Privacy Policy
Last updated: September 1, 2026
Fond ("the app", "we", "us") is operated by Marar Inc. Fond is a personal voice journal: you record voice and text notes, optionally attach photos, and the app transcribes them and organizes the people, places, and moments they mention so you can look back and ask questions. This policy explains what we collect, why, who processes it, and the choices you have. We designed the app to keep your journal private to you.
Information we collect
- Account information — your email address, optional display name, and the identifier from your sign-in provider (Apple or Google) when you use social sign-in. Passwords for email accounts are stored only as a salted PBKDF2 hash, never in plain text. Before you create an account, Fond shows you an example journal that is built into the app itself: it is not your data, it is stored only on your device, and browsing it sends nothing to us. No email, name, or other personal detail is collected until you sign up.
- Your content — the voice recordings, text notes, and photos you create, and the transcripts and derived information produced from them (for example the people, places, activities, and tags the app extracts to build your personal knowledge graph). Recording requires an account — Fond does not capture anything before you create one, so your content is only ever collected after you have agreed to the AI processing described below. Some early users hold older guest sessions, identified only by a random identifier; those sessions can read the notes they already made and attach them to an account, but cannot create new ones.
- Usage analytics — anonymous, behaviour-only product analytics (which actions you take, counts, and durations). We deliberately never send your note content, transcripts, names, search text, or questions to analytics. We do use masked session replay to understand how the app is used. All of your content — your notes and transcripts, the names of people and places in your journal, your photos, and all audio — is masked or blocked on your device before anything leaves it, so your journal content is never visible in a replay; only the app’s own interface (its buttons, menus, and screens) can appear. Replays and analytics events are tied only to an opaque account identifier, not your name or email.
- Crash and error diagnostics — content-free crash and error reports (the app version, the screen or route where a problem happened, and a scrubbed technical error message) so we can find and fix bugs. These never contain your journal content, email, or name.
- Advertising and measurement — to run our own ads (to reach more people who might like Fond), we use Meta's advertising SDK. On iOS it collects your device advertising identifier (IDFA) only if you grant permission when the App Tracking Transparency prompt appears; on Android it uses your advertising ID. We also record a small set of app events — that Fond was installed and opened, that you created an account, started Fond's no-card free access, bought a paid subscription, or made a lifetime purchase — so Meta can measure and optimise our ads. These are counts and amounts only; your recordings, transcripts, names, and search text are never involved. On iOS the app also obtains Apple's AdServices attribution token, Apple's own privacy-preserving way of telling us whether an Apple Search Ads ad led to your install. The app sends that token to Fond's backend, which exchanges it directly with Apple for limited campaign metadata. We do not store or log the raw token; we retain only safe campaign details used to measure installs and subsequent account creation. AdServices contains no advertising identifier, does not track you across other apps, and is not dependent on your App Tracking Transparency choice.
- Install attribution — when a link, ad, or store referral brings you to Fond, we may store which of our own campaigns or ads it was (for example a campaign name or ad identifier from the link, Meta's deferred app link, or Google Play's install referrer) with your account, so we know which of our ads work. This says nothing about your journal — it is only a label for how you arrived.
- Technical data — standard request information (such as device time zone for resolving "today") needed to operate the service.
How we use your information
- To transcribe your recordings and provide the core journaling, search, and "ask" features.
- To extract and organize entities (people, places, activities) and generate summaries, reflections, and answers grounded in your own notes.
- To operate, secure, debug, and improve the service.
- To measure and optimise our own advertising and understand which sources bring people to Fond.
We do not sell your personal information, and we never use your journal content — your recordings, transcripts, notes, names, or searches — to target or serve advertising. We do use Meta's advertising tools to measure and optimise our own ads, as described under "Advertising and measurement" above and "Service providers" below; on iOS Meta measurement happens only with your App Tracking Transparency permission. Apple's separate AdServices measurement does not use the advertising identifier and is not gated by that permission.
Your choice about AI data sharing
Fond cannot turn what you say into a journal without sending it to an AI service, so this is disclosed to you before you ever create or sign in to an account — and before any of your content leaves your device. On iOS, current versions of the app ask for your explicit agreement: the account screens carry a consent checkbox — unchecked until you tick it — whose label states that your recordings and entries are sent and names both recipients, with a “What’s sent?” control that expands the full breakdown of what each one receives. Signing in or creating an account does not proceed until you have checked it, and a device only needs to agree once. On all platforms, this section is that disclosure, and creating an account or signing in is how you give your permission. Until then, Fond only shows you a locally stored example journal and sends nothing anywhere. The disclosure covers:
- Cloudflare Workers AI — voice recordings for speech-to-text, and note text or search terms used to create embeddings for meaning-based search and journal connections.
- Anthropic (Claude) — transcripts, typed notes, questions you ask, relevant journal excerpts, and extracted names or details used to tidy transcripts, organize entries, and generate answers, summaries, reflections, prompts, and portraits.
This processing is how Fond works, so there is no way to keep using it while switching the AI services off. If you would rather not have your journal processed this way, do not create an account — the example journal needs no account and sends nothing. If you have already created one, you can withdraw at any time by deleting your account under Profile → Delete account or at keepfond.com/delete-account, which stops all further transfers and permanently removes your recordings, transcripts, images, and derived entities. Deleting does not undo processing that already happened, and any copies held by the AI services fall away under the retention terms described below.
Service providers who process your data
We share data only with the processors needed to run the app:
- Cloudflare — hosting, storage of your audio and images, the database that holds your notes and knowledge graph, and Workers AI, which performs speech-to-text transcription and generates embeddings used for search and connections. Cloudflare states that Workers AI customer content is not used to train its AI models or improve Cloudflare or third-party services without explicit consent.
- Anthropic (Claude) — receives the journal data described in the AI permission section to extract entities and generate the answers, summaries, reflections, prompts, and portraits you request. Anthropic states that inputs and outputs from its commercial API are not used to train its models by default. Under Anthropic's standard API terms, inputs and outputs are normally deleted from its backend within 30 days, subject to limited safety, legal, or separately agreed exceptions.
- PostHog — anonymous, content-free product analytics, masked session replay, and crash/error diagnostics as described above.
- Apple — processes the AdServices attribution token that Fond's backend sends to Apple and returns limited, privacy-preserving campaign metadata used to measure Apple Search Ads installs and subsequent account creation. Fond does not store or log the raw token.
- RevenueCat — manages your Fond Pro subscription and its entitlement across devices; it processes your subscription status and store transaction data and may separately collect Apple's AdServices attribution information to attribute purchases and subscription performance — never your journal content.
- Resend — delivers our transactional email (your sign-up verification code, password-reset links, and the occasional account email). It receives your email address and the message we send you, never your journal content.
- Meta (Facebook) — our advertising SDK. With your App Tracking Transparency permission on iOS, it receives your advertising identifier and the app events described above so we can measure and optimise our own ads. Your journal content is never shared with Meta.
- Apple and Google (sign-in) — only to verify your identity token when you choose "Sign in with Apple" or Google sign-in.
Our agreements require service providers that receive personal data to use it only to provide their contracted services and to protect it to the same or an equivalent standard as this policy.
Notifications. Fond can send journaling reminders and related notifications. Reminder schedules start enabled for new accounts; the app asks you about notifications when you sign up, and on iOS and recent Android versions the system notification permission is also required before anything can be delivered. To deliver notifications we store a push token for your device, and they travel via Expo's push service and Apple's and Google's notification services. Notification text is deliberately content-free — it never contains your recordings, transcripts, or note text. If you enable "Personal touches", a notification may mention a name from your own journal and can appear on your lock screen. You can decline in the app when asked, and at any time turn off "Personal touches", change reminder times, disable reminders, or pause all notifications under Profile.
Data security and retention
All data is encrypted in transit (HTTPS/TLS). Session tokens are stored on your device in the system keychain and only as a hash on our servers. We retain your account and content until you delete them or delete your account. You can delete an individual note at any time, or delete your entire account and all associated data as described below. Canceling a Fond Pro subscription does not delete anything — your account and content remain available to you until you choose to delete them. Guest notes that are never attached to an account are automatically and permanently deleted after 14 days.
Your rights and choices
- Access & portability — your content is always visible to you in the app. Contact us for an export.
- Deletion — delete your account at any time in the app under Profile → Delete account, which permanently removes your account, recordings, images, transcripts, and derived entities. You can also request deletion on the web at keepfond.com/delete-account.
- Ad tracking — on iOS you can decline the App Tracking Transparency prompt, or change your choice any time in Settings → Privacy & Security → Tracking. If you decline, we do not collect your advertising identifier and Meta cannot use your activity to measure our ads. Apple's separate AdServices measurement does not use an advertising identifier and is not controlled by this setting. On Android you can reset or limit your advertising ID in your device settings.
- AI processing — disclosed on the account screens before anything is sent, and agreed to by creating an account or signing in. Because it is how Fond works, it cannot be switched off separately; withdraw by deleting your account, which stops all further transfers.
- Depending on where you live (for example the EEA, UK, or California) you may have additional rights to access, correct, or restrict processing of your data. Contact us to exercise them.
Children
Fond is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect their data.
International transfers
Our providers may process data in the United States and other countries. We rely on their contractual safeguards for any cross-border transfers.
Changes to this policy
We will update this page and revise the "Last updated" date when this policy changes.
Contact
Questions or privacy requests: Email us.