This policy explains what we collect when you use the RealityPal Android app, the RealityPal web app at https://dev.realitypal.ai, and their related services (the “Service”), how we use it, who we share it with, how long we keep it, and your choices.
1. Summary
- We collect what we need to run your account and your chats with your AI companions (“Pals”). That includes your account details, your conversations, and your subscription status.
- Your messages go to an AI model hosted by Amazon Web Services (Amazon Bedrock) to generate replies. Your Pal’s replies can be turned into speech by ElevenLabs.
- If you speak to a Pal using the microphone button, your device’s speech recognition service turns your voice into text. We never receive or store your voice recordings, only the resulting text message you choose to send.
- Optional wake words (“Hey Aria” / “Hey Mina”, Android, off by default): the app listens for them on your phone only. That audio isn’t recorded, stored or sent to us; what you say after the wake word is handled like any voice message.
- If you send a photo or short clip, it goes to our backend and Amazon Bedrock so your Pal can reply to it, and it is stored for 30 days.
- Optional face greeting and face recognition run entirely on your phone. Face templates are biometric data: they are computed and stored only on your device, encrypted, never uploaded, and only with your explicit consent.
- If you connect your own AI agent, Hermes or OpenClaw (optional, higher plans), your phone talks to it directly over your own private network. We never see its address, key or tokens, but the tasks your Pal hands to your agent and the results it sends back pass through our backend and Amazon Bedrock and are kept in your chat history.
- Your Pal can send you notifications: reminders you ask for, steps of routines you set up, a morning briefing and evening recap, and (only if you turn it on) messages when you’ve been away. To deliver them we store your phone’s push token and use Google Firebase Cloud Messaging. Notifications sent through Google carry only identifiers and your Pal’s name, never your messages; the app fetches the message from us directly.
- If you turn on calendar access (optional, off by default), your phone reads your calendar when you ask about your schedule, or for your morning briefing, and sends the event details it finds to our backend and Amazon Bedrock. Events are only added after you confirm on screen. We never connect to your calendar account ourselves.
- In Translator mode (higher plans), what you and the person you’re talking to say is turned into text by your phone, translated by Amazon Bedrock or Amazon Translate, and spoken by ElevenLabs. None of it is stored. The other person sees an on-screen notice, in their language, that the conversation is being translated by an app.
- In optional hands-free translation (Pro and above), the app listens continuously while it’s on, and your voice and the other person’s voice are streamed to Amazon Transcribe to be turned into text. We don’t store the audio. The other person sees a notice that the app is listening to translate the conversation.
- Optional texting (Android, off by default): when you ask your Pal to text someone, the app looks them up in your phone’s contacts on your phone and shows you the exact message first; nothing is sent until you tap Send. Your contact list is never uploaded; we only receive the name you used and whether the text went through.
- Optional Discord: if you link your Discord account, your Pal can chat with you in Discord DMs and in servers you add her to. Server conversations are kept as a separate, encrypted server memory for up to 90 days; your private app chats and memories are never used in servers. In voice channels, speech is turned into text to reply.
- The web app stores your sign-in session and two small preferences in your browser. It uses the camera or microphone only when you click the matching button, and it has no analytics, advertising or tracking cookies (see 2.4).
- Your Pal has a long-term memory: she keeps facts about you and short summaries of past chats, learned automatically after a chat goes quiet or when you ask her to remember something. Memories are encrypted with your personal key, and you can view, edit, delete or pause them in the app. Sensitive topics aren’t stored automatically unless you allow it, and she never stores passwords or card numbers (see Memories in 2.1).
- Your data is encrypted in transit and at rest, with a separate encryption key for each user. It is not end-to-end encrypted: our servers and the providers that generate replies, voice and translations (Amazon Bedrock, ElevenLabs, Amazon Transcribe and Amazon Translate) process your content while handling a request (see section 8).
- Authorized Reality AI staff can see your account details (such as your username, email, plan and usage counts) for support, billing and abuse prevention. They can’t read your conversations or memories, and their access is logged. If you report a message, a copy of it and your comments are shared with our moderation team, and if you contact support, our support staff can read your request (see 4.1).
- We don’t sell your personal information, and we don’t show ads.
- You can delete your account and data in the app at any time. Deleting your account destroys your encryption key immediately.
- The Service is for adults (18+) and is not directed at children.
2. Information we collect
2.1 Information you give us
| Data | Details |
|---|---|
| Account information | Username, email address, password, and optional display name. Your password is handled by Amazon Cognito; we never see or store it in plain text. |
| Google sign-in information | If you choose “Continue with Google”, Google shares your name, email address, email verification status and a Google account identifier (the openid, email and profile scopes). |
| Conversations | The messages you send to Pals, whether typed or spoken, and the AI-generated replies. |
| Memories | So your Pal can remember you across conversations, we keep facts about you and short summaries of past conversations derived from your chats (for example “Has a dog called Pixel”, or that you were nervous about a job interview), plus things you ask her to remember. Facts are shared by all your Pals; a conversation summary belongs to the Pal you talked with. How: things you ask her to remember are saved right away. Other memories are created automatically after a chat goes quiet: the conversation is processed by our AI providers (Amazon Bedrock) under the same terms as chat, to pick out what’s worth remembering and to create a numeric representation of each memory (an embedding) used to find the relevant ones later. Protection: memories and their embeddings are encrypted with your personal encryption key, and our staff can’t read them. Your control: you can view, edit and delete memories, pause memory, or forget everything in the app (What she remembers). They’re deleted with your account, and deleting a chat removes the summaries from it (and, if you choose, what she learned in it). Voice calls (Pro and Pro+): during a call your microphone is used only while the call screen is open. Your voice is streamed directly from your device to Amazon Transcribe to turn it into text; the audio is not stored by us or kept by Amazon Transcribe. What you and your Pal say on the call is saved in your chat like normal messages, and the call time counts towards your monthly minutes. Your own Pals (Pro and Pro+): if you create a Pal, the name, personality and other details you write are encrypted with your personal key and only used for your chats with that Pal. Before they’re saved, they’re checked by Amazon Bedrock to keep Pals suitable for everyone. Deleting a Pal deletes its chats, and your Pals are deleted with your account. Follow-ups (Pro and Pro+): when you mention something coming up, like an interview or a trip, your Pal may remember it with its date so she can ask how it went afterwards (as one of her proactive messages, only if you’ve turned those on). Follow-ups are encrypted like other memories, shown under Coming up where you can delete them, and removed once she’s asked. Memory book (Pro and Pro+): at the start of each month your Pal writes you a letter about the month before, created by Amazon Bedrock from that month’s memories (never sensitive ones, and none while memory is paused). The letter and the highlights it used are encrypted with your personal key; you can read, save as PDF or delete each one in the app, and they’re deleted with your account. Sensitive topics: details about your health, sexuality, religion, political views, ethnicity or trade-union membership are not stored automatically unless you turn on Sensitive topics; otherwise she stores them only when you explicitly ask her to remember them. She never stores passwords, PINs, card, bank or ID numbers or one-time codes, even if you ask. |
| Voice input (optional) | When you tap the microphone button, the app uses your device’s speech recognition service (on most Android phones, Google’s speech services) to turn what you say into text, which appears in the message box for you to review. The microphone is only on while the button shows it is listening. Audio is processed by that service under its own privacy terms; it is not sent to or stored by Reality AI. Only the text you choose to send is transmitted to us, and it is treated like any typed message. Microphone access is optional and can be turned off at any time in Android Settings → Apps → RealityPal → Permissions. |
| Wake words (optional, off by default, Standard and above, Android) | When you turn on wake words, the app listens with your phone’s microphone for “Hey Aria” and “Hey Mina” so you can talk to a Pal hands-free, including when your phone is locked. This audio is processed only on your device: it is kept in memory for a few seconds to detect the phrase and is not recorded, stored or sent to us or anyone else. A notification and Android’s microphone indicator are shown while it listens, and it pauses during calls and when another app uses the microphone. After the wake word, what you say is handled like any voice message (turned into text by your device’s speech recognition service, see Voice input). You can pause it or turn it off at any time. |
| Reports | If you report an AI reply: the reason, any comments you add, and a copy of the reported reply and its identifiers. The copy and your comments are shared with our moderation team (see 4.1). |
| Texting (optional, off by default, Android) | When you turn on texting and ask your Pal to text someone, the app searches your phone’s contacts on your phone for the name you used and shows a confirmation card with the recipient and the exact message. Your contacts are never uploaded. We receive the name you used, the message text (as part of your conversation) and whether the text was sent; the phone number stays on your phone. Nothing is sent without your tap. |
| Discord (optional) | If you link a Discord account: your Discord user ID, the servers where you host your Pal, messages you and others send her there (and, in servers that turn on ambient mode, recent channel messages), display names and @tags of people in those conversations, and daily summaries of server conversations. In voice channels, speech is sent to a speech-to-text provider to reply and is not stored as audio. Server data is encrypted with the host’s key and deleted after at most 90 days, or sooner with /pal forget, /pal forget-me, unlinking or deleting your account. |
| Support requests | If you contact support in the app or web app (Settings → Contact support): the category, subject and message you write, a reference code (e.g. RP-7K3Q9X), your account identifiers (user ID and username) and your plan, and the request’s status. Optional device info (app version, platform, operating system version, device model or browser, and language setting) is shown to you before you send and can be switched off. We use it only to answer your request and fix problems. Our support staff can read your request (see 4.1). If you email us, we may add your email to your account’s support history in the same way. |
| Photos and clips (optional) | When you choose to show your Pal something (camera, voice command or gallery), the photo or 2–4 still frames of a clip, plus any caption, are sent to our backend and to Amazon Bedrock to generate the reply, and stored in Amazon S3 so they appear in your chat history. The camera only captures when you ask and turns off right after. Images may show you, other people or your surroundings; please only send images of people who are happy for you to do so. |
| Face greeting events (optional, off by default) | If you turn on Let her notice when you’re here, the front camera runs at low resolution only while a chat is open and the app is on screen, and a face detector on your phone notices when someone sits down. No image leaves the device. We only receive a short event (“someone appeared”, whether they were recognised, and the display name if your phone recognised an enrolled person), which counts as one message and is stored with your conversation like any message. |
| Hermes and OpenClaw tasks and results (optional) | If you connect a Hermes or OpenClaw agent that you run on your own computer, your Pal may write a short task for it (for example “check my calendar for tomorrow”). Your phone sends the task to your agent over your own network (e.g. Tailscale) and sends the result back to us so your Pal can reply. We receive and store the task text, the result (shortened to about 4,000 characters), its status and which agent was used with your conversation, plus the optional short descriptions you give each agent (“What should your Pal use it for?”). Your agent’s address and credentials (the Hermes API key; the OpenClaw gateway token, device key and device token) stay on your phone and are never sent to us. Whatever your agent does on your computer, and the services it connects to, are under your control and those services’ own terms. |
| Reminders (optional) | When you ask your Pal to remind you of something: what to remind you about, when (in your local time), whether it repeats, and the short message she will send you at that time. |
| Routines (optional) | Routines you set up in the app or in chat: routine names, days, steps (title, time, optional duration and note), follow-up and pause settings, and the short messages your Pal pre-writes for each step. Also your routine history: whether you marked each step done, snoozed, skipped or missed it, and your streaks. |
| Calendar events (optional, off by default) | If you turn on Calendar access and grant Android’s calendar permission, the app reads events from your phone’s calendar only (a) when your Pal needs them to answer you (for example “what’s on tomorrow?”) and (b) at the time of your morning briefing. It sends us the event titles, times, locations and notes for the requested days (at most 50 events). When you ask her to add an event, the details are shown on screen and only added to your calendar after you tap Add. We never access your Google account or calendar servers directly; your phone’s calendar app syncs any added event. You can turn calendar access off at any time in Settings or in Android Settings → Apps → RealityPal → Permissions. |
| Translator mode (optional, Advanced and above) | When you use the Translator screen for a face-to-face conversation, you and the other person each hold a talk button. Your phone’s speech recognition service (see Voice input) turns what each of you says into text on the phone; the phone sends us that text, the two languages, and up to the 6 most recent lines of the session for context. We translate it with Amazon Bedrock (or Amazon Translate if Bedrock is slow or unavailable) and, if you choose, turn the translation into speech in your Pal’s voice with ElevenLabs. The translation and the voice clip are returned straight to your phone. We don’t store the text, the context lines, the translation or the audio, and the session log on your phone is cleared when you leave the screen. Our service logs record only the languages, sizes and timings, never the words. This includes the other person’s speech: while they are talking to you, their words are processed the same way, and their half of the screen shows a notice in their language: “This conversation is being translated by an app.” Please only use Translator mode with people who are happy to be translated. Translations have their own daily fair-use limit, and each spoken clip counts toward your monthly voice allowance. |
| Hands-free translation (optional, Pro and above) | If you turn on Hands-free on the Translator screen, the app listens continuously with the phone’s microphone until you pause it or leave the screen, so you don’t need to press buttons. While it listens, the voice audio of you and the person you’re talking to is streamed directly from your phone to Amazon Transcribe (an AWS service we use as our processor) to be turned into text and to detect which language is being spoken. The audio doesn’t pass through or get stored on our servers, and we don’t store the audio. To save listening time, the app only sends audio while someone is speaking, and it ignores the moments when it plays a translation on the speaker. The resulting text is translated exactly as in Translator mode (not stored). The other person’s half of the screen shows, in their language: “This app is listening to translate this conversation.” We count hands-free listening time to apply your plan’s monthly hands-free allowance. Please only use hands-free mode with people who are happy to be listened to and translated. |
| Notification and routine settings | Your quiet hours, whether proactive messages, the morning briefing and the evening recap are on, and their times. |
| Names of recognised people (optional) | If on-device face recognition is on and recognises an enrolled person in a photo you send, the photo request includes that person’s display name (up to 5 names). We never receive face templates or any biometric data. |
2.1a Face recognition (biometric data): processed only on your device
Face recognition is optional, off by default, and requires your explicit consent in the app (Settings → Faces). With consent:
- What is created: for each person you enrol (up to 10), the app computes a numeric face template (a list of numbers derived from 3–5 camera frames) using a model that runs on your phone. You give each person a display name.
- Where it is kept: only on your device, in app-private storage, encrypted with a key held in the Android Keystore. It is excluded from Android backups and device-to-device transfer.
- What is never done: face templates, face images and crops are never uploaded to Reality AI or anyone else, never logged, never sold, leased, traded or otherwise disclosed, and no enrolment photos are kept. Reality AI never receives, stores or has access to biometric identifiers or biometric information.
- Purpose: solely to recognise enrolled people inside the app (greeting you by name and telling your Pal who is in photos you send).
- Others: you may only enrol another person after confirming they have agreed.
- Deleting it: delete one person (Settings → Faces → Delete) or withdraw consent (Settings → Faces → Turn off & delete all), which deletes every template and the encryption key. All face data is also deleted when you sign out, when you delete your account, and when you uninstall the app.
Biometric data notice and retention schedule (e.g. Illinois BIPA, Texas CUBI, Washington): face templates are retained on your device only until the first of: (a) you delete that person or withdraw consent, (b) you sign out, (c) you delete your account, (d) you uninstall the app, or (e) the purpose of recognising enrolled people has been satisfied, and in any case no longer than 3 years after your last use of the app. Because the templates never leave your device, Reality AI holds no biometric data to retain or destroy on its servers.
2.2 Information collected automatically
| Data | Details |
|---|---|
| Time zone | Your device’s time-zone name (e.g. Europe/London). It’s used to reset your daily allowance at local midnight, to let your Pal know your local time of day and how long it’s been since your last message, and to send reminders, routine steps, briefings and recaps at the right local time. We don’t collect GPS or precise location. |
| Push notification token | A token issued by Google Firebase Cloud Messaging that lets us send notifications to your phone. It identifies the app installation, not you personally. We delete it when you sign out or delete your account, and when Google tells us it’s no longer valid. |
| Usage counters | How many messages you’ve sent each day, and how many voice replies and hands-free translation minutes you’ve used each month. |
| Voice replies | Audio files (MP3) of your Pal’s replies that we generate for you. |
| Technical logs | Service logs and traces for security, debugging and abuse prevention. They can include your internal user ID, request metadata such as the IP address and request time, and error details. Our API keeps access logs (your IP address, your internal user ID, the type of request, its status and timing, never message content) for security and abuse prevention; they are deleted after 30 days. |
2.3 Purchase information
When you subscribe through Google Play, Google processes your payment. We don’t receive your card details. We do receive and store:
- the product and plan, the purchase token, and the subscription state and expiry,
- whether it’s a trial, and whether it auto-renews,
- an obfuscated account identifier (a one-way hash of your account ID) that links the purchase to your account.
2.4 Web app (browser)
The web app lets you create an account or sign in from a computer’s browser. It uses the same account and handles your conversations, photos and voice replies exactly as described above. In addition:
| Data | Details |
|---|---|
| Browser storage | Your sign-in session (Amazon Cognito tokens, stored by the AWS Amplify library in your browser’s local storage so you stay signed in, plus temporary values used during Google sign-in) and two small preferences: whether voice replies are on, and the day you last saw the “Lite mode” notice. They stay in your browser until you sign out (which removes the session) or clear your browser data. |
| Camera (optional) | Only when you click the webcam button to take a photo. Your browser asks for permission first, the camera turns off when the dialog closes, and only the snapshot you choose to send is uploaded. It is then handled like any photo (section 2.1). |
| Microphone (optional) | Only while you use the microphone button. Speech is turned into text by your browser’s own speech recognition service (for example, Google’s in Chrome or Microsoft’s in Edge), under that provider’s terms. We receive only the text you choose to send. |
| Photos and voice replies | As in the app: photos you send are stored for 30 days, and voice replies are generated for you and delivered through short-lived links. |
| Web hosting logs | Our content delivery network (Amazon CloudFront) processes your IP address and request details to deliver the site and protect it from abuse. We don’t enable CloudFront access logging, so we don’t keep web server access logs for the web app or this website beyond AWS’s standard operational handling. (Requests the web app makes to our API are covered by the API access logs described in section 2.2.) |
The web app does not use analytics, advertising or tracking cookies, and it doesn’t load third-party scripts. It doesn’t offer purchases (subscriptions are bought in the Android app through Google Play) or push notifications.
This website (https://www.realitypal.ai) is delivered the same way. It sets no cookies and loads no analytics, advertising or third-party scripts.
3. How we use your information
- To provide the Service: creating and securing your account, generating your Pal’s replies and voice, saving and showing your conversation history, and letting your Pal remember you across conversations (memories).
- To manage subscriptions: checking purchases with Google Play, applying your plan’s allowances (daily and monthly), and handling renewals, cancellations and refunds.
- Notifications you asked for: sending reminders, routine steps and follow-ups, your morning briefing and evening recap, and (if you turned them on) messages from your Pal when you’ve been away. Follow-ups and away messages are never sent during your quiet hours.
- Calendar and routine help: answering questions about your schedule, adding events you confirm, and summarising your day and routine progress.
- Safety and abuse prevention: rate limiting, detecting unusual usage, and reviewing reported content.
- Enforcing our Terms: if an account breaks our Terms of Service, we may suspend or ban it. If we ban an account, we keep a one-way, keyed hash of its email address (not the address itself) so the same email can’t be used to sign up again, even after the account is deleted. You can contact support@realitypal.ai to appeal.
- Support and communication: verification codes, password resets, and answering your support requests (including investigating and fixing the problems you tell us about).
- Improving reliability: monitoring errors and performance.
- Aggregated statistics: we use aggregated, de-identified statistics (counts, such as how many people signed up, how many are on each plan, or how many messages were sent each day) to run and improve the Service. They don’t identify you.
We do not use your conversations to train AI models. Amazon Bedrock, which generates your Pal’s replies, doesn’t use your messages or its replies to train the underlying models and doesn’t share them with model providers.
4. Who we share information with
We share information only with service providers (processors) that help us run the Service, under contracts that limit their use of it:
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (incl. Amazon Cognito, Amazon Bedrock, Amazon Translate, Amazon Transcribe, DynamoDB, S3, Lambda, CloudWatch, Secrets Manager) | Hosting, authentication, AI reply generation, translation, speech-to-text for hands-free translation, storage, logging | All data in section 2 except on-device face data. Your messages, conversation context and any photos/clip frames you send are processed by Amazon Bedrock (Anthropic Claude model) to generate replies; photos are stored in Amazon S3. After a chat goes quiet, it is processed by Amazon Bedrock (Anthropic Claude, and Amazon Titan embeddings) to create and update your memories. In Translator mode, the text to translate and its recent context lines are processed by Amazon Bedrock, or by Amazon Translate as a fallback (and to translate the on-screen notice), and are not stored. In hands-free translation, the voice audio of you and the other person is streamed to Amazon Transcribe for transcription and language detection, and is not stored by us. |
| ElevenLabs | Text-to-speech for voice replies (paid plans), for reminders, routine messages, check-ins, briefings and recaps when you choose to have them spoken or receive them as voice notes (Pro and Pro+), and for spoken translations in Translator mode | The text of your Pal’s message being voiced, or in Translator mode the translated sentence (which may be your words or the other person’s, translated). Otherwise your own messages aren’t sent. |
| Discord | Delivering your Pal’s messages and voice in Discord, if you link your account | Messages and voice exchanged with your Pal in Discord DMs and servers, handled under Discord’s privacy policy. Voice in voice channels is turned into text by a speech-to-text provider (ElevenLabs or Amazon Transcribe) and not stored as audio. |
| Google (Google Play, Google Play Billing, Google Sign-In, Firebase Cloud Messaging) | App distribution, payments and subscription status, optional sign-in, delivering notifications | Purchase data; Google account profile if you use Google sign-in; your push token and the notification identifiers (your Pal’s name, a mood tag and message IDs). No message text, preview, reminder or routine wording is sent through Google; the app fetches the message from us over an encrypted connection. |
We may also disclose information:
- if the law requires it,
- to protect rights, safety and the integrity of the Service,
- as part of a business transfer (e.g. a merger), with notice to you.
We do not sell personal information and do not share it for cross-context behavioral advertising.
4.1 Access by our team
Only authorized Reality AI staff can use our internal support tools, and they must sign in with two-step verification.
- Reported messages: when you report a message, a copy of that message and any comments you add are shared with our moderation team so they can review it. They’re stored encrypted with a separate moderation key (not your personal key), only authorized staff can open them, and every time a report is viewed it’s logged. Reports are deleted when you delete your account.
- Account details: authorized staff can see your account details (username, email address, plan, usage counts and sign-in status) when needed for support, billing and abuse prevention. They cannot read your conversations or your memories: our staff tools have no access to the personal encryption key that protects them, and no access to memories at all. Every time staff look up an account, it’s logged.
- Support requests: when you contact support, our support staff can read your request (subject, message, category and any device info you chose to include) so they can answer it. We reply by email from support@realitypal.ai. Requests are stored encrypted with the moderation key (not your personal key), every time a request is opened it’s logged, and staff’s internal notes on it are never shown to you.
5. Where your data is processed
Our backend is hosted by AWS in the United States (us-east-1, N. Virginia). ElevenLabs and Google may process data in other countries.
The Service is currently offered only in the United States, and this policy is written for users in the United States.
6. How long we keep information
| Data | Retention |
|---|---|
| Account profile (username, email, display name, time zone) | Until you delete your account |
| Conversations and messages | Until you delete the conversation or your account. When you delete a conversation it disappears from your list at once, and its messages, photos and voice replies are deleted shortly after (within 30 days at most) |
| Memories (facts about you and summaries of past conversations) | Until you delete them (one by one, or with Forget everything) or your account. Deleting a conversation also deletes the summaries created from it, and, if you choose, the facts learned from it. Pausing memory keeps what’s stored. There’s no time limit, but if a very large number build up, the least important automatically created memories are removed first (never the ones you asked her to remember) |
| Voice reply audio files | Deleted automatically 30 days after creation, or sooner if you delete your account |
| Your voice (microphone input) | Not received or retained by us. Only the transcribed text you send is stored, as part of your conversations |
| Hands-free translation audio (your voice and the other person’s) | Not stored. Streamed from your phone to Amazon Transcribe only to transcribe it, then discarded by us. We keep only the monthly listening-time counter (deleted automatically about 70 days after the month ends) and short-lived session and block records without content (about 8 days) |
| Photos and clip frames you send | Deleted automatically from S3 30 days after they are sent, or sooner if you delete your account. The message itself (caption, “photo” marker, image count) stays in your history until you delete your account |
| Hermes and OpenClaw tasks and results | Stored with your Pal’s reply in your conversation until you delete your account. Outstanding (unanswered) agent requests are deleted automatically after about 15 minutes, or when you delete your account |
| Face greeting events | Stored as a message in your conversation until you delete your account. The camera frames are never stored or sent |
| Translator mode (your words, the other person’s words, context lines, translations, spoken clips) | Not stored. Processed only to answer each request and then discarded. The session log on your phone is cleared when you leave the Translator screen. Only the daily usage counters are updated |
| Reminders | Active reminders until they fire (one-off) or you cancel them (repeating). Finished or cancelled reminders are deleted automatically about 30 days later. The message she sent when it fired stays in your conversation until you delete your account |
| Routines | Until you delete the routine or your account |
| Routine history (done / snoozed / skipped / missed, streak inputs) | Deleted automatically 90 days after the day it relates to, or sooner if you delete your account. Current and best streak counts are kept with the routine |
| Calendar event details | Events your Pal reads to answer you: kept with her reply in your conversation until you delete your account. Events sent for a morning briefing: kept with that day’s routine record for 90 days. Events you add live in your phone’s calendar, under your control |
| Proactive messages, reminders, routine messages, briefings and recaps sent to you | Stored as messages in your conversation until you delete your account |
| Push notification token | Until you sign out, delete your account, or Google reports it invalid |
| Notification and routine settings (quiet hours, briefing/recap times) | Until you change them or delete your account |
| Face templates (biometric, on device only) | Never received by us. On your device until you delete the person, withdraw consent, sign out, delete your account or uninstall the app (see 2.1a) |
| Texting (contacts, phone numbers) | Never received by us. Only the recipient name you used and the outcome are stored with your conversation |
| Discord server conversations and summaries | Deleted automatically after at most 90 days, or sooner with /pal forget, /pal forget-me, unlinking Discord or deleting your account |
| Usage counters | Daily counters are deleted automatically about 8 days after the day ends; monthly counters (voice, hands-free minutes) about 70 days after the month ends |
| Subscription/entitlement records | Until you delete your account. Google keeps its own purchase records under its policies, and we may keep only minimal transaction records required for tax/accounting for up to 7 years. |
| Content reports (the reason, your comments and the copy of the reported message) | Kept for safety review until you delete your account (reports are deleted with the account) |
| Support requests (subject, message, category, device info, reference, status and staff notes) | Deleted automatically 1 year after the request is resolved (reopening it restarts this), or when you delete your account, whichever comes first |
| Banned email hash (only if we ban an account for breaking our Terms) | A one-way, keyed hash of the email address (not the address itself), kept even after the account is deleted so the email can’t be used to sign up again. It’s removed if we lift the ban, for example after a successful appeal to support@realitypal.ai |
| Records of staff access (which staff member looked up or acted on an account or report, and when; never message content) | Kept for security and accountability for as long as needed for that purpose |
| Aggregated statistics (counts that don’t identify you) | Kept for as long as they’re useful for running and improving the Service |
| Service logs, including API access logs (IP address and user ID) | 30 days |
| Backups | Production databases have point-in-time recovery. Deleted data can stay in backups for up to 35 days before it’s overwritten. Your conversation content in those backups is encrypted with your personal key, which is destroyed (and not backed up) when you delete your account, so it can no longer be read. |
7. Your choices and rights
- Delete your account in the app: Settings → Delete account. This permanently deletes your profile, conversations, messages, memories, photos, voice audio, reminders, routines and routine history, content reports, support requests, usage records, subscription records, your push token and your sign-in account, and deletes all face data from your device. Your personal encryption key and your sign-in account are destroyed immediately, which makes your stored content unreadable at once; the remaining records and files are then removed automatically in the background, usually within minutes. Step-by-step instructions: Delete your account.
- Deleting your account does not cancel your Google Play subscription. Cancel it in Google Play → Payments & subscriptions → Subscriptions to stop future charges.
- If we banned your account, we keep the banned email hash described in section 6 after your account is deleted.
- Suspended or banned accounts: you can still delete your account and data (in the app while suspended; by email or at https://www.realitypal.ai/delete-account if a ban stops you signing in). To appeal a suspension, use Contact support in the app (it stays available while you’re suspended) or email support@realitypal.ai; to appeal a ban, email support@realitypal.ai.
- Notifications: turn off Let her message me first in Settings; set your quiet hours in Settings; turn the morning briefing and evening recap on or off in Settings → Routines; delete or pause routines and cancel reminders at any time (in the Routines screen or by asking your Pal). You can also block notifications for the app, or for individual notification categories, in Android Settings. Reminders and routine messages are still saved in your chat.
- Translator mode: optional; use it only when you choose. You can turn off spoken translations (the text is still shown), and without headphones your side is shown as text only unless you turn on Also say it out loud without headphones. Microphone access can be revoked in Android Settings.
- Hands-free translation: off unless you turn it on. Pause stops listening and streaming immediately, and leaving the Translator screen ends it. You can always use the two-button mode instead, where nothing is streamed to us.
- Wake words: off by default. Turn them off any time in Settings → Wake words or with Turn off in the “Wake words” notification (Pause 1 hour pauses them). Revoking the microphone permission also stops them.
- Texting: off by default. Turn it off in Settings → Texting, or revoke Contacts access in Android Settings → Apps → RealityPal → Permissions.
- Discord: unlink in Settings → Discord, use
/pal forget-mein a server to remove what you said there, or/pal optoutto stop being heard in voice channels. - Memories: in the app’s What she remembers screen you can see everything she remembers and where it came from, edit or delete any memory, pause memory (she stops learning and recalling; nothing is deleted), turn off automatic learning, turn Sensitive topics on or off (off by default), or forget everything. You can also ask her in chat to forget something. When you delete a chat you can choose to also forget what she learned in it.
- Calendar access: off by default. Turn it off in Settings → Calendar access or revoke the calendar permission in Android Settings. Once it’s off, no calendar data is read or sent, including for briefings.
- Camera features: the face greeting is off by default; turn it off any time in Settings or by tapping the camera indicator in the chat. Face recognition can be withdrawn at any time (Settings → Faces → Turn off & delete all). Camera access can be revoked in Android Settings → Apps → RealityPal → Permissions.
- Delete your account without the app: visit https://www.realitypal.ai/delete-account or email support@realitypal.ai from the address on your account. We’ll verify the request and delete your data within 30 days.
- Access, correct or export: you can see and update your display name in the app. For a copy of your data or other requests, email support@realitypal.ai.
- Object or withdraw consent: contact us. You can also turn off optional features (camera, microphone, calendar, notifications, memory) at any time as described above.
- US state privacy rights: depending on the state where you live (for example California under the CCPA/CPRA, and other states with similar laws), you may have the right to know what personal information we collect and how we use it, to access it and get a copy, to correct it, to delete it, and to opt out of the sale or sharing of personal information, targeted advertising and certain profiling. We don’t sell or share personal information (as those terms are defined under the CCPA/CPRA), we don’t use it for targeted advertising, and we don’t use it for profiling that produces legal or similarly significant effects. We use sensitive personal information only to provide the Service you ask for. To make a request, email support@realitypal.ai from the address on your account so we can verify it; an authorized agent may make a request on your behalf where the law allows. If we decline your request, you can appeal by replying to our decision.
We won’t discriminate against you for using your rights.
8. Security
We use industry-standard protections:
- encryption in transit (HTTPS/TLS) for all connections, including to your own Hermes or OpenClaw agent,
- encryption at rest for our databases, photo and audio storage and logs, with keys we manage in AWS Key Management Service,
- an additional personal encryption key for each user, used to encrypt your conversations, memories, reminders, routines and similar content in our database; deleting your account destroys that key,
- notifications that don’t carry your messages through Google,
- no message content in our service logs,
- for voice requests, we request that ElevenLabs not retain the text (zero-retention mode) where our plan supports it,
- optional two-step sign-in (authenticator app), a 12-character minimum password and automatic protection against compromised passwords and suspicious sign-ins,
- a private, non-public media bucket with time-limited links,
- access controls with least-privilege permissions,
- staff access limited to authorized team members with required two-step verification, no staff access to your personal encryption key, and a log of every account lookup, report view and support-request view,
- secrets stored in a managed secrets service,
- on your phone: an encrypted local database, no Android cloud backup of app data, private lock-screen notifications, and chat screens hidden from screenshots unless you turn on Allow screenshots.
Not end-to-end encrypted. To write your Pal’s replies, send reminders and routine messages when your phone is offline, speak and translate, our servers must read your content while handling a request. It is processed by Amazon Web Services (including Amazon Bedrock for replies, Amazon Transcribe and Amazon Translate for translation) and by ElevenLabs for voice, as described in section 4. They receive only what is needed for that request.
No system is perfectly secure. Please use a strong, unique password and turn on two-step sign-in.
9. Children
The Service is intended for adults aged 18 and over and is not directed at children. We don’t knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we’ll delete it and its data.
If you believe a child has given us personal information, contact support@realitypal.ai and we’ll delete it.
10. AI-generated content
Pal replies are generated by AI and can be inaccurate or inappropriate. They don’t reflect the views of Reality AI. You can report any reply in the app (long-press → Report on Android; the message’s options menu → Report message on the web). Reports are reviewed by our moderation team (see 4.1).
11. Changes to this policy
We may update this policy. If we make material changes, we’ll notify you in the app or by email and update the effective date above.
12. Contact
Reality AI LLC
Arizona, United States
Privacy requests: support@realitypal.ai
General support: support@realitypal.ai
Website: https://www.realitypal.ai