Privacy Policy
Last Updated: September 5, 2026
1. INTRODUCTION
KnowItOwl! ("we," "our," or "the App") is committed to protecting your privacy. This policy explains how we handle your information when you use our Apple Watch and iPhone application.
Our core privacy principle: KnowItOwl! does not ask you to create a profile and does not request your name, email address, phone number, or location. Your questions and audio are sent over HTTPS to the KnowItOwl! API so we can generate answers, transcripts, grounding, and spoken responses. Do not include information in a question that you do not want processed for that purpose. Conversation history and audio saved for cross-device sync are encrypted on your device before being stored in Firebase. We follow security best practices as recommended by Apple and Google.
2. INFORMATION WE COLLECT
Account Information
- KnowItOwl! does not have a sign-in screen and does not request or store your name, email address, phone number, or location
- Apple provides a signed, app-scoped App Transaction. Our backend validates it and derives an opaque identifier used for authentication, cross-device sync, and credit accounting
- The app-scoped identifier is not your Apple ID and cannot be used by us to identify you personally or track you across other apps
Voice Input and Conversations
- When you speak to KnowItOwl!, your voice audio is sent to the KnowItOwl! AI API for transcription, answer generation, and text-to-speech audio generation
- Your typed questions, spoken questions, transcripts, and AI responses are processed only to provide the app experience
- Your questions and the AI responses are stored under your app-scoped identifier to maintain conversation history and enable cross-device sync
- Audio recordings (your voice messages and AI-generated voice responses) are encrypted on your device before being stored under that identifier for playback
Credit and Purchase Information
- Credit balance and transaction history (purchases, free grants, usage) are stored in your account
- We do NOT process or store payment card details — all purchases are handled by Apple through the App Store
Device Information
- Basic device attestation information is used to verify that requests come from legitimate Apple devices (Firebase App Check)
- No personal identifiers, location data, or usage patterns are collected
3. HOW WE USE YOUR INFORMATION
- To provide AI-powered responses to your questions
- To maintain conversation history for contextual, multi-turn dialogue
- To sync your conversations and credits between your Apple Watch and iPhone
- To store and play back audio recordings of conversations
- To manage your credit balance and process free credit grants
What We Do NOT Use Your Data For
- We do NOT use your conversations, audio, or any personal data to train AI models — not ours, not anyone else's
- We do NOT sell, license, or provide your data to data brokers, aggregators, or any third parties for marketing, profiling, or any purpose beyond operating this app
- We do NOT mine your conversations for insights, trends, or analytics
- Your data exists solely to provide you with the KnowItOwl! service. Period.
4. THIRD-PARTY SERVICES
KnowItOwl! AI API and Google AI Services
KnowItOwl! sends your requests to an authenticated API operated by Sandy Brook DevWorks LLC. The API uses Google Cloud Speech-to-Text, Vertex AI Gemini, Google Search grounding when available, and Cloud Text-to-Speech to transcribe audio, generate concise answers, and generate spoken responses. The following data may be processed each time you ask a question:
- Voice audio recordings — the AAC audio captured when you speak a question (voice input only)
- Text messages — the text you type when using text input
- Conversation history — up to 3 recent messages (questions and answers) to maintain context across a conversation
This data is transmitted over HTTPS and is used solely to generate a transcript, answer, and text-to-speech audio output for your request. Your data is not used to train AI models. Google's handling of this data is governed by the Google Privacy Policy and Google Cloud Data Processing Addendum, which provide equivalent data protection to the terms under which Sandy Brook DevWorks LLC operates.
The app obtains your explicit consent before sending AI requests. You may withdraw consent at any time from iPhone Settings > Privacy & Data. Withdrawing consent immediately stops new AI questions on both iPhone and the paired Apple Watch until you allow processing again; it does not delete existing history.
Firebase (Data Infrastructure)
We use Google Firebase services to securely store and sync your data:
- Firebase Auth — provides an authenticated session using a custom token minted after the backend validates Apple's signed App Transaction
- Cloud Firestore — stores your encrypted conversation messages and credit balance
- Firebase Storage — stores encrypted audio recordings for playback
- Cloud Run API — handles AI interactions, identity validation, data deletion, and credit operations through server-side transactions
- Firebase App Check — verifies that requests come from legitimate Apple devices (App Attest on iPhone, DeviceCheck on Apple Watch)
- Privacy-filtered diagnostics — nonfatal operational events may be sent to our authenticated API without conversation text, audio, or personal identifiers; Apple may provide crash and diagnostic reports through TestFlight and App Store services according to your device settings
All Firebase data is stored in Google Cloud infrastructure in a multi-region US deployment (nam5) for high availability (99.999% SLA). Your data is isolated under your authenticated user account and is not accessible to other users.
Apple (Purchases and Settings)
In-app purchases are processed entirely by Apple through the App Store. Apple also supplies the signed, app-scoped App Transaction used to create your session without a login screen. Voice preferences are synced between devices using Apple's iCloud Key-Value Store.
Relevant privacy policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Cloud/Firebase Terms: https://firebase.google.com/terms
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
Important: Your questions, audio, and recent conversation context are processed in real time by the KnowItOwl! AI API and Google AI services to generate responses. This data transmission is necessary for the app to function. No data from any of these services is used by Sandy Brook DevWorks for AI training, marketing, or any purpose beyond operating KnowItOwl!.
5. DATA STORAGE AND RETENTION
Where Your Data Lives
- Your conversation messages, credit balance, ledger records, and audio recordings are stored in Google Firebase (Cloud Firestore and Firebase Storage) under your app-scoped identifier
- Data is stored in Google Cloud infrastructure in a multi-region US deployment for high availability and durability
- Your data is isolated to your account and is not accessible to other users or to Sandy Brook DevWorks staff in the normal course of operations
- Voice preferences are synced via Apple's iCloud Key-Value Store
Data Control
- You can delete individual messages or choose Delete Personal Data in iPhone Settings to erase conversations, stored audio, the profile record, the local encryption key, consent, and the current Firebase Auth user and session
- Credit balances, credit-ledger records, and redeemed StoreKit transaction claims are retained after personal-data deletion. These non-personal commerce records preserve purchased credits and prevent welcome credits or consumable purchases from being granted more than once after deletion or reinstallation
- Because Apple supplies the same app-scoped identity again, the app can automatically create a new session after deletion or reinstallation without asking you to sign in
- Uninstalling the app removes local data from your devices
No Data Harvesting
We want to be unambiguous: your data is never harvested, sold, or shared with data aggregators. It is never used to train AI models. It is never analyzed for advertising or profiling purposes. Your conversations and audio exist in Firebase solely to provide you with the KnowItOwl! service, and for no other reason.
7. ANALYTICS AND TRACKING
- We do NOT use third-party analytics or tracking tools for user behavior or usage patterns
- We do NOT track your behavior or usage patterns
- We use Apple's native crash-reporting pipeline through TestFlight, the App Store, and Xcode Organizer. Availability of those reports follows your Apple device analytics settings
- Nonfatal operational events may be sent to our authenticated API with privacy filtering. They do not include conversation content or audio
- Basic app statistics (downloads, active devices) are provided by Apple and do not identify individual users
- No cookies or tracking pixels are used
8. CHILDREN'S PRIVACY
KnowItOwl! is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
9. YOUR PRIVACY RIGHTS
You have the right to:
- Delete individual messages or use Delete Personal Data to erase conversations, stored audio, profile data, the local encryption key, consent, and your current authentication session
- Withdraw AI-processing consent at any time from iPhone Settings, stopping new AI requests on iPhone and Apple Watch until you consent again
- Retain purchased credits after personal-data deletion; limited commerce records remain to preserve the balance and prevent duplicate grants
- Stop using the app at any time
- Contact us with privacy questions or concerns
10. DATA SECURITY
We follow security best practices as recommended by Apple and Google, implementing defense in depth across every layer of the app:
- All data is transmitted over HTTPS/TLS encrypted connections
- Client-side encryption for saved history — conversation text and audio files saved to your account are encrypted on your device using AES-256-GCM (via Apple CryptoKit) before being stored in Firebase. Firestore and Firebase Storage only store ciphertext. Your encryption key is stored in synchronizable Keychain for use by your Apple devices
- No name or email account — we do not request or store your name, email, phone number, or location. The service uses an opaque identifier derived from Apple's signed, app-scoped App Transaction
- Signed App Transaction validation — the backend validates Apple's signature, application identity, environment, and device binding before minting a Firebase session
- Firebase App Check — verifies that every request originates from a legitimate Apple device using hardware attestation (App Attest on iPhone, DeviceCheck on Apple Watch), preventing unauthorized API access
- Firebase Auth — ensures that only you can access your data through authenticated sessions
- Firestore security rules — enforce that users can only read and write their own data. Credit operations are server-side only and use tamper-resistant validation
- Firebase Storage security rules — restrict audio file access to the owning user, with a 5MB file size limit and content type validation
- User-scoped encryption keys — encryption keys are scoped to your user account, preventing cross-user key sharing on shared devices
- Structured logging with privacy annotations — all diagnostic logs use Apple's os.Logger framework with
privacy: .privateannotations, ensuring sensitive data (balances, transaction IDs) is redacted in release builds - No AI-provider API keys are stored on or distributed to client devices; AI requests pass through the authenticated Sandy Brook DevWorks API
Encrypted Storage
Conversation messages and audio files saved to your account are encrypted on your device using AES-256-GCM (via Apple CryptoKit) before being stored in Firebase. The user-scoped key is stored in synchronizable Keychain so your devices can decrypt shared history. AI requests must be processed in readable form by the KnowItOwl! API and Google Cloud services to generate responses, transcripts, grounding, and audio.
11. INTERNATIONAL DATA TRANSFERS
AI service providers may process data in countries outside your residence. By using KnowItOwl!, you consent to this transfer and processing.
12. CHANGES TO THIS POLICY
We may update this privacy policy from time to time. We will notify you of significant changes by:
- Posting the new policy at sandybrook.io/apps/knowitowl/privacy.html
- Updating the "Last Updated" date
- (Optional) In-app notification for material changes
Continued use of the app after changes constitutes acceptance of the updated policy.
13. CALIFORNIA PRIVACY RIGHTS
California residents: We do not sell personal information. We do not share personal information for cross-context behavioral advertising. You have rights under CCPA/CPRA to:
- Request information about data we collect about you
- Delete your conversation data directly within the app
- Not be discriminated against for exercising your privacy rights
To exercise these rights, contact us at hello@sandybrook.io.
14. CONTACT US
If you have questions about this privacy policy or our privacy practices:
Email: hello@sandybrook.io
Sandy Brook DevWorks LLC
5900 Balcones Drive Ste 100
Austin, TX 78731
United States