Privacy policy
Updated October 9, 2026
Facet is built so that we can’t read your conversations. Your chats, attachments, assistants, prompts, settings and API keys are encrypted on your device before they’re synced, and the key that decrypts them never leaves your devices.
Your prompts go directly from your phone to the AI provider you choose. We don’t run ads, analytics or trackers, and we don’t sell data.
Who this covers
Facet is made by DT Software (“we”, “us”). This policy covers the Facet Android app, the hosted sync service at facet.dtsoftware.io, and this website. If you connect the app to a sync server run by someone else, that server’s operator is responsible for it and their policy applies to the data it holds.
Using Facet without an account
You can use Facet without signing up. In that case your conversations, settings and API keys are stored only on your phone and we receive none of it.
To estimate what each reply costs, the app downloads a public price list of AI models from OpenRouter about once a day. That request contains no account information or content. You can turn it off in Settings.
AI providers
When you send a message, the app sends it — together with the conversation so far, any attachments, and your API key — directly to the provider you selected, such as OpenAI, Anthropic, Google, OpenRouter or an endpoint you configured yourself. Facet’s servers don’t relay or see these requests.
Each provider handles that data under its own privacy policy and terms, including how long it keeps requests and whether it uses them to improve its services. Review the policies of the providers you use.
What the sync service stores
If you create an account, the sync service stores:
- Account details: your email address and when the account was created. Your display name, if you set one, is stored inside your encrypted settings, not in plain text.
- Sign-in data: the parameters used to derive keys from your password (a random salt and an iteration count), a hash of a key derived from your password, and your vault key in encrypted form (plus a second encrypted copy that only your recovery code can unlock). We never receive your password or your recovery code.
- Encrypted content: your conversations, messages, attachments, assistants, saved prompts, settings and API keys, stored as ciphertext. Each item is stored under a random-looking identifier with its size rounded up to hide its exact length, the time it last changed, and a sequence number used for syncing. We can’t tell whether an item is a message, a chat, a file or a setting.
- Sessions: for each signed-in device, its name and platform (for example “Pixel 9, Android”), its IP address, and when it signed in and was last active.
- Server logs: IP address, time, requested path and response status for each request, used to keep the service secure and to fix problems.
We can’t read your encrypted content or API keys. They’re encrypted with AES-256-GCM using a key that is created on your device and is itself protected by your password; the server only ever holds it in encrypted form.
How we use information
- To provide sync: storing your encrypted data and delivering it to your signed-in devices.
- To sign you in, keep your account secure, and limit abuse (for example, rate-limiting repeated sign-in attempts).
- To send emails you ask for, such as a password-reset code, when email is enabled on the server.
- To answer you when you contact us.
We don’t use your data for advertising, we don’t build profiles, and we don’t use your data to train AI models. We don’t send marketing email.
Where the GDPR applies, we process account and sync data to provide the service you signed up for, and we keep security logs on the basis of our legitimate interest in protecting the service and its users.
Sharing
We don’t sell or rent personal data. We share it only with:
- the infrastructure provider that hosts the sync service, and an email delivery provider if email is enabled, each acting on our instructions;
- authorities, when the law requires it. We can only hand over what we hold — encrypted content stays encrypted, because we don’t have the key.
Retention and deletion
- Account and sync data is kept while your account exists.
- When you delete an item, a small encrypted placeholder is kept for up to 180 days so your other devices learn about the deletion, then it’s purged.
- Sessions that haven’t been used for 90 days expire and are removed.
- Server logs are kept for up to 14 days.
- Deleting your account (in the app: Settings → Account → Delete account) removes your account, sessions, encrypted items and attachments from the live service immediately. Copies in backups are overwritten within 14 days.
Security
Traffic to the sync service is encrypted with TLS. Your password never leaves your device: the app derives keys from it with 600,000 rounds of PBKDF2-SHA256 and sends the server only a derived authentication key, which the server hashes again before storing.
Because we can’t decrypt your data, we also can’t recover it for you. If you forget your password, your recovery code restores access. If you lose both, the only option is an email reset, which keeps your account but permanently deletes your encrypted data. On the phone, API keys and your vault key are additionally protected by the Android Keystore, and you can turn on a biometric app lock.
App permissions
- Microphone — only when you use voice input. Speech is converted to text by your phone’s speech recognition service, which may process audio under its own provider’s terms.
- Camera and photos — only when you attach an image.
- Notifications — to tell you when a reply finished while the app was in the background.
- Biometrics — handled entirely by Android for the optional app lock. We never receive biometric data.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict how we process it. You can export everything and delete your account from the app. For anything else, email us and we’ll respond within 30 days. You can also complain to your local data protection authority.
Children
Facet isn’t intended for children under 13, or under the age of digital consent where you live, and we don’t knowingly collect their data.
International transfers
The sync service may be hosted outside your country. Wherever it runs, your content reaches it already encrypted.
Changes to this policy
We’ll post any changes on this page and update the date at the top. If a change materially affects how we handle your data, we’ll also tell you in the app before it takes effect.
Contact
Questions or requests: privacy@dtsoftware.io.