Skip to content

Last updated September 2026

Privacy

What SayThis stores, what it refuses to store, and what enforces each of those — because a privacy policy is a claim and an enforcement is a fact.

Nothing is kept, and there is no setting that changes that

There is no retention setting, because there is nothing to retain. SayThis holds no stored conversations, no stored screenshots and no personalisation, whether or not you ever open Settings.

The reply itself is held briefly — long enough that a phone whose signal dropped can retry without being charged twice. After five minutes it is no longer used, and it is deleted on a schedule after that. That buffer does contain what the model wrote, and a reply to “meet me at 42 Maple Street” will name the street, because a reply that avoided it would be useless. What we can tell you is that it does not outlive the request: the row carries an expiry from the moment it is written and a scheduled job removes it.

The conversation itself is not in that buffer, and this is the part worth understanding. Tapping Shorter, Longer or Another sends the conversation again, from your phone, because there is no copy on our side to reuse. That is not an implementation detail — it is what makes “not kept” true rather than a policy sentence.

What is recorded for longer is a usage ledger: who made a request, which model answered, how many tokens it used, how long it took and whether it succeeded. It carries no conversation content. It exists because not keeping your conversations must not also mean losing track of what each request cost: our cost accounting reads it. Only our servers write it, so nothing in the app can add to it or change it.

Nothing is read without an explicit tap

The keyboard never reads while you are typing. Every read happens in response to something you asked for — read this screenshot, use what I copied, write the reply. The clipboard is read only when you tap Paste, never to decide whether to offer pasting.

Secure fields are refused

The reply panel does not appear in password fields or in numeric and phone pads. On Android it also stays out of email address fields and fields an app has marked as not wanting suggestions. The check errs toward refusing: a key that does nothing where it might have worked is a worse feature, but reading a field the app asked us not to help with is a broken promise.

What leaves your phone, and when

  • A message you pasted or typed — the text you supplied, and nothing else on screen. If you also wrote a note about what you want to say, that goes too.
  • A screenshot — usually no image at all, whether it came from the keyboard or from the app. Your phone reads the conversation itself and sends only the text. If the conversation contains a photo somebody sent, that photo is cropped out and only the crop goes; if your phone cannot read the screenshot, the whole image is sent once. On Android, every screenshot is sent whole while your replies are pinned to a language that isn’t written in the Latin alphabet. Never your photo library.
  • An image that does go up — before it goes, the app saves it as a new image, so nothing stored inside the original file goes with it, such as where a photo was taken. Text you share into SayThis is sent as text.
  • Shorter, Longer, Another and Change tone — the conversation again, from your phone, plus the reply being changed. Nothing here kept a copy to reuse.
  • Ordinary typing — nothing leaves the device at all.

Screenshots and photos

Most screenshots never leave your phone. SayThis reads the conversation on the device — Apple’s Vision framework on iPhone, ML Kit on Android — and sends the text, the same way pasting does. Nothing is uploaded, so there is nothing to delete and nothing for a provider to keep.

This is true of the keyboard and of the app alike. A screenshot you share to SayThis, or choose inside it, is read on the phone exactly as one the keyboard picks up is — which was not so at first, and the two halves of the product should not have had two answers to the same question.

On Android, the phone reads only the Latin alphabet, which is the one English, Spanish and French are written in. If you have pinned replies to Chinese, Japanese, Korean, Hindi, Russian or Arabic, Android sends the whole screenshot without trying to read it. Read on the phone, it would come out as timestamps and names, and a reply written to those would be wrong.

An image is sent in two cases. The first is when somebody sent a photo in the conversation: that photo is cropped out of the screenshot and only the crop is sent. The second is when the phone cannot read the screenshot at all — it is not a conversation, the recogniser found nothing, or Android is pinned to a script it cannot read — and then the whole image is sent once. Anything uploaded goes to private storage, is passed to the AI provider inline rather than as a link, and is deleted the moment it has been read. There is no setting that keeps it. A picture of somebody’s conversation is not ours to keep merely because keeping it was convenient.

Who else sees this

SayThis is operated by Superfime LLC. Four companies process data from the app on our behalf, under contract, and none of them is given it to use for their own purposes:

  • Our AI provider — the AI that writes your replies. It receives the conversation text or image you send for a reply. Requests are sent with retention switched off, so it is asked not to keep them either.
  • Supabase — the database, sign-in and file storage behind the app.
  • Sentry — crash reports. A report is a stack trace, the screen it happened on, the build, your account id, and roughly where you are — city at the most precise, worked out from your connection rather than stored as an address. It never contains a screenshot, the rendered contents of the screen, or a message. It also receives errors from this website, into a separate project and described under Analytics below.
  • RevenueCat — subscription status, working with the App Store and Google Play. It sees your account id and what was purchased, never a card number.

Apple and Google process your purchase and, if you use them to sign in, your identity. Their terms govern that.

On Android, the text in a screenshot is read on the phone by Google’s ML Kit. Google’s terms say the image and the words it reads never leave the phone. ML Kit does send Google data about its own use: the phone’s make, model and Android version, the app’s name and version, an identifier for that installation (which Google says is not meant to identify you or the phone), how long a reading took, the image’s format and size, and error codes. Google uses that data to maintain and improve ML Kit and to detect misuse, and does not share it with anyone else. The app has no setting that turns it off.

Consent, and whose data this is

Nothing reaches our AI provider until you have agreed to it. You are asked on a screen of its own during setup, before an account exists and before anything has been sent. Every AI endpoint refuses without a recorded agreement.

The uncomfortable part is worth stating plainly: most of what gets sent is somebody else’s words. A friend who texted you about their divorce never agreed to anything, and you are agreeing on their behalf. A screenshot of a group chat sends everything visible in it, including everyone else in the thread. That is worth a second thought before handing over something told to you in confidence.

You can turn AI processing off at any time in Settings › Privacy, and agree again there later. There is a second switch beside it for the keyboard alone, so the extension that sits over every text field can stay a keyboard while the app still writes replies. Without an agreement, the keyboard still types — only the replies are refused.

Analytics

In the app

Events record what happened, never what was said. Properties are counts, durations, and identifiers only — a database constraint rejects any field named like message content, and both writers drop anything that is not a simple value. Confidence is stored as a bucket rather than a number, because a precise score is a fingerprint of one specific request in a way “high” is not.

No data from the app is used to track you across apps or websites.

On this website

This website is measured by two tools, neither of which the app uses: Google Analytics and Ahrefs Web Analytics. Between them they record which pages are read, approximately where the reader is — city at the most precise, never an address — and what kind of device and browser they used. Neither receives anything from the app: no conversations, no screenshots, no account, and no way to connect a visit here to anything you have replied to.

Google Analytics runs without cookies in the UK, the EEA and Switzerland — nothing is stored on the device and the measurement carries no identifier — which is why this site asks you to accept nothing. Everywhere else it sets its own cookie so that a second visit counts as a second visit rather than a new person. Google’s advertising features are switched off on the property, so none of this follows anyone to another site.

Ahrefs Web Analytics sets no cookie at all — anywhere, for anyone. Ahrefs works out a country and city from the IP address and then discards it, never storing it in their database or their logs, and counts a returning reader with a hash of a salt they throw away every twenty-four hours. Nothing it records follows anyone to another site, another device, or another day. It is here to show which pages are worth writing, including the ones AI assistants send people to.

Google publishes a browser add-on that opts you out of Google Analytics here and on every other site that uses it.

When a page here fails to load, the error is reported to Sentry, into a project of its own rather than the app’s. A report is a stack trace, which browser rendered the page, and the page’s address with everything after a question mark or a hash removed. It carries nothing you typed and no recording of the page — session replay is not installed. Your IP address is not stored, though Sentry does derive an approximate location from it, city at the most precise, the same way the analytics above do. That trimming of the address is the part that matters: the links in confirmation and password-reset emails carry a one-time token in the address, and it is cut off before anything leaves your browser.

Your controls

  • Export — everything held for your account, as JSON. It is short, because there is little to hold.
  • Delete account — removes your sign-in and everything attached to it, immediately and permanently.

There is no “delete my conversations” button, because there are no conversations to delete. A control you have to find and press is a worse promise than never having kept the thing in the first place.

Children

SayThis is not directed at children. We do not knowingly collect data from anyone under 13, and you must be old enough to enter into a contract to hold an account.

Contact

SayThis is operated by Superfime LLC, which is the controller of the data described here. Questions about any of it, including a request to see, correct or delete what we hold: support@getsaythis.com.