Privacy Policy
Fonomigo is an assistant you text. It's invite-only while we test it. This policy covers what Fonomigo collects, why, who else handles it, and how you remove it. If you have a question, write to privacy@fonomigo.com.
What we collect
- Your phone number. It's how you sign in: we text you a code. Sign-in is handled by Clerk.
- Accounts you connect. When you connect a Google account, we keep that account's email address, which permissions you granted, and a token that lets Fonomigo read it. We never see or store your Google password.
- Content from connected accounts. Only when Fonomigo needs it to answer or help you: for example, reading your recent email or upcoming calendar events when you ask about them.
- Your messages to Fonomigo and its replies, so it can keep the conversation going.
- Basic technical logs (such as request times and errors), kept to run and secure the service.
Google account data
If you connect Google, Fonomigo asks for read-only access to Gmail and Google Calendar, and for your email address. It can't send, delete, move or change your email or events.
Fonomigo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google data only to provide and improve the features you use in Fonomigo.
- We don't sell it, use it for advertising, or use it to build profiles for anyone else.
- We don't use it to train general-purpose AI models.
- No person at Fonomigo reads it unless you ask us to (for example, for support), it's needed for security or to comply with the law, or it has been aggregated and anonymized for internal operations.
How we use information
- To answer your messages and do what you ask.
- To keep your account secure and the service working.
- To contact you about your account.
We don't sell your personal information, and we don't show ads.
Who else handles it
We use a few service providers that process data for us, only to run Fonomigo:
- Clerk: phone-number sign-in.
- Fly.io: hosts the Fonomigo app.
- Turso: stores Fonomigo's database.
- AI model providers: when Fonomigo writes a reply, the relevant part of your request is sent to the model provider to generate it, under terms that don't allow them to train on it.
We may disclose information if the law requires it, or to protect people's safety.
How we protect it
- Connection tokens are encrypted (AES-256) before they're stored, with a key kept separately from the database.
- All traffic uses HTTPS.
- Access to production systems is limited to the people who run Fonomigo.
Your controls
These are separate, so you can do one without the others:
- Disconnect an account. In your Fonomigo console, choose Remove on the account. Fonomigo stops reading it right away, deletes its stored token and revokes its access at Google. You can also remove access at myaccount.google.com/permissions.
- Delete collected content, such as emails or events Fonomigo has read.
- Delete what Fonomigo has learned about you.
During testing, the last two, and deleting your whole account, are done on request: email privacy@fonomigo.com and we'll confirm within 30 days.
How long we keep it
We keep your information while your account is open. When you disconnect an account, its token is deleted immediately. When you delete your account, we delete your information within 30 days, except where the law requires us to keep something longer.
Children
Fonomigo isn't for anyone under 16, and we don't knowingly collect their information.
Changes
If we change this policy, we'll update the date at the top. If a change is significant, we'll tell you before it takes effect.