Legal
Last updated: 2026-07-31
Privacy Policy
Appfi is a personal assistant you reach by text message. You text it, it texts back, and it does things for you. To do that it has to keep what you tell it. This page explains what it keeps, where that lives, who else touches it, and how to get it deleted.
We are Scoli Inc., a Canadian corporation operating as Appfi, at 280 Joseph St, Suite 2000, Kitchener, Ontario N2G 4Z5, Canada. We decide how your personal information is handled, which makes us the controller of it.
Privacy questions: privacy@appfi.dev. Anything else: support@appfi.dev.
Summary of key points
What does Appfi collect? Your phone number, the messages you send and receive, any voice notes or files you send, and what it remembers about you so it does not have to ask twice. If you connect an email or calendar account, the messages and events it needs to do what you asked. Learn more
Why? To be your assistant. To bill you. To keep the service working and to stop abuse. Nothing else. Learn more
Does Appfi train AI models on my messages? No. Your messages are sent to a model so it can reply to you. They are not used to train or improve anyone's model. Learn more
What happens to a mailbox I connect? It is used to do the thing you asked for, for you, and nothing else. It is never used to train a model. Learn more
Who else sees it? The companies that carry the messages, run the models, and take the payment. They are listed by name. We do not sell your information and we do not share it for advertising. Learn more
Where does it live? Appfi's core records are stored in Google Cloud in Canada and encrypted. OAuth credentials are held by Nango Cloud, and some processing may happen outside Canada as described below. Where it is stored and how it is protected
Can I make it forget? Yes. Text it "forget me" and it deletes your messages and everything it remembered about you. There is no way to make it forget one specific fact yet. Learn more
Contents
- Who this covers
- What we collect
- How we use it, and our legal basis
- Artificial intelligence
- Connected email and calendar accounts
- Cookies and tracking
- Who we share it with
- We do not sell or share your information
- How long we keep it
- Where it is stored, and international transfers
- How we protect it
- Your choices, and how to use them
- Your rights in Canada
- Your rights in the EU and UK
- Your rights in California
- Your rights in other US states
- Children
- Automated decisions
- Do Not Track
- Links to other sites
- Changes to this policy
- How to reach us, and how to complain
1. Who this covers
In short: this covers appfi.dev and the assistant you text. It does not cover other companies' services you reach through it.
This policy applies to appfi.dev, to the Appfi assistant you reach on iMessage, RCS and SMS, and to the payment pages at appfi.dev/pay. It does not apply to third-party services we do not control. If the assistant reads a web page for you, or sends mail through a provider you connected, that provider's own policy governs what it does on its side.
2. What we collect
In short: your number, your messages, what it remembers about you, and your payment record.
Things you give us directly.
- Your phone number. It is how the assistant knows it is you. There is no username and no password.
- Your messages. Everything you text it and everything it texts back, including the timing of those messages.
- Voice notes. If you send one, it is transcribed so the assistant can read it. The audio itself is transcribed in memory and is not stored by us. What we keep is the transcript, and the link to the file the messaging network is holding.
- Photos, documents and other attachments you send, and files the assistant produces for you.
- What it remembers about you. Your name, what you call people, preferences, the running context of your conversations. This is the part that makes it useful on day thirty instead of day one.
- What you tell it to do. Reminders, tasks, searches, and the results.
- Contact details you give us on the website, such as a name, email address, phone number and a description of what you need, if you fill in the form on appfi.dev.
Things we get automatically.
- Delivery data from the messaging network: whether a message was delivered, on which channel, and any error.
- Server logs: IP address, timestamps, and technical diagnostics when you load a page or the service handles a request. Requests to the payment pages are excluded from our retained logs on purpose.
Things we get from other companies.
- Payment records from Stripe: that a payment succeeded or failed, the subscription state, the card brand and last four digits, and the billing period. We never receive or store your full card number.
- From an account you connect, the messages, events and contacts described in section 5. Only if you connect one.
We do not ask for and do not want your racial or ethnic origin, religious or political beliefs, health data, sexual orientation, biometrics, or government identifiers. If you text something like that anyway it is stored as part of the message, and the same protections in this policy apply to it.
3. How we use it, and our legal basis
In short: to be your assistant, to bill you, and to keep the thing running.
We use your information to:
- reply to you, remember you, and do the things you ask;
- transcribe voice notes so the assistant can act on them;
- send you the reminders and results you asked for;
- take payment, handle renewals and failures, and keep accounting records;
- keep the service up, find and fix faults, and investigate abuse, fraud and security incidents;
- answer your support messages;
- meet our legal obligations and enforce our terms.
We do not use your messages to build advertising profiles. We do not run advertising.
If you are in the EEA or the UK, the GDPR asks us to name a legal basis for each of those. We rely on: performance of our contract with you (Art. 6(1)(b)) to run the assistant, remember you, and bill you; legitimate interests (Art. 6(1)(f)) to keep the service secure, reliable and free of abuse, and to keep proper business records; your consent (Art. 6(1)(a)) to connect an email or calendar account, which you can withdraw at any time by disconnecting it; and legal obligation (Art. 6(1)(c)) where the law requires us to keep or produce something.
4. Artificial intelligence
In short: your messages go to Google's Gemini models so the assistant can answer. They are not used to train models. The model is called through Google's global endpoint, so that one step is not pinned to Canada.
Appfi runs on large language models hosted by Google Cloud on Vertex AI. To answer you, the service sends the model your message, the relevant part of your conversation history, and what it remembers about you. Voice notes are transcribed by the same models. If the assistant needs to read a web page or a document to answer you, that content goes to the model too.
Your data is stored in Canada, as section 10 describes. The model call is different. We use Vertex AI's global endpoint, which means Google may run that one request in a data centre outside Canada. We use it because it is the configuration Google keeps most current. We say so here because the word "Canada" elsewhere in this policy does not cover this step.
Google acts as our processor for this. Under the Google Cloud terms that apply to Vertex AI, your prompts and the model's responses are not used to train Google's models. That protection comes from the contract with Google, not from a setting in our code. There is no toggle in Appfi that turns it on or off.
We do not use your content to train or fine-tune any AI model. Not ours, not anyone else's. We have never done it, and we have no training pipeline to do it with. The assistant improves for you because it remembers you, not because your messages are used to teach a model.
The assistant can be wrong. It can misread a message, miss a detail, or state something that is not true. Check anything that matters before acting on it.
There is no version of Appfi without a model, so there is no toggle to turn this off. What you do control: what you tell it, what you connect, what you tell it to forget, and whether you keep using it.
5. Connected email and calendar accounts
In short: if you connect a mailbox, we use it to do the thing you asked, for you, and never to train a model.
You can connect an email or calendar account so the assistant can act on it for you. This is off unless you turn it on, and you can disconnect at any time.
What we access. When you connect an account, we ask for the narrowest set of permissions that can do the job. Depending on what you connect and what you ask for, that can include reading messages and their attachments, sending mail as you, and reading or writing calendar events. The consent screen shown by your provider at the moment you connect is the authoritative list for your account. Nothing is accessed before you complete that screen.
What we do with it. Exactly what you asked for, and the work needed to do it: find the thread you mentioned, draft the reply, send it, put the meeting on your calendar, tell you what came in. The content passes through the model so the assistant can understand it, in the same way your text messages do.
What we never do with it.
- We never use data from a connected account to train or improve any AI or machine-learning model, including our own. Reading your mail to answer you is allowed. Training on it is not.
- We never use it to serve anyone but you. It is not pooled, not aggregated across people, not used to improve anyone else's assistant.
- We never sell it, and we never transfer it to anyone except the processors named in section 7 who need it to deliver what you asked for.
- We never use it for advertising, and we never let a human read it except with your explicit permission, or where security or the law requires it and only to the extent required.
Google's rules, stated plainly. Appfi's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How access is held. Connections are brokered through Nango Cloud. Nango holds the encrypted OAuth credentials; Appfi's credential-isolated tool broker asks Nango to perform only the provider request needed for your instruction. The model never receives your tokens or Nango credentials. It sees structured requests and structured results.
Turning it off. Disconnect from your assistant, or revoke Appfi's access directly at your provider: Google Account permissions or Microsoft account app permissions. Revoking stops all future access immediately. Anything already delivered to you, such as a draft it wrote or a summary it sent, stays in your conversation until you delete it.
6. Cookies and tracking
In short: almost none, and none at all on the payment pages.
appfi.dev sets no cookies of its own, and stores nothing in your browser's local storage. Fonts are served from our own domain, not a font network.
We can enable Google Analytics 4 to count page views. When it is enabled it is loaded on the marketing pages only, and it is switched off entirely on every /pay/ page. It is not enabled at the time of this update. If we turn it on for visitors in a place that requires prior consent, we will ask first.
We run no advertising pixels, no retargeting tags, and no session recording.
The assistant itself is a text conversation. There is no browser, so there is nothing to track.
7. Who we share it with
In short: the companies that carry the message, run the model, and take the payment. Named, and that is the whole list.
| Who | What they get | Why |
|---|---|---|
| Sendblue | your phone number and the content of messages in transit | carries messages over iMessage, RCS and SMS |
| Google Cloud (Cloud Run, Cloud SQL, Cloud Storage) | messages, transcripts, memory, files | runs the service and stores the data, in Canada |
| Google Cloud (Vertex AI) | your message, the relevant conversation history, and what it remembers about you, at the moment the assistant answers | runs the model. Called through the global endpoint, so this step may run outside Canada. |
| Google (Gmail and Calendar) or Microsoft (Outlook and Graph) | OAuth authorization, provider API requests, and the messages or events involved in the action you requested | supplies the connected email and calendar service you chose |
| Stripe | your name, email, payment details and billing history | takes the payment. Card details go straight to Stripe and never touch our servers. |
| Nango Cloud | encrypted OAuth credentials for accounts you connect and the provider requests made for you | brokers and maintains the connection |
| Your mobile carrier and Apple | the message, in transit | delivers an SMS, RCS or iMessage. Normal for any text message. |
| Resend | your name and email address, if you use the form on appfi.dev | delivers that one notification email |
| Google Cloud (Firebase App Hosting) | your IP address and request data when you load appfi.dev | serves the website |
We also disclose personal information to professional advisors such as lawyers and accountants when they need it; to authorities where the law, a court order or a valid legal process requires it, or where it is necessary to protect someone's safety or our rights; and to a buyer or successor in a merger, acquisition or sale of assets, under confidentiality.
Every processor is under a written contract that limits them to processing your information on our instructions, for us, and requires them to protect it.
8. We do not sell or share your information
In short: no sale, no advertising sharing, ever, and none in the last twelve months.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as California law defines those terms. We have not sold or shared personal information in the preceding twelve months, and we have no business model that would make us want to. We do not sell or share the personal information of anyone under 16.
9. How long we keep it
In short: your messages and everything the assistant remembered about you are deleted 90 days after your account closes, or when you ask if you ask us sooner. Two things do not follow that clock: billing records stay at least seven years because tax law says so, and files in cloud storage are removed by hand rather than on a schedule. Both rows below say so.
A retention period is only real if something enforces it, so the third column names what does. Where the answer is a person doing it by hand, the column says that rather than implying a machine.
| What | How long | What enforces it |
|---|---|---|
| Your messages, your conversation history, the assistant's working transcript of your requests, what it remembered about you, the links to files you sent, and any unused one-time codes | for as long as you use Appfi, then deleted 90 days after your account closes | a deletion job in our own code. Closing an account writes a deletion date 90 days out; a scheduled sweep deletes everything listed here once that date passes. |
| The operational record that a message was handled, and when | kept, with the content and your phone number removed by the same job | the same job. It empties these rows rather than deleting them, because our delivery and billing checks read them. What is left is a timestamp and a status. |
| Files you sent and files the assistant made for you, as stored in Google Cloud Storage | no automatic deletion | nothing automatic, and this is the weakest row in the table. The database records that point at these files are deleted on the schedule above. The files themselves are removed by hand when you ask us to erase you. |
| Billing and tax records: invoices, payment history, subscription state | at least 7 years from the end of the tax year, as Canadian tax law requires | nothing automatic. We do not delete these on a schedule; after the seven years they are removed by hand. |
| Encrypted raw payment-provider webhook payloads | emptied after 30 days | a deletion job in our own code, on the same schedule as above. |
| Payment-link rate-limit records | 1 day | the same job. |
| Database backups | the most recent 14 daily backups, then deleted automatically | Google Cloud SQL's backup retention setting. |
| Ordinary server logs | 30 days | Google Cloud Logging's retention setting on our default log store. |
| Google Cloud's own administrative audit log for our project | 400 days | Google fixes this period and we cannot shorten it. |
| Website contact-form submissions | until we delete them | nothing automatic. The form on appfi.dev does not write to a database. It sends us an email, and that email stays in our mailbox until someone removes it. Ask us and we will remove yours. |
| A record that you asked us to stop contacting you | kept indefinitely | kept on purpose. This record contains your phone number and the words you used, because it is the only thing that stops us texting you again. It survives erasure by design. |
What "your account closes" means. It means you told us you were done, by text or by email, and we recorded it. It does not mean you went quiet, and cancelling your subscription does not close your account on its own. If you simply stop texting, nothing is deleted, because we would rather you find your history where you left it than come back to an empty conversation. If you want the clock to start, say so and we will start it.
If you ask us to erase you, we do it when you ask rather than in 90 days. Anything of yours that is still moving at that moment, such as a reply that has not been sent yet, is finished first and then deleted on the next sweep, which runs every minute.
Where something has to survive a deletion request, for example a tax record or the do-not-contact record, we keep only that, and we stop using it for anything else.
10. Where it is stored, and international transfers
In short: Appfi's core records are stored in Canada on purpose. OAuth credential custody, model calls and some processors operate elsewhere.
Your messages, transcripts, memory and files are stored in Google Cloud's northamerica-northeast1 region, in Montreal, Canada. So is the database and the service that runs the assistant. That is deliberate, not incidental.
The model call goes to Vertex AI's global endpoint, which Google may serve from a region outside Canada, as section 4 explains. Nothing is stored there by us. OAuth credentials for accounts you connect are held by Nango Cloud rather than in Appfi's Canadian database.
Some processors operate elsewhere. Nango, Stripe, Sendblue and Resend may process data in the United States or other countries. Where we transfer personal information out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a transfer to a country the Commission has found adequate. Canada holds a partial adequacy decision from the European Commission for commercial organisations. Ask us at privacy@appfi.dev and we will tell you which safeguard covers a given transfer.
11. How we protect it
In short: encrypted in transit and at rest, with the sensitive fields encrypted a second time under their own keys.
- Everything travels over TLS.
- Everything is encrypted at rest by Google Cloud.
- On top of that, message bodies, the sender and recipient addresses on each message, and the links to files the assistant sends you are encrypted again in Appfi's database under per-tenant keys, with the key version recorded so keys can be rotated. OAuth tokens are not stored in that database; Nango Cloud encrypts and holds them separately.
- Those addresses are also stored as a blind index, so the system can find your conversation without searching a plaintext number.
- Two things are stored as ordinary text and we would rather say so than round up. The first is the identifier that ties your conversation together, which is your channel and your phone number, because the system looks you up by it on every message. The second is the link to a file you send us, which points at the messaging network's own storage. Someone reading the database would learn which numbers hold conversations and when, but not what was said in them.
- Access is limited to the people who need it, and every service runs under its own identity with the narrowest permissions that let it work.
- Payment pages carry a strict content-security policy, send no referrer, are excluded from search indexing, and their URLs are excluded from our retained request logs.
- Card numbers never reach our servers. Stripe handles them under its own PCI DSS compliance.
No system is perfectly secure, and we cannot promise absolute security. If a breach affects your personal information and is likely to create a real risk of significant harm, we will notify the relevant regulator and, where the law requires it, you, without undue delay, and tell you what happened and what we are doing about it.
12. Your choices, and how to use them
In short: text it to forget. Email us to erase. We answer within the deadlines below.
Tell it to forget you. Text the assistant "forget me", "delete my data", "erase my information" or anything close to it, and it starts the erasure below. Phrases it recognises today include "forget me", "forget everything about me", "delete my data", "delete my info", "delete everything you have", "erase my data", "remove my information" and "right to be forgotten".
There is no way yet to make it forget one specific fact while keeping the rest. If that matters to you, email us and we will do it by hand.
Ask us to erase you. Email privacy@appfi.dev, or text the assistant one of the phrases above. Erasure deletes your messages, your conversation history, the assistant's working transcript of your requests, everything it remembered about you, and the links to any files you sent. Where a record has to stay for a delivery or billing check, the content and your phone number are removed from it and only a timestamp and a status are left. Files already stored in Google Cloud Storage are removed by hand as part of the same request.
We keep only what we are legally required to keep, plus the record that you asked us to stop. That record contains your number, on purpose, because it is what stops us contacting you again.
Ask for a copy. Email privacy@appfi.dev and we will send you an export of your data.
Ask us to correct something. Same address.
Disconnect an account. Disconnect from the assistant, or revoke access at your provider.
Stop messages. Reply STOP to any message and we stop. Reply HELP for help. Message and data rates from your carrier may apply.
How to reach us: email privacy@appfi.dev, or text the assistant on the number you already have, or write to Scoli Inc., 280 Joseph St, Suite 2000, Kitchener, Ontario N2G 4Z5, Canada.
We will check you are who you say you are before we act, which for a text-based service usually means confirming from the number we already know. You can use an authorised agent; we may ask them for proof of authority.
How long we take. Under the GDPR and UK GDPR, within one month, extendable by two more for a complex request, with notice. Under California law, we confirm receipt within 10 business days and answer within 45 days, extendable by another 45 with notice. Under Canadian law, within 30 days. Requests are free. We may charge a reasonable fee or decline a request that is manifestly unfounded, excessive or repetitive, and we will tell you why.
We will not treat you worse for exercising any of these rights.
13. Your rights in Canada
In short: access, correct, withdraw consent.
If you are in Canada, you have the right to access your personal information and an account of how it has been used and disclosed, to correct it if it is wrong or incomplete, and to withdraw your consent, subject to legal and contractual limits. Withdrawing consent to core processing generally means the assistant can no longer work for you.
If you are in Quebec, you also have the right to data portability, meaning a copy of your computerised personal information in a structured, commonly used format, and the right to have information de-indexed or its dissemination stopped in certain circumstances.
14. Your rights in the EU and UK
In short: the full GDPR set.
If you are in the European Economic Area or the United Kingdom, you have the right to access your data (Art. 15), correct it (Art. 16), have it erased (Art. 17), restrict how we process it (Art. 18), receive it in a portable form (Art. 20), object to processing including an absolute right to object to direct marketing (Art. 21), not be subject to a decision based solely on automated processing that significantly affects you (Art. 22), and withdraw consent at any time where we rely on it.
15. Your rights in California
In short: know, delete, correct, and no discrimination.
If you are a California resident you have the right to know what personal information we collect, use and disclose; to delete it, subject to exceptions; to correct it; to opt out of sale or sharing, which is moot here because we do neither; to limit the use of sensitive personal information, which is moot because we do not collect it for any purpose that triggers the limit; and to non-discrimination for exercising any of these.
Categories we have collected in the past twelve months, using California's statutory list:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | phone number, name, email address, IP address | Yes |
| California customer records | name, phone number, billing information | Yes |
| Protected classifications | age, gender, ethnicity | No |
| Commercial information | subscription and payment history | Yes |
| Biometric information | face or fingerprint data | No |
| Internet or network activity | server logs, page requests | Yes |
| Geolocation data | device location | No |
| Sensory data | audio you send as a voice note | Yes |
| Professional or employment information | job title, employer | No |
| Education information | schools, records | No |
| Inferences | what the assistant remembers and infers about your preferences | Yes |
Where a row says No, we do not ask for it. If you text it anyway it lives inside the message, which is covered by the Identifiers and message rows above.
California Shine the Light. Civil Code section 1798.83 lets California residents ask us once a year, free, for a list of the categories of personal information we disclosed to third parties for their own direct marketing, and who those third parties were. We disclose nothing for anyone's direct marketing, so the answer is none, but you are welcome to ask at privacy@appfi.dev.
16. Your rights in other US states
In short: the same set, plus an appeal if we say no.
If you live in a US state with a comprehensive consumer privacy law, including Colorado, Connecticut, Virginia, Texas, Utah, Oregon, Montana and others, you have the right to confirm whether we process your personal data and to access it; to correct it; to delete it; to get a portable copy; and to opt out of targeted advertising, sale, and certain profiling. We do none of those last three. Contact privacy@appfi.dev to exercise any of these.
We honour recognised universal opt-out signals such as Global Privacy Control as an opt-out of targeted advertising and sale wherever your state requires it, although we do neither in the first place.
We give you two ways to reach us with a privacy request: privacy@appfi.dev and support@appfi.dev.
Appeals. If we turn down your request, you can appeal by emailing privacy@appfi.dev. We will answer within the period your state's law allows and explain the decision. If we deny the appeal you can complain to your state Attorney General.
17. Children
In short: 18 and over.
Appfi is for people 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has been using Appfi, write to privacy@appfi.dev and we will close the account and delete the data. In the EEA and UK, where consent is the basis for offering a service to a child, we obtain it from the holder of parental responsibility below the applicable age of digital consent, which is between 13 and 16 depending on the country.
18. Automated decisions
In short: the assistant is automated, but it does not make legal decisions about you.
The assistant generates its replies automatically, and it decides on its own what to remember about you. It does not make decisions that produce legal or similarly significant effects about you based solely on automated processing. We do not use it for credit, employment, insurance, housing or eligibility decisions. If we ever did, we would tell you first, explain the main factors, and give you a way to get a human to look at it.
19. Do Not Track
In short: no consistent standard, so we do not act on it. We do honour Global Privacy Control.
Some browsers send a Do Not Track signal. There is still no agreed industry standard for what a site should do with one, so we do not respond to it. Separately, we do honour recognised opt-out preference signals such as Global Privacy Control, as described in section 16. Because we run no advertising or analytics partners that track you across sites, there is little for either signal to switch off here.
20. Links to other sites
In short: we are not responsible for someone else's site.
The website, and the assistant when it sends you a link, may point to services we do not control. Their privacy practices are their own.
21. Changes to this policy
We will update this policy when our practices, our technology or the law change. Material changes get a new "Last updated" date and, where the law requires it or the change is significant, a more direct notice, which for Appfi means a text message. Please read it now and then.
22. How to reach us, and how to complain
- Privacy questions and requests: privacy@appfi.dev
- Everything else: support@appfi.dev
- Phone: +1 519 729 3188
- Post: Scoli Inc., 280 Joseph St, Suite 2000, Kitchener, Ontario N2G 4Z5, Canada
The individual accountable for personal information at Scoli Inc. can be reached at privacy@appfi.dev.
Complaints. Please come to us first, because we can usually fix it faster. You can also complain to a regulator: in Canada, the Office of the Privacy Commissioner of Canada at priv.gc.ca, or in Quebec the Commission d'accès à l'information; in the EEA, your local supervisory authority; in the UK, the Information Commissioner's Office at ico.org.uk; in California, the California Privacy Protection Agency or the Attorney General.