Privacy Policy

Your family's privacy is the foundation

This policy explains, in plain language, what data we collect, how we protect it, and what choices you have.

Effective: March 12, 2026Last Updated: March 12, 2026

Polipo (“we,” “us,” or “our”) is an AI-powered family assistant operated by AxB Labs (AxB, Inc.). We provide household management services through our web application at chat.polipo.ai, voice interfaces, and optional third-party messaging integrations. This Privacy Policy applies to all of these services (collectively, “Services”).

01

Our Privacy Principles

Everything we build starts from these commitments:

  1. 1.
    Your data belongs to your family. We collect only what's necessary to run the service like email, payment details, anonymized telemetry (page visits, button clicks, etc. but never page or chat content), and nothing more.
  2. 2.
    Zero knowledge at rest. Your stored data is fully encrypted at rest. Our devs cannot read it, even if we wanted to. Server admins cannot access it either thanks to confidential compute implementation.
  3. 3.
    Minimal data in transit. When your messages are processed by the AI assistant, only the needed portion of context is sent to the cloud LLM server, encrypted over TLS, and never used to train AI models under commercial terms.
  4. 4.
    No data selling, no ads, no profiling. We have only one single business model, subscription. We will never sell your data, show you ads, or build profiles to monetize your family's information.
  5. 5.
    Radical transparency. Where we have limitations, like necessity of using cloud AI for inference, we tell you exactly how it works rather than hiding behind vague language.
02

Information That Exists in Your Polipo Account

Traditional services collect your data into their databases. Polipo is different: all of the information below lives inside your family's isolated, encrypted container. Our engineers cannot see, read, or access it. It's yours.

Information You Share With Your Assistant

During onboarding and normal use, you may share the following with your Polipo assistant. All of this is stored exclusively inside your family's encrypted container, not in any central Polipo database:

Family information: Names and ages of family members, schedules, dietary preferences, and household details. Even the onboarding conversation where you first share this happens inside your isolated container.

Conversations: Every message you send to your assistant via text or voice stays in your encrypted container. We have no access to it.

Connected service tokens: If you link Google Calendar, Gmail, Google Drive, or other services, the OAuth tokens are stored in your container. We never see your Google credentials or data.

Phone number: If you enable SMS or voice call features, text conversations or call transcripts are stored in your container. We don't keep any copies.

Information We Do Handle Directly

A small amount of information necessarily passes through our infrastructure outside of your encrypted container:

Account identity: Your email address and name are used for authentication and to route you to your family’s container. This is the only personal information we can see.

Connection data: IP address, browser type, and device information — used only for authentication and spam/DDoS prevention, not stored long-term.

Anonymized usage patterns: Which features are used and when, in aggregate. This data is not tied to your conversations or family content.

Information We Do Not Collect

We do not collect location data, contacts from your phone, photos or media (except media you explicitly share with the assistant, which are stored encrypted inside the container), biometric data, or data from other apps on your device.

03

How We Protect Your Data

We've designed Polipo so that even our own team cannot access your family's private information. Here's how.

Per-Family Container Isolation

Each family runs in its own isolated computing environment (a dedicated container). Your data never mixes with another family's data. There is no shared database, your family's conversations, schedules, and preferences live in a sandboxed environment that belongs only to you.

Zero-Knowledge Encryption at Rest

All data stored on our servers is encrypted using keys derived from your family's credentials. We use SQLCipher for database encryption and gocryptfs for file-level encryption. The practical result: your data at rest is unreadable to us, to our hosting provider, and to anyone who might gain unauthorized access to our servers.

Confidential Virtual Machines

We run on AMD SEV Confidential Virtual Machines, a hardware-level security technology that encrypts your data even while it's being processed in memory. This protects your family's information from cloud provider administrators, hypervisor-level attacks, and other infrastructure-level threats. Combined with Secure Boot, vTPM, and Integrity Monitoring, this means your data is protected at every layer, at rest, in transit, and in use.

Encryption in Transit

All communications between your device and our servers use TLS (Transport Layer Security) encryption. This applies to web connections, WebSocket real-time messaging, and API calls. No data travels unencrypted.

04

How AI Processing Works

This is where we're radically transparent. Polipo uses cloud-based AI to understand your messages and take action. Here's exactly what that means for your privacy.

What Happens When You Send a Message

When you send a message to Polipo, the minimum context needed to generate a helpful response is sent to our AI inference provider (currently Anthropic & Gemini) over an encrypted TLS connection. The AI processes your message and returns a response. Here's what's important to understand:

The AI does see your message content in order to understand it and respond. This is inherent to how AI assistants work, the model needs to read your message to help you.

We minimize what's sent. Only the relevant context for your current request is included, not your entire history or all of your family's data.

Never used to train AI models. Under our commercial agreements with AI inference providers, your family's conversations are never used to train, fine-tune, or improve their models. The provider may briefly retain data (typically a few days) solely to monitor for abuse and policy violations, after which it is deleted.

No persistent memory at the provider. Each request is processed independently. The AI provider does not accumulate a profile of your family over time.

Our Roadmap Toward Self-Hosted AI

We recognize that sending any data to a third-party AI provider, even with no-training agreements and TLS encryption, is a trust dependency. As open-source AI models mature, we are actively working toward self-hosted inference that would keep all processing within our confidential computing environment, eliminating even short-term third-party data exposure. We will update this policy as that capability becomes available.

05

Third-Party Integrations

Google Workspace

If you connect Google Calendar, Gmail, Google Drive, or Google Sheets, Polipo accesses these services using OAuth 2.0 tokens that you explicitly authorize. We request only the permissions necessary for the features you use. You can revoke access at any time through your Google Account settings. We do not store copies of your Google data beyond what is needed for active session context.

External Messaging Channels

If you choose to interact with Polipo through third-party messaging platforms such as WhatsApp, Telegram, SMS, or Alexa, please be aware of the following.

Messages sent through these platforms are delivered to Polipo via secure, encrypted connections. However, the third-party platform itself also processes and stores its own copy of the conversation according to its own privacy policy. Specifically:

  • WhatsApp and Telegram store encrypted versions of messages on their servers. While these messages are encrypted, the platforms have their own data retention and access policies.
  • SMS messages are transmitted through your mobile carrier and our telephony provider (Telnyx). Carriers and Telnyx may retain message metadata or content in accordance with their own policies and applicable law.
  • Alexa and other voice assistants process your voice commands through their own AI systems before passing the text to Polipo. Amazon (or the relevant provider) retains data according to their privacy policy.

We encrypt all data received from these platforms the moment it reaches our servers and apply the same per-family isolation and encryption protections described above. However, we cannot control what the third-party platform retains on their end. We recommend reviewing each platform's privacy policy before choosing to use it as a channel for Polipo.

Payment Processing

Payments are handled by Stripe. We do not store your credit card number or payment credentials on our servers. Stripe's handling of your payment information is governed by their privacy policy.

06

How We Use Your Information

We use your information for the following purposes and no others:

  • To provide and operate the service: managing your family's calendar, tasks, reminders, grocery lists, and other household functions.
  • To personalize your experience: remembering your preferences, your family's schedules, and context from prior conversations to provide proactive, helpful assistance.
  • To communicate with you: sending push notifications, SMS reminders, or email summaries that you've opted into.
  • To improve the service: analyzing anonymized, aggregated usage patterns (not conversation content) to fix bugs and build better features.
  • To ensure security: detecting and preventing unauthorized access or abuse.

We do not use your data for advertising, profiling, or any purpose beyond operating the service you've signed up for.

07

When We Share Your Information

We share your information only in these limited circumstances:

  • AI inference providers (currently Anthropic & Gemini): minimal message context, encrypted in transit, never used for model training. May be briefly retained for abuse monitoring per commercial terms.
  • Connected services you authorize (Google Workspace, Telnyx for SMS/voice, Stripe for payments): only the data necessary to perform the integration you requested.
  • Legal requirements: if required by law, subpoena, or court order. We will notify you unless legally prohibited from doing so.
  • Business transfers: in the event of a merger or acquisition, your data would remain subject to this privacy policy.

We never sell your personal information. We never share your data with advertisers. We never provide your data to data brokers.

08

Data Retention

We retain your data only as long as you are using the service. You can delete or destroy the entire family pod at any time, wiping all data you shared to date with your assistant.

  • Conversation history: stored in your family's encrypted container for as long as your account exists. You can delete individual conversations or your entire history at any time.
  • Connected service tokens: OAuth tokens are stored only while the integration is active. Revoking access deletes the token.
  • AI processing: your conversations are never used to train AI models. The inference provider may retain data for a short period for safety and abuse monitoring, after which it is deleted.
  • Account deletion: when you delete your account, your family's container and all data within it are destroyed. Since we cannot read the encrypted contents, there is nothing to selectively retain.
09

Your Rights and Choices

Regardless of where you live, we provide every Polipo user with the following rights:

Access

View all data Polipo holds about your family directly within the app.

Correction

Update your family information, profiles, and preferences at any time.

Deletion

Delete conversations, disconnect integrations, or delete your entire account.

Revoke integrations

Disconnect Google Workspace, SMS, or any other integration at any time.

For users in the European Union, United Kingdom, or California, you have additional rights under GDPR, UK GDPR, or CCPA respectively, including the right to object to processing, restrict processing, and lodge complaints with supervisory authorities. Contact us at privacy@polipo.ai to exercise any of these rights.

10

Children's Privacy

Polipo is designed for families, which means children's information may be part of the household data you share. We treat all family data with the same high level of protection described in this policy. We do not knowingly collect personal information directly from children under 13 (or the applicable age in your jurisdiction) without parental consent. The parent or guardian who sets up the family account is responsible for managing children's information within Polipo.

11

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Polipo app or via email at least 30 days before the changes take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.

12

Contact Us

If you have questions about this Privacy Policy or your family's data, we'd love to hear from you:

Operated by AxB Labs (AxB, Inc.)

This Privacy Policy is made available under a Creative Commons Sharealike license. It was inspired by Automattic's open-source privacy policy.