Legal
Privacy policy
Last updated: 22 August 2026
Auddi.ai is built around a simple idea: your cube should know it is you, but we should not need to know everything about you. This page explains exactly what we store, why we store it, how long we keep it, and how you can take it back.
What we store
We only collect what is needed to run your account, pair your cube, and fulfill your order. We do not sell personal data.
| Data type | Examples | Why we store it | How long we keep it |
|---|---|---|---|
| Account profile | Email address, display name, profile photo, sign-in provider (Google/Apple), password hash managed by Lovable Cloud auth. | To identify you, secure your account, and send order/shipping updates. | Kept while your account is active. Deleted within 30 days of account closure, except where legal/tax records require us to keep it longer. |
| Cube devices | Device serial number, nickname, paired status, plan tier, last-seen timestamp, public key fingerprint. | To pair your cube to your account, enforce device limits, and show device status in your account. | Kept while the device is paired to your account. Unpaired/revoked devices are removed after 90 days. |
| Biometric templates | Mathematical fingerprint templates created during enrollment. These are stored only inside the cube's secure enclave, never on our servers. | To let the cube verify that it is you touching the scanner. | Stored locally on the cube. If you factory reset the cube or revoke it from your account, the templates are erased immediately. |
| Verification events | Success/fail status, timestamp, device serial, and which profile was used. No image or raw biometric data is stored. | To let you review recent access activity in your account. | Rolling 90-day history. Older events are deleted automatically. |
| Voice verification audio | The short recording of your spoken passphrase. It is transcribed to compare the words only — no voiceprint or biometric voice template is created. | To confirm the spoken passphrase matches when the fingerprint sensor cannot read. | Never stored by default: the audio is processed in memory and discarded. If you turn on retention in Voice passphrase settings, audio is held in private encrypted storage for 24 hours, 7 days, or 30 days (your choice) and deleted automatically after that. You can delete it sooner at any time. |
| Orders & reservations | Product handle, quantity, price, reservation charge, shipping destination, and order status from our checkout provider. | To fulfill your order and provide customer support. | Kept for 7 years to meet tax and accounting requirements, then purged. |
| Support tickets | Name, email, message content, and any attachments you send us. | To answer questions and resolve issues. | Kept for 2 years after the ticket is closed, then deleted. |
| Cookies & analytics | Essential session cookie, privacy-friendly aggregate page analytics, and PWA service-worker cache data. | To keep you signed in and understand how the site is used without identifying individuals. | Session cookies expire when you sign out. Analytics data is retained for 26 months in aggregate form. |
What we never store
- We do not store raw fingerprint images or scans. The scanner creates a local mathematical template inside the cube's secure enclave.
- We do not store the contents of your screen, your files, your conversations, or the tasks you run on your cube.
- We do not store full payment card details. Card processing is handled by our payment provider using industry-standard encryption.
- We do not store voice recordings unless you explicitly switch on audio retention, and we never build a voiceprint from them.
- We do not share personal data with advertisers or data brokers.
Retention schedule
Active account
Profile, device pairing, and active support data are kept while your account remains open.
After you delete your account
Personal data is erased within 30 days. Order and tax records are kept for 7 years as required by law.
Unpaired cubes
Device records are removed 90 days after the cube is unpaired or revoked.
Verification logs
Access activity is stored on a rolling 90-day window, then deleted automatically.
How to request deletion
You can ask us to delete your account and personal data at any time. Follow these steps and we will handle the rest.
- Sign in and go to your Account page.
- Unpair or revoke any cube you no longer use.
- Factory reset the cube to erase local fingerprint templates.
- Email privacy@auddi.ai from your registered address with the subject 'Delete my data'.
- We confirm your request within 48 hours and complete deletion within 30 days.
If you are not the account owner, you cannot request deletion on someone else's behalf. We will verify your identity before processing any deletion request.
Questions?
If anything here is unclear, contact us at privacy@auddi.ai or open a support request. A real human will reply.