Privacy Policy

Last Updated: September 4, 2026

1. INTRODUCTION

KnowItOwl! ("we," "our," or "the App") is committed to protecting your privacy. This policy explains how we handle your information when you use our Apple Watch and iPhone application.

Our core privacy principle: KnowItOwl! does not request your name, email address, phone number, contacts, advertising identifier, or location from the app. We process an opaque app-scoped account identifier, your questions, audio, conversation context, purchase records, and limited technical diagnostics only to operate and secure the service. Questions sent for AI processing travel over HTTPS in readable form; conversation history and audio saved to your account are encrypted on your device before being stored in Firebase.

2. INFORMATION WE COLLECT

Account Information

  • KnowItOwl! has no login screen. On iPhone, the app verifies Apple's signed App Transaction and creates a stable account identifier scoped to KnowItOwl!
  • Our backend derives a one-way hashed user ID from the app's bundle ID, the App Store environment, and Apple's app transaction identifier. It does not contain your Apple Account name or email address and is not used to track you across other apps or websites
  • The same app-scoped identity lets your credits and account data remain available after reinstalling KnowItOwl! or using it on another eligible device associated with the same App Store account

Voice Input and Conversations

  • When you ask by voice, your recording is sent through the authenticated KnowItOwl! backend to Google Cloud Speech-to-Text. The transcript or a typed question and up to three recent messages are sent to Vertex AI Gemini, with Google Search grounding when available. Answer text is sent to Google Cloud Text-to-Speech when spoken audio is requested
  • Your questions and AI responses are encrypted on your device before being stored in your account for conversation history and cross-device sync
  • Voice recordings and AI-generated audio saved for playback are encrypted on your device before Firebase storage

Credit and Purchase Information

  • Your credit balance and ledger history (purchases, free grants, and usage) are stored under your app-scoped account identifier
  • App Store transaction claims are retained to prevent the same consumable purchase or promotional credit from being granted more than once
  • We do NOT process or store payment card details — all purchases are handled by Apple through the App Store

Device Information

  • Device and app attestation tokens are processed to verify that requests come from legitimate copies of KnowItOwl! (Firebase App Check using App Attest on iPhone and DeviceCheck on Apple Watch)
  • The app does not collect precise location, contacts, advertising identifiers, or cross-app tracking data

Diagnostics

  • Apple may provide anonymized crash and hang reports through App Store Connect and Xcode Organizer when users share diagnostics with Apple
  • KnowItOwl! sends privacy-filtered operational events such as app version, platform, workflow state, duration, and error category to our authenticated backend. These events exclude questions, transcripts, answers, audio, authentication tokens, and purchase transaction IDs
  • Optional verbose logging adds additional privacy-filtered workflow breadcrumbs and can be turned off in Settings

Support Communications

If you contact us by email or use the support form, we receive the name, email address, subject, and message you choose to provide so we can respond. This information is not collected by the KnowItOwl! app itself.

3. HOW WE USE YOUR INFORMATION

  • To provide AI-powered responses to your questions
  • To maintain conversation history for contextual, multi-turn dialogue
  • To sync your conversations and credits between your Apple Watch and iPhone
  • To store and play back audio recordings of conversations
  • To manage your credit balance and process free credit grants
  • To validate App Store purchases and prevent duplicate grants
  • To diagnose failures, secure the service, and improve reliability without recording conversation content in diagnostics

What We Do NOT Use Your Data For

  • We do NOT use your conversations, audio, or any personal data to train AI models — not ours, not anyone else's
  • We do NOT sell, license, or provide your data to data brokers, aggregators, or any third parties for marketing, profiling, or any purpose beyond operating this app
  • We do NOT mine your conversations for insights, trends, or analytics
  • Your data exists solely to provide you with the KnowItOwl! service. Period.

4. THIRD-PARTY SERVICES

KnowItOwl! Backend and Google Cloud AI Services

KnowItOwl! sends requests to an authenticated backend operated by Sandy Brook DevWorks LLC on Google Cloud Run. The backend uses Google Cloud Speech-to-Text, Vertex AI Gemini, Google Search grounding, and Google Cloud Text-to-Speech as needed to answer a question. The following data may be processed each time you ask:

  • Voice audio recordings — the AAC audio captured when you speak a question (voice input only)
  • Questions — a voice transcript or the text you type
  • Conversation context — up to three recent messages to maintain context
  • Answer text — sent to Google Cloud Text-to-Speech when spoken audio is requested

This data is transmitted over HTTPS solely to create a transcript, generate and ground an answer, and synthesize spoken audio. Sandy Brook DevWorks does not use it to train AI models. Google's handling of this data is governed by the Google Privacy Policy and Google Cloud Data Processing Addendum. We require service providers to protect user data consistently with this policy and applicable App Store requirements.

Before the first question, the app identifies Sandy Brook DevWorks and Google as the processors, lists the data sent, and asks for explicit permission. No question is sent unless you choose Allow & Continue. You can stop future AI processing by not submitting another question, erase personal content with Delete Personal Data in Settings, or contact us for help with a privacy request.

Firebase (Data Infrastructure)

We use Google Firebase services to securely store and sync your data:

  • Firebase Auth — manages the short-lived authenticated session for your app-scoped App Store identity
  • Cloud Firestore — stores your encrypted conversation messages and credit balance
  • Firebase Storage — stores encrypted audio recordings for playback
  • Firebase App Check — verifies that requests come from legitimate Apple devices (App Attest on iPhone, DeviceCheck on Apple Watch)

All Firebase data is stored in Google Cloud infrastructure in a multi-region US deployment (nam5) for high availability (99.999% SLA). Your data is isolated under your authenticated user account and is not accessible to other users.

Apple (Identity, Purchases, Settings, and Diagnostics)

Apple's signed App Transaction supplies the app-scoped identifier used to create your account without a login screen. In-app purchases are processed entirely by Apple through the App Store. Voice preferences are synced using iCloud Key-Value Store, and encryption keys can sync using iCloud Keychain. Apple may provide anonymized crash and hang diagnostics through App Store Connect and Xcode when users share diagnostics with Apple.

Formspree (Support Requests)

If you submit the optional web support form, Formspree processes the name, email address, subject, and message you enter so the request can be delivered to us. You can contact us directly by email instead. See the Formspree Privacy Policy.

Relevant privacy policies:

Important: Your question, voice audio when used, and recent conversation context are processed in readable form by the KnowItOwl! backend and applicable Google Cloud AI services in real time. This processing is necessary to generate an answer. Saved conversation content and audio are separately encrypted on your device before Firebase storage.

5. DATA STORAGE AND RETENTION

Where Your Data Lives

  • Encrypted conversation messages, your credit balance, and encrypted audio recordings are stored in Google Firebase under your app-scoped account identifier
  • Data is stored in Google Cloud infrastructure in a multi-region US deployment for high availability and durability
  • Your data is isolated to your account and is not accessible to other users or to Sandy Brook DevWorks staff in the normal course of operations
  • Voice preferences are synced via Apple's iCloud Key-Value Store

Retention and Data Control

  • You can delete individual messages or all conversation history at any time within the app
  • Delete Personal Data in iPhone Settings permanently removes your conversation messages, stored audio, pending interaction records, local encryption key, and Firebase Auth user record
  • Your exact credit balance, credit ledger, and redeemed App Store transaction claims are retained after personal-data deletion or reinstallation. These commerce records are kept for the life of the service, or longer if required by law, so purchases and promotional credits cannot be granted more than once
  • Privacy-filtered operational diagnostics are retained only as long as reasonably needed for security, reliability, and troubleshooting under our current Google Cloud logging settings
  • Support messages are retained while needed to answer the request, maintain reasonable support records, and meet legal obligations
  • Uninstalling the app removes local app data but does not by itself delete encrypted cloud content or retained commerce records

No Data Harvesting

We want to be unambiguous: your data is never harvested, sold, or shared with data aggregators. It is never used to train AI models. It is never analyzed for advertising or profiling purposes. Your conversations and audio exist in Firebase solely to provide you with the KnowItOwl! service, and for no other reason.

6. DATA SHARING

  • We do NOT sell, rent, license, or share your personal information with third parties for marketing, advertising, profiling, or AI training purposes
  • We do NOT provide your data to data brokers or aggregators under any circumstances
  • We do NOT use advertising or tracking technologies
  • Data is disclosed to Google Cloud and Firebase only as necessary for authentication, storage, transcription, answer generation, search grounding, text-to-speech, security, and privacy-filtered operational diagnostics
  • Optional web support requests are disclosed to Formspree so they can be delivered to us
  • We receive only aggregate, non-identifying statistics from Apple App Store Connect (download counts, basic usage metrics)

7. ANALYTICS AND TRACKING

  • We do NOT use third-party analytics or tracking tools for user behavior or usage patterns
  • We do NOT track your behavior or usage patterns
  • Apple may provide anonymized crash and hang reports through App Store Connect and Xcode Organizer when a user chooses to share diagnostics with Apple
  • Our authenticated backend receives allow-listed operational events for errors and workflow health. These events do not contain questions, transcripts, answers, audio, authentication tokens, or purchase transaction IDs
  • Optional verbose logging can be disabled in the iPhone app's Settings
  • Basic app statistics (downloads, active devices) are provided by Apple and do not identify individual users
  • No cookies or tracking pixels are used

8. CHILDREN'S PRIVACY

KnowItOwl! is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

9. YOUR PRIVACY RIGHTS

You have the right to:

  • Delete individual messages or all conversation history within the app
  • Use Delete Personal Data in iPhone Settings to erase conversation content, stored audio, the encryption key, and the current Firebase Auth user record
  • Stop future AI processing by not submitting additional questions
  • Ask us to help with access, deletion, or consent questions; retained commerce records remain subject to the limitations described above
  • Stop using the app at any time
  • Contact us with privacy questions or concerns

10. DATA SECURITY

We follow security best practices as recommended by Apple and Google, implementing defense in depth across every layer of the app:

  • All data is transmitted over HTTPS/TLS encrypted connections
  • Client-side encryption for saved content — conversation text and audio saved to your account are encrypted on your device using AES-256-GCM before Firebase storage. AI requests must be processed in readable form by the backend and Google Cloud AI services to generate transcripts, answers, and audio
  • App-scoped identity — the backend validates Apple's signed App Transaction and derives a one-way hashed user ID without requesting your Apple Account name or email address
  • Firebase App Check — verifies that every request originates from a legitimate Apple device using hardware attestation (App Attest on iPhone, DeviceCheck on Apple Watch), preventing unauthorized API access
  • Firebase Auth — ensures that only you can access your data through authenticated sessions
  • Server-side credit validation — the backend verifies signed App Store transactions and performs credit operations in tamper-resistant Firestore transactions; clients cannot directly grant credits
  • Firebase Storage security rules — restrict audio file access to the owning user, with a 5MB file size limit and content type validation
  • User-scoped encryption keys — encryption keys are scoped to your user account, preventing cross-user key sharing on shared devices
  • Privacy-filtered structured logging — diagnostics use allow-listed event names and Apple's os.Logger privacy annotations. Questions, transcripts, answers, audio, authentication tokens, and purchase transaction IDs are excluded from diagnostic events, while sensitive local values are marked private
  • No Google AI service credentials are stored on or distributed to client devices; provider access is restricted to the authenticated backend

Encrypted Storage

Conversation messages and audio files saved to your account are encrypted on your device using AES-256-GCM (via Apple CryptoKit) before being stored in Firebase. The encryption key is stored in your iCloud Keychain and syncs only through Apple's Keychain services. This storage protection is separate from real-time AI processing, during which the current question, applicable audio, and recent context must be readable by the KnowItOwl! backend and Google Cloud AI services.

11. INTERNATIONAL DATA TRANSFERS

AI service providers may process data in countries outside your residence. By using KnowItOwl!, you consent to this transfer and processing.

12. CHANGES TO THIS POLICY

We may update this privacy policy from time to time. We will notify you of significant changes by:

  • Posting the new policy at knowitowl.sandybrook.io/privacy
  • Updating the "Last Updated" date
  • Providing an in-app notice when a material change requires renewed consent

Continued use of the app after changes constitutes acceptance of the updated policy.

13. CALIFORNIA PRIVACY RIGHTS

California residents: We do not sell personal information. We do not share personal information for cross-context behavioral advertising. You have rights under CCPA/CPRA to:

  • Request information about data we collect about you
  • Delete eligible personal content directly within the app; commerce records are retained as described in Section 5
  • Not be discriminated against for exercising your privacy rights

To exercise these rights, contact us at hello@sandybrook.io.

14. CONTACT US

If you have questions about this privacy policy or our privacy practices:

Email: hello@sandybrook.io

Sandy Brook DevWorks LLC
5900 Balcones Drive Ste 100
Austin, TX 78731
United States