayStays inside Hearthsay
Auth tokens and session cookiesStays inside HearthsayStays inside HearthsayStays inside Hearthsay
Billing and subscription detailsStays inside HearthsayStays inside HearthsayStays inside Hearthsay
Future message draftsStays inside HearthsayStays inside HearthsayOnly if future-messages scope is approved
MCP tool responses (memory answers, lists)Stays inside HearthsayStays inside HearthsayReturned to the connected assistant

What never leaves Hearthsay in in-app and BYO-AI modes

  • Raw voice recording files in in-app AI and BYO-AI modes (MCP can return a consent-gated, short-lived signed audio link only under the sources scope)
  • Consent Passport records and verification status
  • Auth tokens, session cookies, and login credentials
  • Billing details and subscription status
  • Vault contents outside the scopes you explicitly approve (for MCP)
  • Memories you did not select for a specific AI query
  • System audit logs and access history
  • Loved-one profile data outside the tools you approved