Last updated · 2026-08-21
Privacy Policy
idem is built to do work for you, and that means it sometimes handles personal information. This page explains what we collect, why, and your choices. For a quick version, see the FAQs on the home page.
What we collect
- Account info. Email, sign-in method, and basic profile data when you create an account.
- Content you provide. Messages, instructions, files, images, voice messages and their transcripts, and the memory idem builds from your conversations.
- Integration data. When you connect third-party services, we access only the data you've authorized, and only as needed to complete tasks.
- Usage data. Diagnostics, performance, and feature usage to help us improve the app.
What we send to AI providers
idem is an AI assistant, so answering you means sending your content to the AI provider that generates the response. Depending on what you ask for, that can include:
- your messages and instructions
- the relevant part of the conversation history
- relevant memory, preferences, and account context
- files, images, and voice transcripts you reference
- content pulled from a connected service when a request needs it (for example the emails or calendar events relevant to what you asked)
A provider only sees what a given request needs. It does not get a copy of your inbox, your calendar, or your files as a whole. Integration credentials, OAuth tokens, API keys, and stored secret values are never sent to an AI provider in plaintext: scripts reference them by name and the value is injected at request time.
Which AI providers
Which provider handles a request depends on the model chosen for that conversation or background job. The default is Anthropic's Claude. In production, your content can reach:
- OpenAI: GPT models, and, if you connect your own ChatGPT account, requests routed through it
- Anthropic: Claude models, idem's default
- OpenRouter: a gateway that routes to these model labs, and only these: Google, xAI, DeepSeek, Moonshot AI, Alibaba (Qwen), and Z.ai (GLM)
Requests for Google models are restricted to Google's own endpoints. For the open-weight models in that list, OpenRouter selects the host that serves the request, which may be the lab itself or another inference host on OpenRouter's network.
Your consent
Before any of your content goes to a third-party AI provider, idem asks for your explicit permission and names the providers above. Until you accept, no content is sent for model processing: our server refuses model requests for both chats and background jobs, so the block applies to the actual data flow, not just the screen. If you decline, the assistant stays unavailable, and you can sign out. If this disclosure changes materially, we ask you to review and accept it again.
Retention and training
We don't use your content to train models, and we don't sell it. Each AI provider handles your content under its own terms, and those terms are not the same across providers:
- Anthropic and OpenAI state that content sent through their APIs is not used to train their models. OpenAI retains API content for up to 30 days by default for abuse monitoring.
- OpenRouter says it works with providers so that prompts are not trained on, but notes exceptions, and retention depends on the lab and host that serves the request. We don't claim no-training or zero retention for this path.
- If you connect your own ChatGPT account, those requests run on your subscription, under your own OpenAI account terms and settings.
On our side, your conversations, memory, and files are kept until you delete them, or until you delete your account. You can delete any conversation, memory file, or upload at any time in the app.
Where your data lives
Your account data, conversations, memory, and files are stored in our Postgres database on Railway (EU region, Netherlands). Uploads, images, and data exports are stored in Cloudflare R2. Connections are encrypted in transit. Secrets like OAuth tokens and API keys are additionally encrypted at rest with AES-256-GCM.
How we use it
- To run the tasks you ask idem to perform
- To notify you when tasks complete
- To improve the app's reliability and performance
- To respond to support requests
Billing
Subscriptions are sold and billed on our website through Stripe, which handles your payment details. idem does not sell subscriptions inside the app, and Apple does not process idem payments. Stripe never receives your conversation content.
Subprocessors
- Railway (EU region): hosting and Postgres database
- Cloudflare R2: file storage and data exports
- Anthropic, OpenAI, and OpenRouter (routing to Google, xAI, DeepSeek, Moonshot AI, Alibaba, and Z.ai): generating responses
- Serper: the web searches idem runs for you
- Browserbase (EU region): the cloud browser idem drives, including pages it loads and what you type in the live view
- ElevenLabs: transcribing your voice messages and speaking replies aloud
- Vapi: placing the outbound phone calls you ask for, including the call audio and its transcript
- Composio: connecting and calling the third-party apps it fronts (for example Gmail, Calendar, Drive, Slack)
- Unipile: personal messaging accounts you connect, and the messages sent and received through them
- Resend: sign-in links and notification emails
- Apple and Google: push notifications to your devices, which can include a short message preview
- Stripe: subscription billing
- Latitude: diagnostic traces of assistant runs, which can include message content. Turning off "Help improve idem" in Settings stops these traces.
- Vercel and Loops: hosting idem.so and the request-access form on it
- OAuth providers per integration you connect (Google, Notion, etc.)
No ads, no selling
idem is paid software. We don't sell your data, share it with advertisers, or run ads. We don't track you across other apps and websites, and the app ships no third-party tracking or analytics SDKs.
Your choices
- Review and edit the memory idem keeps on you, anytime, inside the app
- Use an incognito chat: it's never written to the database, doesn't read your memory, and is dropped from memory within 30 minutes
- Turn off "Help improve idem" to stop diagnostic traces
- Export your data from Settings, and get it emailed to you as a link
- Disconnect any integration in one tap (revoking deletes the token)
- Delete your account from your account page on the web, which the app links you to. This immediately removes your account, your sign-in sessions, and your stored integration credentials and secrets, and cancels billing.
- Contact us with privacy questions
Children
idem isn't directed at children under 13 and we don't knowingly collect their data.
Changes
We may update this policy. Material changes will be flagged in the app, and a material change to how your content is shared with AI providers will ask you to accept the disclosure again.
Contact
Privacy questions? Email support@idem.so.