Koemi

privacy policy

What we know, and what we never keep.

Last updated July 17, 2026

Working draft. Koemi is in heavy beta and this document is still under legal review; the reviewed version will replace this page before wide launch.

The short version

  • Nothing you say is stored. Conversations are never written down on our side: no transcripts, no replies, no audio recordings.
  • The conversation lives only in the app's memory while you talk. Quitting ends the session; nothing is written down, on our side or yours.
  • What we do keep is a small set of operating records: your account, and numbers with no words in them (timings, token counts, costs, errors).
  • The service is hosted in the EU. We run no ads, sell no data, and do not train models on your conversations.

1. Who is responsible

The data controller is the operator of koemi.ai, the service's sole developer, reachable at support@koemi.ai. While Koemi is a free beta the operator's full legal identity is not published here; it is held by the hosting provider (see the legal notice) and will be published before the service takes any payment. There is no data protection officer; at this scale the operator handles requests personally.

2. What we process, why, and for how long

WhatWhyLegal basisKept
AccountYour email, a hashed password (argon2), your role, and your monthly usage allowance: what running your account requires.Contract (the tester agreement)Until you delete your account
Sign-in sessionsA hashed session token so you stay signed in.Contract30 days, expired rows purged
Social sign-in linksIf you sign in with Google or Discord: the provider's stable user id and the email it confirmed, so the same account opens next time.ContractUntil you delete your account
Access requestsThe old waitlist form is gone; sign-up is open. Emails given on it remain only until their scheduled erasure.Steps prior to a contract, at your requestEmail erased 180 days after a decision
Usage telemetryPer-turn timings, token counts, provider cost, and error events. Numbers only, never words.Legitimate interest (service health)90 days (turn detail), 180 days (session records), 400 days (usage accounting)
Visitor countingA per-day, per-page tally. Your IP address is hashed with a salt that changes every day, so one day can never be linked to the next, and the raw IP never reaches the database.Legitimate interest (audience measurement)400 days, as daily counts
FeedbackBug reports you write in Settings, with a snapshot of your app configuration.Legitimate interest (support)365 days, deleted outright with your account
Abuse throttlingRecent request counts per IP for the sign-in and sign-up forms, held in memory only, never written to the database.Legitimate interest (abuse prevention)Minutes to one hour

3. What is never stored

The conversation itself. What you say is transcribed and answered in transit: the audio clip is discarded after transcription, the session's conversation history lives in memory and dies when the session ends, and no transcript, reply, audio, or embedding is ever written to our database. Because the record does not exist, it cannot be leaked, sold, subpoenaed from us, or trained on.

The apps keep nothing either: the session's conversation is held in the app's memory while you talk and is gone when you quit. Nothing conversational is written to your disk, and every session starts fresh.

4. Your voice

The microphone streams audio while you talk to her. Speech detection runs on our server; when you finish a sentence, the utterance clip goes to a speech-to-text provider, comes back as text, and the clip is discarded. Your voice is not stored, and it is never used to identify you: there is no voice fingerprinting and no biometric processing.

5. Who processes data for us

A small set of providers process data on our instructions:

ProviderRoleWhat reaches themWhere
Hetzner Online GmbHHostingEverything above, at restGermany (EU)
OpenRouterAI replies and speech to textConversation text and utterance audio clips, in transitUnited States
RunPodGPU compute when Dara's dedicated model is liveConversation text, in transitUnited States
ResendTransactional emailBug-report notices to the operator's own inbox: your email address and the report textUnited States
GoogleSign-in, only if you choose itWhen you sign in with Google, it confirms your identity and email address to us. Nothing conversational.United States
DiscordSign-in, only if you choose itWhen you sign in with Discord, it confirms your identity and email address to us. Nothing conversational.United States

Conversation content transits these providers only long enough to produce the reply and is not stored by us. AI requests ride our OpenRouter account with zero data retention enforced: what you say and what she answers are routed only to model endpoints that do not log or store them. Where a provider is outside the EU, we rely on the safeguards GDPR provides for international transfers; the per-provider agreements are being confirmed and this section will name them precisely.

6. Your rights

GDPR gives you the right to access the data we hold about you, to correct it, to delete it, to restrict or object to its processing, and to receive a copy of it in a portable format. Write to support@koemi.ai and we will answer within a month; we may ask you to confirm you control the account's email address first.

One honest limit: the conversation itself cannot be exported or corrected, because it does not exist on our side.

If you believe we mishandle your data, you can complain to the French supervisory authority, the CNIL (cnil.fr), or to the authority of your own country.

7. Deleting your account

Ask by email today; a self-serve button is planned. Deletion anonymises your account row in place (the email is replaced, the password hash is cleared), deletes your feedback outright, deletes any Google or Discord sign-in link, revokes your sessions, and disconnects the live app. Remaining telemetry rows carry an identifier that no longer resolves to anyone.

8. Children

Koemi is not for children and does not target them. You must be at least 15 years old to use it.

9. Security

Passwords are hashed with argon2id and never stored in clear. Sessions ride an HttpOnly, Secure cookie. Sign-in, sign-up and the social sign-in callback are rate limited per IP. Raw IP addresses never reach the database. Transport is encrypted. No system is perfect; if a breach ever affects your data, we will notify you and the CNIL as the law requires.

10. Changes

When this policy changes materially, we will say so in the app or by email before the change takes effect, and this page always carries its date.