Effective Date: February 12, 2026
Sphyro is built on a privacy-first design. We believe your private life is your data, and the app is built to keep it on your device and minimize what is sent to external networks — only what a given feature genuinely needs to work.
All your notes, financial transactions, goals, and dialogue history are stored exclusively in your Android device's internal memory (SQLite). We do not create server-side copies of your content database. (The server keeps only an anonymous usage record — your device UUID and feature-usage counters — needed to enforce free/Pro limits and verify your subscription.)
Optional backup to Google Drive. If you choose to back up your data, Sphyro signs in with
your Google account and stores a single backup archive in your Drive's hidden, app-specific folder (the
drive.appdata scope). This folder is private to the app and not visible in your Drive UI. We
access only this app folder — never your other Drive files, documents, or photos — solely
to create and restore your backup at your request. Backup is entirely optional and user-initiated; you can
disconnect it at any time, and revoke access in your Google Account settings.
For intelligent features (semantic search, context analysis) to function, your device transmits to the cloud only those data fragments necessary to answer a specific query. These fragments are processed by our AI sub-processors — Google Cloud Vertex AI (Gemini) for language understanding and Jina AI for relevance ranking — solely to generate the answer to your request. (Under Google Cloud's terms, data sent to Vertex AI is not used to train Google's foundation models.) The cloud operates in Stateless mode: it does not store your knowledge base permanently. Your "memory" is provided to the server by your device fresh for each request and is wiped from the server's RAM immediately after the response is generated.
For features that need live external data — web search and places/flights — only what is necessary is sent to the relevant provider to fulfill your request: your query, and for location-based features your location. This is used solely to produce the result, never for advertising or the sale of your data.
Files and images you attach in chat. When you attach a photo or a document (PDF, Word, Excel, text file) to a message, the file is sent over an encrypted connection to our server and then to our AI provider (Google Cloud Vertex AI) solely to read its contents and answer your question. We do not store the files themselves — only the resulting answer remains in your conversation. If you ask us to save the content (for example, “save this to my notes”), the extracted text is stored in your account and is deleted together with it.
Sphyro does not use email addresses, phone numbers, or social networks for login. Your identity in the system is an anonymous UUID (unique identifier) tied to your device. If you delete the app, we cannot recover your data, as we have no access to your key.
For payment processing and subscription management, we use the RevenueCat service. An anonymous system ID of your device is transmitted to confirm the availability of paid features if the application is reinstalled. All payment information (card numbers, etc.) is processed exclusively through Google Play Billing; Sphyro has no access to it.
Sphyro requests microphone access for its voice features. The floating voice assistant (Orb) can keep a hands-free voice conversation running while the app is in the background, as a foreground service with a persistent notification you can turn off at any time. The microphone is active only during a voice session you have started — never silently. When you ask the assistant to "look at your screen," the app captures the current screen (after the system's screen-capture consent dialog), sends that single image to the AI for vision, and then discards it — only on your explicit request. Audio and screen data are used solely to fulfill your requests and are never sent to advertising networks.
Your data is stored in the app's private storage, which Android isolates from other applications. Access to the app can be gated by your device PIN, fingerprint, or Face ID (app lock), and sensitive keys are held in the hardware-backed Android Keystore. Note: the local database itself is not separately file-encrypted, so we recommend keeping a device lock enabled.
We do not collect telemetry about your movements or interests, and we do not sell your data. For app stability we use two diagnostics tools: Google Play's built-in Android Vitals (anonymous, aggregated crash/ANR data via Google Play) and Sentry (crash and error reports). Sentry receives only technical diagnostics — stack traces plus device/app metadata — with personal identifiers and sensitive values scrubbed before sending; it never includes your notes, messages, finances, or other content. Technical server logs contain only anonymous information about load and system errors, not the meaning of your requests.
Data is stored on your device as long as the Sphyro app is installed. When you delete the app, Android system mechanisms automatically wipe the app's private database.
You have full control over your data. You can edit or delete any record within the application at any time.
To delete your account and all associated data, open Settings → Delete account & data in the app. This permanently erases everything stored on your device (memories, finances, notes, habits, chat history) and purges the data held on our servers (usage counters, subscription state and your device identifier). This action cannot be undone.
Uninstalling the app removes all locally stored data from your device. If you have already uninstalled the app and want the remaining server-side data deleted, email us at ai@sphyro.me and we will process your request.
The application is not intended for children under 13 years of age. We do not knowingly collect or store personal information from children.
We may update this policy. In case of significant changes, information about this will appear in the app interface.
If you have any questions about this policy or the security of your data, you can contact us at: ai@sphyro.me