Privacy
Last updated 30 September 2026
Foley keeps a local copy of your work on your computer, phone or browser. Signing in lets your account sync across devices. This page says which information leaves your device, where it goes, and when.
Your tasks live on your machine
Foley stores your tasks, projects, folders, dates, notes, attachments and rules in a local database. Account data also syncs through the Foley service when you sign in. Rules created while signed out stay local and are not automatically transferred into a signed-in account.
The phone app
The phone app is a full Foley: it keeps your tasks in its own database on the phone, and it syncs them through our server so your Mac and your phone show the same list. Signing in is the same Firebase account as the Mac app.
When you speak to it, the audio and a short list of your tasks and project names go to the AI the same way the Mac app's do - through our server to OpenRouter on a subscription, or straight from the phone to OpenRouter if you added your own key in Settings. The phone does not retain recordings after capture. It keeps transcript and result history in its local database and syncs that history with your signed-in account.
The phone asks before the first time. A sheet says what will be sent and to whom, and offers Agree and continue or Not now. Nothing leaves the phone until you agree, and Settings > Privacy withdraws that at any time, after which the phone asks again.
Per-project kept out of AI context follows your account to the phone and the browser too. Calendar and Slack connections are configured in the Mac app. The ChatGPT connection uses Foley's cloud service and does not require the Mac app to be running.
What happens when you speak
To turn what you said into tasks, Foley sends two things to an AI service: the audio, to be transcribed, and then the transcript together with a short list of your tasks and project names, so it can work out which project a job belongs to and what a date like before Thursday means - and, when you follow up or speak again within 60 seconds of Foley's last reply, what you last said and what Foley answered, so "make it Sunday instead" has something to refer to.
Your saved rules are included when Foley organises a capture. Confirmed active rules guide the result; pending and inactive rules help Foley recognise a request that matches an existing rule. A proposed rule needs your confirmation before it becomes active. Your explicit instruction for the current capture takes precedence.
Rules belong to your account and are not shared with project collaborators. You can review, edit, pause or delete them in Settings. Deleting a rule removes its instruction from the current record and from future AI context. Synchronisation history can retain earlier instructions until the account is erased.
When you correct and save a name in a task created from dictation, Foley can retain the original spelling, the corrected spelling and a short surrounding context. These learned spellings guide later voice captures and may be sent with a transcription or organising request. They sync privately within your account, not with project collaborators; spellings learned while signed out stay on that device. Review or forget them in Learned spellings in Settings. Forget removes the hint from future requests and prevents a delayed upload from restoring it. The manual Dictionary remains separate.
On a subscription the request goes to our server first - the Foley service, run by Hanamori Labs, LLC - which forwards it to OpenRouter. OpenRouter routes it to the model provider doing the work, so that provider receives the words for that one request. With your own OpenRouter key on desktop or the native phone app, AI requests go directly to OpenRouter. Signed-in transcript history still syncs through Foley, including when you use your own key. The browser uses your account's AI service and does not use a key saved in another Foley app. Browser speech recognition is handled by the browser's speech service; the resulting words go to Foley for organisation.
Replies read aloud are voiced by ElevenLabs. When Foley reads its reply to you through our AI service, our server sends the words of that reply to ElevenLabs (Eleven Labs Inc., in the US), which turns them into the voice you hear. A reply can include a task's title, a project name or a date. Only the reply's words and the chosen voice are sent - not your recording, your transcript, your other tasks, your account or your email address. ElevenLabs keeps request data under its own terms, to improve its services, troubleshoot and keep its systems secure; its zero-retention option is for enterprise customers, which Foley is not. If ElevenLabs cannot read a reply, the phone and Mac apps read it with a voice model through OpenRouter instead. The Mac app uses ElevenLabs from version 1.0.66; earlier versions read every reply through OpenRouter. With your own OpenRouter key, replies are not sent to ElevenLabs.
A project can be marked kept out of AI context. Its tasks are never included in anything sent to the AI - not as context, not for planning, not once.
Research searches the web, and only when you ask. Say "research for me", "look into this" or "find out about" while capturing, or press Research this on a task, and Foley sends one question to a search model through OpenRouter. That model searches the public web, so the question reaches a search provider as well. What goes out is that one question - or, from the button, the task's own title and details. Your other tasks, your projects, your account and the rest of what you said do not. The findings are written into that task's details, on your devices, and nothing is sent unless you asked for it. Research is part of Foley Pro and is limited to fifty searches a month.
Every capture is sorted first. Each time you capture something, Foley asks TypeSafe what kind of request it is - a new task, finishing or removing one, a change, a question, something to research - and which of your tasks, if any, it is about. When the answer is clear, Foley acts on it straight away - answering your question, marking a task done or removing it, or asking the time of an appointment - instead of waiting for the full organiser. The same question decides which task you meant when you follow up with "mark it as done" or "move that to tomorrow". What goes out is the sentence you said, the exchange just before it when there is one, and the id, title and status of at most sixty of your tasks: the ones your words name come first, then ones due or overdue, ones you've just finished, and others from your list. Your notes, your due dates, your attachments, your projects, your clipboard, your screen, your email address and your account identifier do not. The answers are choices from fixed lists; TypeSafe writes nothing into your tasks. Foley keeps none of what was sent; when Foley acts on TypeSafe's answer, including which task you meant, that capture's support record says so, described below.
Tasks written by agents may have their titles sent to TypeSafe, to judge whether they belong on your plan.
Server errors go to Sentry. When Foley's server hits an error, it sends a report to Sentry (Functional Software, Inc., in the US), the service we use to find and fix bugs. A report says what failed and where in our code, and which of Cloudflare's data centres handled the request. It never includes your account, your tasks or anything you said or typed, request contents, your IP address or your device, and Sentry keeps it for up to 90 days.
Your daily plan is made at the time you set, even when no app is open. If you choose a plan time, Foley's server plans your day at that time on the days you picked. It sends your newest open tasks and your project names to the AI through our server to OpenRouter, as a plan you ask for would, and never a project kept out of AI context. The plan is saved in your transcript history, and your phone gets a notification that says only that it is ready. Clearing the plan time stops it.
Recordings are kept, on your machine, until you say otherwise
The desktop app can retain capture audio for playback, transcription retries and export. Those retained recordings stay on that computer and are excluded from transcript history sync. Transcribing or retrying a recording can send audio to the configured AI provider.
Retention is on by default. Settings lets you turn it off and delete this account's retained recordings, including unfinished captures and older recordings without an assigned account. Recordings belonging to another account on the computer remain there. Deleting audio keeps the transcript. Unfinished desktop captures retain their words and follow-up answers until you complete or explicitly discard the saved attempt.
Account sync and project sharing
Signing in lets Foley sync account data between your devices. Project changes and attachments are stored on Cloudflare. Sharing a project with another person is a separate choice; only the people you grant access can use that shared project.
Transcript history and rules belong privately to your account. Project collaborators do not receive them. Transcript history includes your words, follow-up answers, recorded results and rule use, submission platform and available timings. Original recordings, images and clipboard attachments are excluded from this history sync.
Older local history without a verified account stays on the device until you explicitly import it into your signed-in account. Signing out or clearing a device's cache does not delete history already stored by the service. History and its stored synchronisation receipts remain until account deletion.
Signing in is handled by Google Firebase. We hold the account identifier it gives us and, if Google has confirmed it, your email address - which is what an invitation to a shared project is matched against.
Foley's emails are sent through Resend (Plus Five Five, Inc., in the US). There are two kinds. An invitation goes to the address you invite, and names the project, the role, your verified email address and the link to join; a reply goes to you. A sync warning goes to a project's owner if the project suddenly logs an unusual amount of activity, and gives the project's name and how much it logged - no task titles or content.
Encryption and service access
Cloudflare encrypts the stored server copy using Cloudflare-managed keys. Foley can read synced content to operate the service; this is not end-to-end encryption. Local databases do not currently have a separate layer of content encryption provided by Foley. Their protection depends on your device, browser profile and operating-system settings.
Calendar, Slack and coding agents
Foley can put an entry in your Google Calendar, send a message to Slack, and let a coding agent such as Claude read and add to your list. None of these are on unless you connect them, each is separate. The cloud ChatGPT connection and its revocation timing are described below. What a connected assistant reads is then held under its own provider's privacy policy.
Foley in ChatGPT
The Foley plugin is provided by Hanamori Labs, LLC. When you connect it, you sign in to Foley through Google Firebase and choose permissions on Foley's consent page. Each connection belongs to the Foley account you sign in with. Your Foley password is not given to ChatGPT; the connection uses OAuth access tokens.
Read permission (foley:read) lets ChatGPT request your synced project names,
identifiers, your role and open-task counts, and task identifiers, titles, details,
status, priority and due dates and times. Optional write permission
(foley:write) additionally allows it to create projects and tasks, edit or
complete tasks, and add comments. Tool requests and the values needed for those actions
are sent from ChatGPT to Foley; Foley sends tool results back to ChatGPT.
The connection covers projects that account can access, including shared projects, rather than a separately selected project list. Existing membership and viewer-role restrictions still apply. Archived projects, deleted tasks, and projects kept out of AI context are excluded from these tools. The tools do not retrieve local-only tasks, recordings, attachments, private transcript history or saved rules.
Foley processes these requests through its existing Cloudflare service. OAuth records link your Foley account identifier to the client, permissions, resource, creation and expiry times, and the token information needed to operate and revoke the connection. Changes made through ChatGPT are stored and synced as ordinary Foley project data; disconnecting does not undo them.
Access tokens last five minutes. If you also approve offline_access,
rotating refresh tokens can keep the connection working without another sign-in for
up to 30 days per grant. Without that permission, no refresh token is issued.
Sign in to Foley's connections page to review or revoke a connection. Revocation removes its grant and associated
access-token records, but changes can take time to propagate through Cloudflare's
distributed storage. Access may therefore continue briefly; immediate disconnection
is not guaranteed. The five-minute token lifetime is not a promise that every
revocation has propagated within five minutes. Account deletion also invalidates
earlier grants.
OpenAI receives the Foley data returned to ChatGPT. Its handling and retention depend on your ChatGPT account, settings and applicable terms and privacy policy. Foley's statements about its own model training do not describe OpenAI's practices. Revoking Foley access or deleting your Foley account does not delete information already received by ChatGPT; manage that information with OpenAI separately.
Feedback you send
Feedback from Settings sends the category, title and message you enter, plus the app's platform and version. Your verified email is included for a reply only if you choose. Tasks, transcripts, recordings, logs and saved unsent edits are not attached automatically.
Foley stores the submission and its delivery status on Cloudflare and creates a support ticket in our private GitHub repository. Our support team can read what you submit. Account exports include your submitted feedback, and account deletion waits for confirmed cleanup of the associated feedback records and support tickets.
Payments
On the website, subscriptions are handled by Stripe; on the phone, by the App Store or Google Play. Your card details go to them and never to us - we are told only that a subscription started, renewed or ended. Tax is calculated and collected at checkout where it applies.
On the phone, the store's purchase record reaches us through RevenueCat (RevenueCat, Inc., in the US), which keeps track of which subscription belongs to which account. RevenueCat is given your Foley account identifier and the store's record of the purchase - not your email address, your tasks or anything you said or typed.
How we use your data
- We do not sell your data, and we do not share it with anyone for advertising.
- We use synced content to operate Foley and provide the features you request.
- We do not train any model on what you say.
- There is no advertising or third-party analytics inside the app, and nothing tracks you across other apps or websites. To run the service, Foley keeps a few counts per account: the first day your account used the service, the days you were active, whether you used voice, and on which platform and app version (kept for 90 days), how many AI requests you made on Foley's key each day and what they cost, and your subscription status. These are counts and identifiers only, never your tasks, transcripts or anything you typed or said, and deleting your account deletes them.
- Separately, so that we can help when a capture goes wrong, Foley keeps a support record of each capture for 90 days - which AI model and provider answered it, how long it took and what it cost when it went through our server, and which of Foley's own checks changed the result and how, including the wording before the change - which our support team can read alongside your transcript history, and deleting your account deletes it.
Getting your data out, or deleting it
Account exports include your private transcript history, learned spellings and stored synchronisation receipts, alongside the other account data. Removing a local copy or leaving a shared project does not erase your account's private history.
To remove everything, the phone app has a Delete account button in Settings - it erases every project only you belong to, your account record, your rules, private transcript history, learned spellings and their synchronisation records, and your billing history. A minimal account deletion marker remains to reject delayed uploads from an old device; it contains no transcripts, recordings or rule instructions. The steps are on the deletion page. If you cannot use the app, email hello@foleyapp.com and we will do the same by hand.
Who we are
Foley is made by Hanamori Labs, LLC. Questions about any of this go to hello@foleyapp.com and a person will answer.