Privacy Policy
Updated August 5, 2026
Our promise
Sherry is designed as a private assistant. We do not sell personal data, run targeted advertising, or use connected email or financial records for advertising. Sample mode stores the professional desk in the current browser and clearly labels sample records.
Data you choose to provide
Depending on the features you use, Sherry may process account details, conversations, reminders, notification subscriptions, voice transcripts or audio, files, calendar events, email content, relationship notes, meeting briefs, decisions, saved merchant and usual-order preferences, and read-only financial information.
When Assistant memory and automatic memory are enabled, Sherry may save useful, stable details you directly state in chat or in a consented, saved call transcript, such as birthdays, preferences, relationships, and regular work schedules. If you also connect Google, the owner-only Memory screen and a background pass no more than once every 24 hours may scan a small bounded set of sent-email body excerpts and automatically save only exact, explicit, high-confidence, non-sensitive family relationships or month-and-day birthdays. It does not store an entire email or learn from received, quoted, forwarded, undated, ambiguous, or instruction-like email text.
A complete connected Google Calendar sync may also automatically save a month-and-day birthday only from Google's typed birthday record and a recurring office-weekday pattern only from repeated typed office working-location records on the primary calendar. It does not learn from ordinary event titles or descriptions, attendees, links, custom or home locations, invitations, or event instructions, and it discards precise office labels and addresses. Conflicting, incomplete, sparse, sensitive, or oversized evidence is not reconciled. Structured calendar memory may correct an older automatic email or calendar fact, but neither email nor calendar memory can replace a fact you entered, imported, or stated directly.
Credentials, payment and account details, government identifiers, biometric secrets, full birth dates or years, and other sensitive provider details are excluded from automatic provider memory. Other sensitive details stated directly remain inactive until the account owner approves them. Assistant replies, financial and CRM records, arbitrary tool/provider output, and files do not automatically become memory.
Saved checkout links open the merchant's secure site. Sherry does not request or store card numbers, security codes, bank credentials, or the merchant's final payment confirmation.
Live call transcription and transcript storage are off by default. They begin only after you enable the transcript control for that call. Turning the control off stops new transcription and clears Sherry's saved text for that call; the voice provider still processes the audio needed for the live AI conversation.
Connected services are optional. The app requests only the permissions needed for the feature you enable and shows connection status only after the server verifies it.
How data is used
Data is used for app functionality: authenticating you, saving your workspace, answering requests, delivering reminders, preparing user-approved actions, synchronizing connected services, preventing abuse, and maintaining an audit trail. Clear requests can create reversible items in Sherry's calendar directly. External communications, connected-calendar changes, destructive actions, and sensitive actions require explicit approval.
AI processing
When AI is enabled, only the context needed to answer a request is sent to the configured AI provider. Financial queries should use scoped summaries and redact account identifiers. Entire email threads and financial histories are not automatically stored as permanent assistant memories.
Storage and security
User-owned cloud records are isolated by database row-level security. Saved memory content is stored as ordinary database content and is not separately encrypted by the application. Connector tokens are encrypted with a server-only key. Permanent OpenAI, Plaid, connector, and database administrator credentials are never exposed to the browser. Local-first professional desk records remain in browser storage until cloud sync is configured.
Your controls
You can independently turn saved-memory use and automatic memory off, review or edit active memories, approve or reject sensitive proposals, optionally import memories, delete one or all ordinary memories, export your account data, and permanently delete a signed-in account from Settings. Turning a memory switch off does not itself delete existing records. The public Sherry account-deletion page also accepts verified email requests when app access is unavailable. Browser-only sample records can be removed in Sherry or by clearing site data.
Retention and deletion
We retain account data while the account is active and as needed to provide requested features. Delivery and audit records support security and accountability while the account exists. In-app deletion removes active user-owned records immediately after safety checks. Verified email requests are completed within 30 calendar days. Residual copies may remain in encrypted infrastructure backups for up to 30 days during ordinary rotation and are not used to provide the service. A narrowly limited record is retained longer only when law, security, fraud prevention, or dispute resolution requires it, and is deleted when that obligation ends.
Service providers
Configured production deployments use Supabase for authentication and database services, Render for the web application and durable background worker, and OpenAI for enabled AI and voice features. Google provides optional Gmail and Calendar connections and Firebase Cloud Messaging (FCM) for consented Android notifications. Plaid provides optional read-only financial connections. Browser push may also use the browser platform's push service. Vercel is used only by deployments that enable the documented compatibility path. Provider involvement depends on the features you enable.
Contact
Privacy and support questions: willruzycki@gmail.com.