Privacy Policy
Last updated: 2026-07-04 / This service is in beta
1. Core principle: your data stays in your hands
Shiori works with your daily notes, reflections, and work data, but it does not store that actual content — journals, meeting records, recordings, health data — on our servers. It lives on your own computer and in storage that you yourself manage (a place your account owns and you can delete at any time).
Our servers keep only the minimum metadata needed to run the service: your account, billing, and integration settings (see §2).
This policy explains, for each of the three parts that make up Shiori — (1) the Shiori cloud service, (2) the Mac app, and (3) the iPhone app — what information is handled and where it is stored.
2. The Shiori cloud service
2.1 Information we collect
- Google account information (email address, name, profile image)
- GitHub integration details (linked repository name, access token)
- Profile and goals you enter during Shiori's initial setup
- Billing and subscription information (plan and payment status; your card number itself is never stored by us)
- Usage (aggregated token consumption, model, etc.)
- If you send feedback: its content and your reply-to email address
This metadata is stored encrypted in our cloud database and protected by row-level security (RLS). Your actual content — journals, meeting records, recordings, health data — is never stored there.
2.2 External services we use (role, company, country)
We use the following external services to provide Shiori. All of them are companies in the United States, and the relevant personal data is handled in a foreign country (primarily the United States). For each company's data protection practices, please refer to its privacy policy.
- Sign-in and calendar integrations: Google LLC (USA)
- Payment processing: Stripe, Inc. (USA). Your card details are held by Stripe and never stored by us
- Email delivery: Resend, Inc. (USA). Used for emails we send you, such as replies to your feedback
- Database and authentication: Supabase, Inc. (USA). This is where the metadata in §2.1 is stored
- Error monitoring: Sentry (Functional Software, Inc., USA). Collects technical information about failures only — never the content of your conversations or documents
Your conversations with Shiori (the AI) take place on your own Anthropic (Claude) account, and their handling is governed by your agreement with Anthropic and its policies.
2.3 Google services integration
If you connect Google Tasks or Google Calendar, the service accesses them within the scopes you grant, to read or create tasks and events as you instruct. Retrieved data is handled transiently and not permanently stored in our database. You can disconnect at any time in settings.
2.4 Cookies and analytics
We use authentication cookies to keep you signed in. We may use analytics tools such as Vercel Analytics and Google Analytics to collect anonymous usage data (page views, time on page, device type). We do not collect personally identifying information through these tools.
2.5 Shared projects and guests
When the owner of a shared project invites a guest (a viewer without an account), our server — with the owner's permission — reads the shared project's content to display it to the guest, and delivers the guest's comments back to the owner's shared project (i.e., the server relays content between the owner and the guest). Only the invited shared project is relayed; the owner's personal projects and personal memory are never shared with guests.
- Information we store about guests: display name, posted comments, and an access token. An email address is retained only if it was used to send the invitation email.
- Joining, invitations, permission changes, and removals are recorded in an audit log that the owner can review.
- The owner can revoke or disable a guest invitation at any time; once disabled, the guest can no longer access the shared content.
3. The Mac app
- Audio (meeting recordings): records audio in step with the meetings on your calendar and produces transcripts and summaries. Transcription and summarization are processed on your Mac; the audio is never sent to an external server. Recordings, transcripts, and summaries are stored on your Mac. You are responsible for notifying meeting or call participants and obtaining any consent required where you are.
- Activity (app and browser usage): records which apps and sites you used, stored only on your Mac as material for reflection. Nothing is sent externally.
Data handled by the Mac app is stored locally on your Mac. If you enable the optional GitHub integration, these records are also stored in your own private GitHub repository — a place your account owns and you can delete at any time.
Each feature can be turned off individually in the app settings at any time.
4. The iPhone app
- Recording: records audio such as voice memos and produces transcripts. For transcription, audio data is sent to the speech-recognition provider Soniox, Inc. (USA). Before anything is sent, the app asks for your consent (if you do not consent, no audio is sent). Recordings and transcripts are stored on your device.
- Health: reads health data such as steps, sleep, and heart rate (read-only; we never write), and delivers it to your Mac via your own iCloud Drive. It is never sent to our servers. We never use your health data for advertising or data mining.
- Camera (document scanning): captured documents are stored only on your device and on your Mac. They are never sent to our servers.
Each feature can be turned off individually in the app settings at any time.
5. Purposes and administrator access
- Providing the Shiori service (conversation, memory, profile)
- Account authentication and session management
- Service improvement using anonymized, aggregated usage only
- Investigating serious problems and responding to your feedback
Administrators (the service developers) do not read individual users' data. As described in §1, your actual content does not exist on our servers by design.
Individual access happens only when:
- you report a technical problem or feedback and we investigate to respond, or
- disclosure is required by law.
6. Your rights
- View your data at any time (on your devices, GitHub, and in Shiori)
- Edit your profile and goals (in conversation or settings)
- Reset onboarding (confirmed in conversation; existing goals are archived first)
- Delete your account and all data in our database (sidebar → "Delete account"; takes effect immediately)
- Delete on-device data (uninstall the Mac/iPhone apps or remove the data folders)
Deleting your account removes all data tied to you in our database. Data on your devices and GitHub remains under your own control — we cannot delete it, because it is yours.
7. Changes
This policy may change without notice. Significant changes will be announced within Shiori.
8. Contact
For questions about this policy, contact SARAI, K.K. (support@shiori-ai.com).