PersonalGenie

What leaves your device.

PersonalGenie reads conversations you choose so it can hold your context. That only works if you know exactly what travels, where it stops, and when it is gone. This page is the answer, written from the code rather than from a policy template.

Every claim below describes behaviour that is implemented today. Where the iPhone app and the web app differ, both are stated separately — because they do differ, and a single reassuring sentence covering both would be false for one of them.

The rule

Local by default. Cloud only where you chose it.

Nothing about your life is collected in the background. A conversation is read only after you pick that specific person, and only in the mode you picked. Reading is a thing you do, not a thing that is happening.

Modes

Two reading modes, and what each one sends

Genie asks for one decision about every relationship read: whether it may see the other person's words. Both modes clean the conversation first; they differ only in whose turns survive that cleaning.

Your messages onlyDefault
  • Only the messages you wrote go to the model.
  • Every turn the other person sent is replaced, before anything leaves, with the literal token “[received]”. Their words are not summarised, classified, or transcribed — they are not present.
  • Genie still sees that they replied and when, so it can read cadence and reciprocity without reading them.
Both sidesYou turn this on
  • Both people’s turns go to the model, after the same cleaning pass your own messages get.
  • This is the mode that lets Genie understand an actual back-and-forth — the repair, the tension, the joke that keeps coming back.
  • It applies to new reads only. Turning it off does not rewrite a portrait that was already built with it on, and turning it on does not go back and re-read anything.
The cleaning pass

What happens before anything is sent

The cleaning runs on your device — in the browser on the web, on the phone in the iPhone app — before the first byte goes anywhere. It does three things:

  • Names become slots. You are USER. Everyone else is CONTACT_A, CONTACT_B, and so on. The model is told the real names are not provided, and they are not.
  • Direct identifiers come out by pattern. Email addresses, phone numbers, card numbers, social-security patterns, and long digit runs are stripped from the text. URLs keep their destination and lose their tracking parameters.
  • The history is bounded. A single read sends at most the newest 24 months of a conversation, and at most 400,000 characters of it, newest first. Older messages are not sent. This cap is enforced in one place on each platform, on the path every read flows through.

The raw file or message database itself never leaves. On the web your export is parsed in the browser tab and the original is never uploaded. In the iPhone app the messages your Mac reads travel over your own local network to your own phone and stop there.

Never

What is never sent to a model, in any mode

  • Your name, or the name of anyone you talk to.
  • The raw conversation file, or the message database it came from.
  • Photos, videos, voice notes, documents, or contact cards authored by the other person — not as files, not as transcripts, not as descriptions.
  • Exact identifiers: the phone numbers and email addresses the cleaning pass removed.
  • Anything at all from a conversation you did not select. Selection is per person, and a Genie that has read three people has read three people.
The guard

This is enforced at the boundary, not trusted

A client that is buggy, stale, or modified must not be able to park raw content on our server. So the contract above is re-checked server-side, at the moment of enqueue, by web/lib/ingest/validateEnvelope.mjs. It refuses an envelope that:

  • carries any of the other person's words while your mode is your messages only — every non-user turn must be exactly [received];
  • contains an unscrubbed email, phone number, card number, social-security pattern, or long digit run — checked with the same expressions the on-device scrubber uses, so a compliant client always passes and a non-compliant one always fails;
  • addresses anyone by anything other than an alias slot (USER or CONTACT_…);
  • carries a timestamp that does not parse.

A refused envelope is not queued, not stored, and not read. The validator is pinned by a test that injects a distinctive string into each forbidden position and asserts the rejection — required for any new outbound payload type before it can ship.

Custody

What our server holds, and for how long

The cleaned copy of a conversation
Held only until that read finishes, then deleted. If a read fails transiently it is kept for one retry; after that it is deleted and re-reading means adding the conversation again. Anything abandoned is deleted within 24 hours by a sweeper, whether or not it was ever read.
The model relay (iPhone app)
The iPhone builds its own model request and sends it to a relay at personalgenie.ai that adds the API key and forwards it to Google. The relay holds no logic and no state: it does not store the request, the response, or anything derived from either.
Display names (web only)
On the web, the real name of a person you added is stored with your account so the interface can say “your chat with Sam” instead of “your chat with CONTACT_A”. It is never included in anything sent to the model. The iPhone app does not send names to us at all — it keeps its own.
Your portrait and conversations
On the web, stored with your account so they are there on your next visit. In the iPhone app, stored in a local vault on the phone that is marked excluded from device backups, so it is not copied into iCloud Backup or a migration image.
An unclaimed Genie (iPhone app)
A Genie you have not signed into has one row on our side: its id, a hash of a secret held on your phone, and request counters. No content. It is removed by “Delete everything”.
Deletion

Delete everything means everything we can reach

Settings has one control. On the web it removes your companion, your portrait, your conversations, and everything derived from them. In the iPhone app it removes the local vault and, when your Mac is reachable on the same network, tells the Mac companion to drop its pairing, its standing permission, and its cached index in the same action.

If the Mac cannot be reached, the phone is still wiped and the app says so — the Mac wipe is left queued and clearly pending rather than reported as done. We do not describe deletion as atomic across two devices until it is atomic across two devices.

There is no soft delete and no recovery window. Deleting is not reversible, which is the point of it.

Third parties

Who else ever sees any of it

One: Google, which runs the model. A cleaned, aliased, bounded conversation goes to the Gemini API for that one request. What Google may do with an API request is governed by Google's terms for that API; we have no separate arrangement that changes them.

Nobody else. Your data is not sold, not shared, not used to build a product for anyone else, and not used to train any model of ours — we do not train models. There is no advertising in this product and no plan for any.

There is no analytics or telemetry SDK in the app or on this site. Nothing reports your usage anywhere. What the iPhone app measures about itself, it writes to the phone and leaves there.

Questions, or something on this page that does not match what you observe: privacy@personalgenie.ai. The principles this page is held to are the thirteen in our internal privacy constitution; a claim here that the code does not support is treated as a bug, not as marketing.