Privacy Policy

Our code of conduct and your pledge to be an upstanding member of the Product.

Privacy Policy & Terms Illustration

1. Introduction & Scope

Fonecue ("Fonecue", "we", "us", or "our") operates the Fonecue Desktop AI Assistant application, our web platform (fonecue.com), developer tools, browser and IDE companion extensions, and related APIs (collectively, the "Services"). We are deeply committed to safeguarding user privacy and data security. This Privacy Policy details how we collect, process, store, transmit, and protect your information across all Fonecue platforms.

2. Our Core Principle: Zero AI Model Training on User Data

We uphold a strict Zero-Training policy: Fonecue does NOT sell your data, nor do we use your private source code, chat prompts, screen captures, OCR-extracted text, voice recordings, or local files to train or fine-tune public foundation AI models. Data transmitted to AI inference gateways is processed strictly to generate real-time responses for your active session and is never repurposed for machine learning model training.

3. Categories of Information We Collect

We collect only the minimum data required to deliver our Services: (a) Account & Identity: Email address, encrypted authentication credentials, active subscription tier, and billing status; (b) Device & Session Metadata: Cryptographically generated device pairing tokens and device identifiers used to manage active connection limits (e.g. 1 device on Free, 3 on Pro, 10 on Max); (c) User Inputs & Prompts: Chat queries, coding prompts, custom instructions, and skill definitions configured by you; (d) Generated Visual Assets: AI-generated images, app icons, and UI mockups stored in secure cloud object storage (AWS S3) associated with your account; (e) Diagnostic & Performance Telemetry: Anonymous crash reports, error stack traces, and OS versions collected via Sentry to diagnose bugs and maintain desktop stability; (f) Network Security & Abuse Prevention: Transient IP addresses and request timestamps processed in volatile cache (Redis) under GDPR Art. 6(1)(f) Legitimate Interest strictly for API rate limiting, DDoS defense, brute-force mitigation, and unauthorized traffic blocking. These security records automatically expire and are never used for marketing or user profiling.

4. Screen Analysis, Local OCR & Ephemeral Vision

Fonecue is designed with privacy-first visual processing: (a) On-Demand Only: Screen snapshots and visual inspections are NEVER recorded continuously or passively in the background. They are initiated exclusively when you press an explicit capture shortcut, click an attachment button, or confirm an OCR command; (b) Local-First Optical Character Recognition: Wherever applicable, text extraction is performed on-device using our embedded offline OCR engine (fonecue-local-engine), preventing raw images from leaving your computer; (c) Ephemeral Vision Reasoning: When complex visual inspection is requested, visual frames are transmitted over encrypted TLS 1.3 channels to our secure inference API, processed solely in volatile memory (RAM), and immediately deleted without persistent archiving.

5. Speech & Audio Processing (Local & Cloud Options)

Fonecue offers hybrid speech recognition: (a) Dictation Mode: When you invoke Fonecue's dictation overlay, audio from your microphone is streamed strictly to convert your spoken words into text prompts; (b) Ephemeral Handling: Both local on-device transcription and optional high-precision cloud speech models process audio ephemerally, deleting the audio stream immediately upon transcription; (c) No Biometrics: We do not store biometric voiceprints, record ambient background audio, or archive raw audio files.

6. Real-Time Web Search & Page Reader Extraction

When you enable real-time web search or request documentation analysis, Fonecue queries privacy-focused search engines and extracts readable webpage text. Search queries are anonymized before transmission and are never linked to your personal profile or browsing history.

7. Local Codebase Indexing, MCP & Tool Permissions

Fonecue includes local workspace AST indexing, terminal execution helpers, and Model Context Protocol (MCP) integrations: (a) Local-Only Indexing: Codebase AST search, file trees, and workspace symbol graphs are processed and indexed locally on your machine; (b) Explicit Authorization: Destructive actions, file modifications, terminal commands, and MCP tool executions require explicit user approval unless you intentionally enable the 'Auto-approve permissions' toggle in Desktop Settings; (c) Strict Scoping: Tools cannot access directories or resources outside the workspace roots you designate.

8. Browser Extensions, IDE Companions & Third-Party Plugin Privacy

Fonecue provides optional companion extensions for web browsers (e.g. Google Chrome, Microsoft Edge Add-ons) and code editors (e.g. Visual Studio Code): (a) Official Extensions: Official Fonecue extensions communicate exclusively with your local desktop Fonecue client over isolated local loopback WebSockets and REST APIs (127.0.0.1). They inspect active DOM elements or code editor diffs strictly upon explicit on-demand user invocation and never harvest, track, or exfiltrate your browsing history, keystrokes, background web activity, or unrequested local files; (b) Third-Party Extensions & External Plugins: You may choose to interface Fonecue with third-party extensions, custom browser addons, IDE plugins, or external Model Context Protocol (MCP) servers. Third-party extensions and plugins are operated by independent developers and are governed entirely by their respective privacy policies. Fonecue does not control, supervise, inspect, or audit third-party extensions and assumes no responsibility or liability for how third-party plugins access, handle, store, or transmit your local data or source code. Users are strongly advised to exercise caution and thoroughly review the permissions, security practices, and source code of any third-party plugin before installing it on their system.

9. Community Skills & Public Marketplace Privacy

When you create, upload, or publish a custom AI skill to the Fonecue Skills Marketplace (or share an unlisted skill via a unique share link), the skill metadata—including title, description, custom instructions, prompts, tags, version changelogs, publisher handle, and uploaded visual assets—is stored in our cloud databases and made accessible to other users: (a) Public by Design: Content published to the Marketplace is publicly viewable. You must NEVER embed private API keys, passwords, personal data, proprietary source code, or confidential credentials into skill definitions, prompt templates, or readme documentation. Fonecue disclaims all liability for confidential data exposed by creators in public or shared skills; (b) Local Execution Isolation: When users install community skills, execution occurs locally within their client environment and is governed by our Zero-Training commitment; (c) Data Exfiltration Prohibition: Community Skills are strictly prohibited from attempting to covertly harvest, log, or transmit user keystrokes, screen data, or personal files to third-party endpoints.

10. Sub-Processors & Third-Party Service Providers

To deliver high-reasoning intelligence, cloud queries are routed to vetted, enterprise-grade AI model providers (such as Anthropic, OpenAI, and Google) and trusted infrastructure providers (Neon for encrypted databases, Amazon Web Services (AWS S3) for generated asset storage, Stripe for PCI-DSS payment processing, and Sentry for error tracking). All interactions are governed by Data Processing Agreements (DPAs) that mandate strict zero-data-retention for training, enterprise confidentiality, and encryption standards.

11. Data Retention & Deletion Schedules

We adhere to strict data minimization schedules: (a) Screen & Voice Buffers: Ephemeral (0 days, deleted immediately after processing); (b) Chat History, Skills & Generated Assets: Retained in your account until you delete them; (c) Diagnostic Logs: Anonymized crash logs in Sentry are automatically purged after 30 to 90 days; (d) Account Deletion: When you request account deletion, all associated cloud data, paired device tokens, and stored preferences are permanently purged from our primary databases within 30 days; (e) Network & Security Cache: Temporary rate-limiting records and automated security defense logs in volatile memory (Redis) expire automatically on a rolling basis strictly as required for active system protection.

12. Security, Encryption & Data Storage

Security is engineered into every layer of Fonecue: (a) In-Transit: All communication between the desktop application, browser extensions, and backend services is encrypted using modern TLS 1.3; (b) At-Rest: Database records, user credentials, and session tokens are encrypted using AES-256; (c) Local Security: Sensitive device pairing keys and local configurations are stored securely within isolated OS application directories.

13. Billing, Payments & Cookies

Payments, subscriptions, and Pay-as-you-go credit billing are processed directly by certified PCI-DSS compliant payment gateways (e.g. Stripe). Fonecue never receives or stores your full credit card number. On our website, cookies are used strictly for session authentication, security verification, and essential site operation.

14. International Data Transfers (GDPR & Global Privacy)

If you access our Services from the European Economic Area (EEA), United Kingdom, or Switzerland, your data may be transferred to and processed in countries outside your jurisdiction. Such transfers are safeguarded under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent levels of data protection.

15. Children's Privacy (COPPA)

Fonecue Services are designed for developers, creators, and professionals. Our Services are not directed to children under the age of 16 (or the applicable legal age in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal information, we will delete it immediately.

16. Your Rights & Privacy Controls (GDPR, CCPA / CPRA)

You maintain full ownership of your data. Under global privacy laws including GDPR and CCPA/CPRA, you have the right to: (a) Request access to and export your personal data; (b) Request correction of inaccurate information; (c) Request complete erasure of your account and associated data; (d) Revoke connected desktop devices instantly via the Web Dashboard; (e) Opt out of telemetry diagnostics in Desktop Settings. To exercise these rights, contact privacy@fonecue.com.

17. Updates & Contact Information

We may update this Privacy Policy periodically to reflect technological, operational, or legal developments. Significant changes will be announced via our website, desktop client notifications, or direct email. For inquiries or data protection requests, please reach us at privacy@fonecue.com or contact@fonecue.com.