Privacy policy

Updated October 9, 2026

Facet is built so that we can’t read your conversations. Your chats, attachments, assistants, prompts, settings and API keys are encrypted on your device before they’re synced, and the key that decrypts them never leaves your devices.

Your prompts go directly from your phone to the AI provider you choose. We don’t run ads, analytics or trackers, and we don’t sell data.

Who this covers

Facet is made by DT Software (“we”, “us”). This policy covers the Facet Android app, the hosted sync service at facet.dtsoftware.io, and this website. If you connect the app to a sync server run by someone else, that server’s operator is responsible for it and their policy applies to the data it holds.

Using Facet without an account

You can use Facet without signing up. In that case your conversations, settings and API keys are stored only on your phone and we receive none of it.

To estimate what each reply costs, the app downloads a public price list of AI models from OpenRouter about once a day. That request contains no account information or content. You can turn it off in Settings.

AI providers

When you send a message, the app sends it — together with the conversation so far, any attachments, and your API key — directly to the provider you selected, such as OpenAI, Anthropic, Google, OpenRouter or an endpoint you configured yourself. Facet’s servers don’t relay or see these requests.

Each provider handles that data under its own privacy policy and terms, including how long it keeps requests and whether it uses them to improve its services. Review the policies of the providers you use.

What the sync service stores

If you create an account, the sync service stores:

We can’t read your encrypted content or API keys. They’re encrypted with AES-256-GCM using a key that is created on your device and is itself protected by your password; the server only ever holds it in encrypted form.

How we use information

We don’t use your data for advertising, we don’t build profiles, and we don’t use your data to train AI models. We don’t send marketing email.

Where the GDPR applies, we process account and sync data to provide the service you signed up for, and we keep security logs on the basis of our legitimate interest in protecting the service and its users.

Sharing

We don’t sell or rent personal data. We share it only with:

Retention and deletion

Security

Traffic to the sync service is encrypted with TLS. Your password never leaves your device: the app derives keys from it with 600,000 rounds of PBKDF2-SHA256 and sends the server only a derived authentication key, which the server hashes again before storing.

Because we can’t decrypt your data, we also can’t recover it for you. If you forget your password, your recovery code restores access. If you lose both, the only option is an email reset, which keeps your account but permanently deletes your encrypted data. On the phone, API keys and your vault key are additionally protected by the Android Keystore, and you can turn on a biometric app lock.

App permissions

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict how we process it. You can export everything and delete your account from the app. For anything else, email us and we’ll respond within 30 days. You can also complain to your local data protection authority.

Children

Facet isn’t intended for children under 13, or under the age of digital consent where you live, and we don’t knowingly collect their data.

International transfers

The sync service may be hosted outside your country. Wherever it runs, your content reaches it already encrypted.

Changes to this policy

We’ll post any changes on this page and update the date at the top. If a change materially affects how we handle your data, we’ll also tell you in the app before it takes effect.

Contact

Questions or requests: privacy@dtsoftware.io.