Tome ("Tome," "we," "us," or "our") provides a voice-journaling application and related services (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use and share it, the choices you have, and how to exercise your rights. By creating an account or otherwise using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
This policy is written to be specific rather than generic: every practice described below reflects what the app actually does, not a boilerplate description of what a journaling app might do.
Contents
- Information we collect
- How we use information
- Our legal basis for processing (EEA/UK users)
- Who we share information with
- AI processing and model providers, in detail
- Voice recordings and sensitive/biometric data
- How we secure your data
- Data retention and deletion
- International data transfers
- Your rights and choices
- California privacy rights (CCPA/CPRA)
- Other U.S. state privacy rights
- EEA, UK, and Swiss users (GDPR)
- Children's privacy
- Cookies and tracking technologies
- Legal and safety disclosures
- Data breach notification
- Third-party links
- Changes to this policy
- Contact us
1. Information we collect
Account information. The email address you sign up with, and — if you use Google Sign-In — the name and email address Google shares with us. Creating an account requires nothing else: no phone number, no birthdate, no physical address.
Content you create. Audio recordings you make, the text they're transcribed into, anything you type directly, photos and files you attach, the people and tags you add, and, on the Storyteller plan, your guided-interview conversations and the chapters written from them. If you import a document you wrote before using Tome, that text is stored the same way as anything recorded in the app.
Usage and billing information. Which plan you're on, how much of your monthly recording and AI allowance you've used, and — if you subscribe — a Stripe customer ID and subscription ID. Tome never receives or stores your card number, expiration date, or CVV; Stripe collects and processes that information directly, under its own privacy policy.
Device and diagnostic information. If you opt in (you're asked once, and can change your answer at any time in Settings), we receive crash reports and technical diagnostics through Firebase Crashlytics: device model, operating system version, app version, and the state of the app at the moment of a crash or error. This never includes your recordings, transcripts, or anything you've written, and nothing is collected here if you decline or opt out.
Information we do not collect. We do not collect precise geolocation, contacts, browsing history outside the app, or any information from other apps on your device. We do not use advertising identifiers, and the Service contains no third-party advertising or tracking SDKs.
2. How we use information
- To provide the Service: storing your entries, transcribing audio, organizing content into titles/tags/people/dates, running guided interviews, and generating chapter drafts.
- To operate your account: authentication, sync across your devices, and enforcing plan limits.
- To process payments and manage subscriptions, through Stripe.
- To maintain and improve the Service's reliability — for example, using opt-in crash reports to find and fix bugs.
- To communicate with you about your account, such as a security notice or a reply to a support request.
- To comply with legal obligations, and to detect, prevent, or address fraud, abuse, or security incidents.
We do not use your journal content, recordings, or transcripts to train any AI model — ours or a third party's — and we do not sell or use your information for advertising, because the Service carries no advertising to begin with.
3. Our legal basis for processing (EEA/UK users)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your information under the following legal bases:
- Performance of a contract — processing your content and account information is necessary to provide the Service you've signed up for.
- Consent — for optional diagnostics/crash reporting, which is off until you affirmatively opt in, and for any other processing where we ask you directly.
- Legitimate interests — for example, maintaining the security and integrity of the Service — balanced against your rights and never used to justify uses you would not reasonably expect.
- Legal obligation — where processing or disclosure is required by law.
4. Who we share information with
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes. We share information only in the following circumstances:
- Service providers ("processors") who perform specific, limited functions on our behalf and under contractual confidentiality and data-protection obligations — listed in detail in Section 5.
- Legal and safety reasons — see Section 16.
- Business transfers — if Tome is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
- With your direction — for example, when you export a story to a Word document, or share a memory with a verified family member inside the app.
5. AI processing and model providers, in detail
Turning a recording into an organized, searchable memory involves more than one step, and different steps are handled by different processors. Each one receives only the specific input its task requires — never your full account, and never more than one step's worth of content at a time:
- OpenAI receives recorded audio and returns a text transcript. It does not receive your account email, other entries, or any content beyond the single recording being transcribed.
- Anthropic (Claude) receives a transcript and returns a title, date, people, tags, and short summary — the automatic organizing Tome performs on every entry.
- Google (Gemini) powers the Storyteller guided interview — both the live voice conversation and follow-up questions — and writes chapter drafts from what you've said. If you import a longer document, Gemini also identifies which periods of your life it covers, working only from short boundary markers we extract server-side, not your full document text (see below).
Under our agreements with each of these providers, none of them may retain your content for their own purposes or use it to train their models. Each processes what it receives solely to return a result to Tome, the same way a courier delivers a sealed package without opening it. Where a provider offers a "zero data retention" or API-data-training-opt-out configuration, we use it.
When you import a document that spans more than one period of your life, our document-segmentation function asks the model only for short structural markers (an era, a title, and the first several words of each section) rather than the full text of each section — our own servers then locate and extract the real text using those markers. This means the model is never asked to reproduce, summarize, or paraphrase your own writing back to you; it only tells us where the sections begin.
Tome's own infrastructure — the database, file storage, and application servers — runs on Google Cloud and Firebase, based in the United States. Stripe processes payments and holds billing information under its own privacy policy, available at stripe.com/privacy.
6. Voice recordings and sensitive/biometric data
Some jurisdictions (including Illinois, Texas, and Washington) regulate "biometric identifiers," which can include voiceprints used to identify a specific person. Tome does not create voiceprints and does not use your recordings for biometric identification or speaker verification. Your audio is used solely to produce a text transcript. We do not match your voice against other recordings, build a biometric profile of you, or use voice data to identify or authenticate you.
Depending on what you choose to record or write about, your content may reveal sensitive information — health, religious beliefs, relationships, or similar — the same way any personal journal might. That information is treated with the same access controls, encryption, and non-disclosure practices as the rest of your content, described throughout this policy. We do not analyze your content to infer sensitive attributes about you for any purpose beyond the organizing features (titles, tags, people, dates) described in Section 2.
7. How we secure your data
Everything sent between the app and Tome's servers travels encrypted — HTTPS for uploads and requests, and a secured WebSocket connection for live voice conversations. Stored data — your database records and uploaded files — is encrypted at rest by Google Cloud's infrastructure. Access to production data is limited to what's necessary to operate and support the Service, and every collection is governed by security rules that scope a request strictly to the account that owns it — one account's data is never readable by another's request, enforced at the database layer, not just in application code.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify you as described in Section 17.
8. Data retention and deletion
Deleting a memory or a story moves it to Trash, where it remains fully recoverable for 30 days before being permanently removed — or you can empty Trash yourself at any time for an immediate, permanent delete.
Deleting your account is immediate, not delayed: every memory, story, person, tag, and attachment, along with the account itself, is permanently removed as soon as you confirm, and any active subscription is cancelled in the same step. There is no waiting period and nothing is held back afterward. You can request this from Settings inside the app, or without installing anything, at tomejournal.com/account.html.
Short of a full account deletion, we retain your content for as long as your account exists, so the Service can keep doing what it's for — being there when you return to a memory months or years later. Billing records may be retained longer where required by tax, accounting, or other legal obligations, limited to what those obligations require.
9. International data transfers
Tome's infrastructure and service providers are based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards — such as standard contractual clauses — for these transfers.
10. Your rights and choices
Regardless of where you live, you can ask to see what Tome holds about you, correct it, export it, or delete it:
- Access and portability — export your written stories to a Word document at any time, directly in the app.
- Correction — edit any entry, story, tag, or person directly in the app at any time.
- Deletion — delete individual items (via Trash) or your entire account (immediate and total), both described in Section 8.
- Withdrawing consent — turn off crash and diagnostic reporting at any time in Settings.
- Objection or restriction — contact us using the details in Section 20 and we will respond within the timeframe required by applicable law.
For anything not self-service in the app, email hello@tome.app. We do not require a formal legal process for a request about your own account, and a person reads and handles it — not a ticket queue.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), gives you specific rights. In the preceding 12 months, we have collected the following categories of personal information, for the purposes described in Section 2: identifiers (email address); customer records (billing status); audio, electronic, and visual information (recordings and attachments you create); and internet or network activity (app usage limited to your own account's diagnostics, if opted in).
- We do not sell or "share" (as that term is defined under the CPRA, including for cross-context behavioral advertising) personal information, and have not done so in the preceding 12 months.
- We do not use or disclose sensitive personal information for any purpose beyond what is necessary to provide the Service you requested.
- You have the right to know what personal information we collect, to request its deletion, to correct inaccurate information, and to non-discrimination for exercising these rights.
- To exercise these rights, use the in-app or web deletion flow in Section 8, or email hello@tome.app. We will verify your request using your account's email address before acting on it.
12. Other U.S. state privacy rights
Residents of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and other states with comprehensive privacy laws have similar rights to those described in Section 11: access, correction, deletion, portability, and opt-out of sale, targeted advertising, and certain profiling. As described throughout this policy, Tome does not sell personal information, does not serve targeted advertising, and does not perform profiling that produces legal or similarly significant effects. To exercise any right available under your state's law, use the deletion flow in Section 8 or contact us using Section 20; we will not charge a fee for a first request in a 12-month period and you may appeal a denial by replying to our response.
13. EEA, UK, and Swiss users (GDPR)
If the General Data Protection Regulation or UK GDPR applies to you, you additionally have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first at hello@tome.app so we can try to resolve your concern directly. Your rights of access, rectification, erasure, restriction, portability, and objection are described in Section 10 and apply in full; we will respond to a verified request within one month, extendable by a further two months for complex requests, as permitted by the GDPR.
14. Children's privacy
Tome is not directed at children and is not intended for anyone under 13 (or the minimum age required by your jurisdiction, if higher). We do not knowingly collect personal information from a child under that age. If we learn that we have, we will delete that account and its data promptly. If you believe a child has provided us with personal information, contact us at hello@tome.app.
15. Cookies and tracking technologies
The Tome mobile app does not use cookies or third-party advertising trackers. Our website (tomejournal.com) uses only the minimum technology necessary for it to function — such as a session token to keep you signed in while managing your account or subscription — and no advertising or cross-site tracking cookies. Because we do not track users across third-party sites over time, "Do Not Track" signals have no additional effect and we do not respond to them differently.
16. Legal and safety disclosures
We may access, preserve, or disclose account or content information if we have a good-faith belief that doing so is reasonably necessary to: comply with a valid legal process (such as a subpoena, court order, or warrant) or applicable law; enforce our terms; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Tome, our users, or the public, as required or permitted by law. We do not disclose the content of your journal or stories voluntarily, and we will notify you of a request for your data unless legally prohibited from doing so or where we believe notice would create a genuine risk of harm.
17. Data breach notification
If we discover a security incident that compromises your personal information in a way that requires notice under applicable law, we will notify affected users without unreasonable delay, through the email address on your account, and take reasonable steps to contain and remediate the incident.
18. Third-party links
The Service may contain links to third-party websites (such as Stripe's checkout pages). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing any information to them.
19. Changes to this policy
We may update this policy from time to time. If a change is material, we will provide notice inside the app or by email before it takes effect, and we will update the "Last updated" date at the top of this page. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
20. Contact us
Questions, requests, or concerns about this policy or your information: email hello@tome.app. A person reads it, not a ticket queue, and we aim to respond within a few business days.