Privacy policy

What happens to what you say.

Smart Rant may hold some of the most personal things you say all year. This page describes plainly what we store, who processes it, and the controls you have.

Last updated September 19, 2026

The short version

  • Your archive is private to your account. Nothing is social or public.
  • We don't show ads, and we never sell your recordings, transcripts or anything derived from them.
  • Burn recordings are never uploaded and never kept. Private moments are uploaded so you can play them, but are kept out of patterns, threads, insights, Ask and resurfacing, and are transcribed only if you allow that separately.
  • Nothing is uploaded or sent for transcription until you turn on cloud processing. Transcription and analysis then use the OpenAI API, which does not train on API data by default.
  • You can remove cloud audio, turn cloud processing off, export everything, or delete your account.
  • We don't use session replay, and our analytics never include what you said.

What we store

Recordings

When you finish a Normal or Private recording, it is saved on your device first (on iPhone, or in your browser when you record on the web). Only after you have turned on cloud processing is the audio file uploaded to private object storage under your account, never a public bucket. Uploads and playback use short-lived signed links scoped to your account, no other account can reach your files, and the service checks the size and type of every upload. You can remove the cloud audio for any moment while keeping its transcript.

Transcripts and derived information

We store the transcript of each uploaded moment in versions: the original machine transcript, any corrections you make (which create a new version rather than erasing the old one), and a readable view with punctuation and paragraphs added. We also store information derived from it: a title and short preview, labels such as tone, people and topics you mention, threads that connect related moments, and the modules, Ask answers and Relive stories built from your history. We treat derived information as your data, just like the recording itself.

Account and settings

We store an internal account identifier linked to your sign-in, your time zone, preferences (including when you allowed cloud processing), subscription status and monthly usage counts. Your email address and sign-in method (for example Sign in with Apple, Google or an email code) are held by our authentication provider, Clerk, and read when you open Account. Clerk also processes the technical session and security information needed to authenticate and protect accounts, such as IP address, device or browser characteristics and approximate location derived from IP address.

Who processes your content

OpenAI

Only after you turn on cloud processing, and to transcribe recordings and analyze your history (for example connecting threads, composing You modules and answering Ask questions), the relevant audio or text is sent to the OpenAI API. Private moments are sent for transcription only if you separately allow it, and never for analysis. We send only what each step needs: a single recording for transcription, a single transcript for labeling, a bounded set of relevant excerpts when answering a question, and the words of a search of two or more words so Past can find moments by meaning (searches aren't saved to your account), never your whole archive. Our requests set store: false so responses are not stored for later retrieval, and OpenAI does not use API data to train its models by default. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring on text endpoints, as described in OpenAI's API data usage policies.

Infrastructure

Your archive database runs on Neon Postgres in the United States (AWS US East). Audio and exports are kept in private object storage, never in a public bucket. Sign-in is handled by Clerk, which verifies your identity; our service maps that verified sign-in to an internal account and never trusts an account identifier sent by an app or browser. Subscriptions are purchased directly through Apple's App Store using StoreKit. Our service receives Apple-signed transaction and subscription-status information so it can grant the right access; it never receives your card number or other App Store payment details.

Normal, Private and Burn

  • Normal moments are uploaded, transcribed and can become evidence for threads, You modules, Ask answers and Relive stories.
  • Private moments are uploaded so you can play them, and transcribed only if you allow that separately, but they are excluded from semantic indexing, threads, patterns, You modules and Ask. Switching a moment to Private removes it from that intelligence right away.
  • Burn recordings never reach our servers or OpenAI. They are not added to your archive and are not used for your history.

Your controls

  • Cloud processing. Off until you allow it. While it's off, new recordings are not uploaded or sent for transcription or analysis, and features that depend on it pause.
  • Cloud audio. Turn it off to keep audio off our servers, or remove cloud audio from individual moments.
  • Delete a moment. Deleting a moment removes its audio, transcript and every module, answer or story that cited it.
  • Export. Request a JSON export of your data from Account. When it's ready you get a private, time-limited download link.
  • Delete your account. Deleting your account signs you out and starts a cleanup process that removes your recordings, transcripts, derived data, exports and sign-in account. The process is retried until it completes. Copies held by processors, such as OpenAI's abuse-monitoring retention described above, expire on their own schedules.

Analytics, logs and cookies

We use content-free product analytics: event names such as “recording completed” with coarse properties like a duration range. Analytics never include transcripts, audio, your questions, answers, names or thread labels. The events are stored with your account, deleted with it, and never shared or used for advertising. There is no session replay and no third-party advertising or tracking script on this website. Operational logs record identifiers, timing and error categories rather than what you said. One exception: the words of a search travel in the request address, so they can appear in short-lived server request logs. They are not saved to your account either way.

The website uses only the cookies needed to keep you signed in, set by our authentication provider Clerk on the sign-in page and inside your archive. Marketing pages load no third-party scripts. The website does not use advertising or cross-site tracking cookies.

Notifications

Insight notifications are off by default. If enabled, lock-screen text never includes what you said.

Security

Data is encrypted in transit. Every request is checked against your verified sign-in, database access is restricted to your own rows, audio storage is private and scoped to your account, and server credentials never ship to the app or website. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.

Not a medical service

Smart Rant is not therapy and does not diagnose anything. Observations describe what you said in your recordings.

Changes and contact

If we materially change how your content is handled, we'll update this page and tell you in the app before the change applies. See also the Terms.

A support contact address will be published here before Smart Rant launches publicly.