Legal
Privacy Policy
Last updated: 5 September 2026 · Applies to the Softkeel mobile application and softkeel.com
Contents
- The short version
- Who we are
- What stays on your device
- What we hold on our servers
- What is processed when you talk
- Service providers
- Location
- Backups and recovery codes
- Security
- How long we keep things
- Your choices and rights
- Adults only
- Softkeel is not a medical service
- Changes to this policy
- Contact
1. The short version
The personal picture Softkeel builds of your life — the people, places, dates, goals and commitments it learns — is stored only on your own device, in an encrypted database. We do not hold a readable copy of it.
To hold a conversation, what you say has to travel to our servers, which run the model that writes the reply and the voice that speaks it. That is live processing, not filing: we do not store your conversations in our database.
A small amount of information does sit on our servers, because the product cannot work without it — your account identifier and the reminders and alarms you have scheduled. Section 4 lists all of it.
There is one optional extra: a backup of your history, so a lost or replaced phone does not lose it. It is off until you turn it on, it is scrambled on your device before it is sent, and the keys never leave your device — so we hold a file we cannot open. Section 8 explains it, including the part that is not reversible.
We do not sell your information, and we do not use it for advertising.
2. Who we are
Softkeel is built and operated by Stillwork Labs (“we”, “us”). This policy covers the Softkeel mobile application and this website.
For anything in this policy, or to make a request about your information, write to hello@softkeel.com. We are the data controller for the information described here.
3. What stays on your device
Softkeel works by learning about your life. That knowledge is written to an encrypted database on your phone and is not uploaded to us. It includes:
- Facts you tell it about yourself — your circumstances, preferences, how you like to be spoken to.
- People in your life, and what you have said about them.
- Dates that matter to you, such as birthdays and anniversaries.
- Places you have taught it, such as home, work or the gym, including their coordinates and the labels you gave them.
- Tasks, goals and commitments you have made, and whether you have finished them.
- Conversation history held on the device so that Softkeel can follow a thread.
- Your settings, including the voice you chose and how often you want to be checked on.
You can view all of this inside the app, in plain language, and delete any part of it — a single item, one category, or everything — at any time.
4. What we hold on our servers
This is the complete list of what is stored in our systems. It is deliberately small.
| What | Why |
|---|---|
| An account identifier — a random ID for your account, and the account identifier supplied by Google when you sign in. | So your device can be recognised as yours across sign-ins and reinstalls. We receive the Google account identifier and email address associated with the Google account you sign in with. |
| A push notification token for your device. | So a scheduled check-in or alarm can reach your phone. |
| Scheduled events — alarms, reminders and check-ins you have asked for, including their time, repeat pattern and the wording of the message to be spoken. | These are fired by our scheduler at the right moment, so they have to exist on the server. The wording can contain what the reminder is about (for example, “get up for the gym”). |
| An encrypted backup of your Softkeel history, if — and only if — you turn that on. We hold the scrambled file and a note of its size and when it arrived. We do not hold, and never receive, anything that can unscramble it. | So a factory reset, a lost phone or a new phone does not lose everything Softkeel has learned. We keep the last few versions so a bad backup can be stepped back past, and delete all of them when you ask. See section 8. |
| Bug reports you dictate. If you tell Softkeel about a problem, that report is written to our application log so we can fix it. | Product support. These reports are in your own words and may contain whatever context you chose to include, so please avoid putting sensitive details in them. |
| Ordinary operational logs — timestamps, endpoints called, error traces, IP address at the network layer, and the email address of the Google account when you sign in. | Security, diagnosing faults and keeping the service up. We do not write the content of your conversations to these logs. The sign-in line is the only place your email address appears; it is not stored against your account record. |
Our servers and database run on Microsoft Azure in the United States.
5. What is processed when you talk
A single spoken exchange with Softkeel involves three steps, and it is worth being precise about each:
- Your speech becomes text. This is done by the speech recognition built into your Android device, which is provided by Google. Depending on your device and settings this may happen on the device itself or via Google’s servers, under Google’s own privacy policy. Softkeel does not record or keep audio of your voice.
- The text becomes a reply. Your words are sent over an encrypted connection to our servers, together with the relevant context your device has assembled for that moment (for example the task being discussed, or that today is someone’s birthday). This is passed to the language model we run on our own hardware to generate the reply, and then discarded. It is not written to our database, and it is not sent to a third-party AI company.
- The reply becomes speech. The text of Softkeel’s reply goes to the speech synthesiser we run on that same hardware, which returns audio that your phone plays. The audio is not kept.
Because context is assembled on your device and sent only for the request it is needed for, your full history is never uploaded — only the slice relevant to what you are talking about right now, and only for as long as it takes to answer.
6. Service providers
We use a small number of providers to run Softkeel. They process information on our behalf, under contract, and are not permitted to use it for their own purposes:
- Microsoft Azure — hosting, database and infrastructure (United States).
- Google (Firebase) — sign-in, and delivery of push notifications to your device.
- Open-Meteo — weather forecasts. Receives an approximate location or place name only, with no account identifier attached.
The model that writes Softkeel’s replies, the one that decides what is worth remembering, and the voice that speaks them all run on hardware we operate. Your words are not sent to a third-party AI company to be answered. We previously used outside providers for both; we no longer do, and this policy has been corrected to say so.
We do not sell personal information, we do not share it with data brokers, and we do not use it to target advertising.
7. Location
Location is optional and off until you grant permission. When it is on, Softkeel uses your device location to recognise places you have taught it — so it can tell that you have arrived at the gym, or that you are not where you said you would be.
- The places you teach it, and their coordinates, are stored on your device only.
- Approximate location may be sent to our servers when it is needed to answer something you asked for at that moment, such as a local weather forecast.
- We do not build or retain a location history on our servers, and we do not share location with advertisers.
- You can revoke location permission in Android settings at any time, and delete every place Softkeel knows from inside the app. Doing so does not otherwise break the product.
8. Backups and recovery codes
Because your history lives on your device, losing the device would normally lose the history. Softkeel offers two encrypted backups, and you choose which, if either, you want. Both are scrambled on your device, with keys that never leave it.
- Your own copy. Written to a folder you choose. It never passes through our servers, and it needs no account and no network.
- A copy on your account. Off until you turn it on. Once on, your device sends us the scrambled file about once a day so it stays current, and you can turn it off and delete our copy at any time, in the app, in one tap. What we receive is a single opaque file: we do not have the key that opens it, we never receive it, and we cannot ask for it.
Both are protected by a one-time recovery code shown only to you. On the phone that made the backup, neither needs it — the device can unlock its own. On new hardware the code is the only way in.
If you lose that code and no longer have the original device, nobody — including us — can decrypt that backup. That is a deliberate design decision and it is the price of us not being able to read your history. It is not recoverable by support, by a court order, or by us. Write the code down.
9. Security
- The on-device database is encrypted with AES-256, using a key held in your device’s hardware-backed keystore.
- All traffic between the app and our servers uses encrypted HTTPS connections. The app refuses unencrypted connections outright.
- Our server database is not reachable from the public internet without authentication, and secrets are held in a managed key vault rather than in code.
- Access to production systems is limited to the people who operate the service.
No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach affecting your information, we will tell you and the relevant authorities as required by law.
10. How long we keep things
- On-device data lasts as long as you keep it. Uninstalling the app removes it from the device; only your own backup survives.
- Scheduled events are kept while they are pending and for a short period after they fire, so recurring alarms keep working.
- The encrypted backup, if you turned it on, is kept as the most recent few versions, each replaced as new ones arrive. Turning the backup off deletes every version we hold, and so does asking us to delete your account.
- Operational logs are short-lived and rotate automatically.
- When you ask us to delete your account, we remove your server-side records. Backups and logs may take up to 30 days to age out fully.
11. Your choices and rights
Most control is directly in your hands, inside the app:
- See everything Softkeel knows about you, in plain language.
- Delete a single fact, a whole category, or everything it has learned.
- Turn location off, or revoke the permission entirely.
- Change how often it contacts you, or tell it to stop, out loud.
Depending on where you live, you may also have the right to access, correct, export or erase the information we hold, to object to or restrict certain processing, and to complain to your data protection authority. To exercise any of these, email hello@softkeel.com from the address on your account and we will respond within the time the law allows. We will not discriminate against you for making a request.
Note the honest limit: because the personal picture is on your device and not ours, an access or erasure request to us can only cover the small set of records in section 4. Everything else is already yours to read or destroy directly.
12. Adults only
Softkeel is for people aged 18 or over. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a minor has used Softkeel, contact us and we will delete the account.
13. Softkeel is not a medical service
Softkeel is a personal motivation and organisation tool. It does not diagnose, treat, cure or manage any medical or psychological condition, it is not a medical device, and it is not a substitute for care from a qualified professional. Anything it says about habits, routines, food, exercise or wellbeing is general encouragement, not medical advice. If you have a health concern, speak to a professional. In an emergency, contact your local emergency services — Softkeel cannot help you and is not monitored by a human.
14. Changes to this policy
If we change this policy we will update the date at the top, and if the change is significant we will tell you in the app before it takes effect. We will never make a change that moves your on-device personal history onto our servers without asking you first, in plain words.
The encrypted account backup in section 8 is the one thing that could move your history off the device, which is exactly why it ships off and why turning it on is a deliberate act in the app rather than a default we chose for you.
15. Contact
Questions, requests, or something here that does not match what you are seeing in the app: hello@softkeel.com.