This Privacy Policy explains how Argo (“Argo,” “we,” “us,” or “our”) collects, uses, and protects your information when you use the Argo mobile application and related services (the “Service”). Argo is a private, AI-assisted journaling app. Your journal is among the most personal data a person can keep, and protecting it is central to how the Service is designed.
By using the Service, you agree to this Privacy Policy and to the Terms of Service, which are also included at the end of this page.
1. Information we collect
Account information
When you create an account, we collect the information provided by your chosen sign-in method (for example, Sign in with Apple or Google), which may include a name, email address, or a privacy-relay address. We use this only to authenticate you and operate your account.
Journal content
The Service lets you capture entries as text, voice recordings, video, and photographs (including photos of handwritten pages). This content, along with derived data such as transcripts, summaries, insights, tags, and emotional analysis, is stored so the Service can function and so your AI companion can draw on your history.
Usage and device information
We collect limited technical information needed to run and improve the Service, such as app version, device type, basic diagnostics, crash logs, and feature-usage signals (for example, streak counts and daily word totals). We do not use this to build advertising profiles.
Payment information
Subscriptions and Voice Credit purchases are processed by Apple through the App Store. We do not collect or store your payment-card details; we receive only the transaction and entitlement status needed to unlock features you have purchased.
2. How we use your information
- To provide the core Service — storing your entries and generating transcripts, summaries, insights, prompts, daily insight cards, and conversational replies.
- To maintain features such as your streak, daily 750-word goal, and statistics.
- To authenticate you, operate your account, and provide customer support.
- To keep the Service secure, prevent abuse, and diagnose technical problems.
- To comply with legal obligations.
3. On-device processing & transcription
When you dictate into a text field, speech-to-text runs on your device using Apple's on-device framework, and that audio is not required to leave your device. Optical character recognition (OCR) of handwritten pages is likewise performed on your device.
Voice and video journal entries are handled differently: to produce an accurate transcript, the recording's audio is sent over an encrypted connection to our speech-to-text provider (Deepgram — see Section 6), transcribed to text, and not retained by that provider for other purposes.
4. Encryption
Your entries and associated media are encrypted in transit and at rest. Sensitive text fields are protected with a per-user encryption envelope so that journal content is not stored in plaintext.
5. AI processing
Some features — AI insights, pattern analysis, daily insight cards, emotional analysis, and chat or live-voice conversations — are produced using the third-party AI providers named in Section 6. To generate them, the content a feature needs is sent to those providers over an encrypted connection so they can process it on our behalf.
What is shared is largely up to you. It includes your journal text and, for voice features, your audio — together with the details you chose to provide during onboarding: the name you enter, the biography you write about yourself, and other profile information you add (for example your age, location, work, and interests). You decide how much of this to share — you provide only what you feel comfortable sharing, and you can leave any onboarding field blank. We send a feature only the data it needs, and our providers may use it solely to provide these features to you.
Your journal is never used to train AI models — not ours, and not those of our providers.
Live voice calls — a transient exception
For storage and text features, our servers cannot read your journal: entries are kept encrypted and are only ever decrypted on your device. Live voice calls are the one exception. So that your companion can recall relevant memories from your past entries in real time as you speak, at the start of a call your device sends its encryption key to our server for the duration of that call. The server uses it to decrypt only the specific past entries needed to answer you, holding the key and the decrypted text in memory only. Nothing decrypted during a call is written to disk, logged, or retained, and the key and any decrypted content are wiped from memory when the call ends.
The AI that reasons over those memories runs inside a hardware secure enclave (Morpheus — see Section 6), so the model's inference remains confidential. This transient, in-memory decryption happens only during a live voice call; your stored entries, text features, transcription, and search continue to work without our servers reading your journal.
6. Third-party service providers
We share only what is necessary with a limited set of processors who help us run the Service, each acting under contractual confidentiality and security obligations. These currently include, by category:
- Cloud hosting and database / authentication providers (for example, Google Firebase / Firestore) to store accounts and encrypted data.
- AI model providers (for example, Together AI) to generate insights, summaries, prompts, and conversation.
- Speech-to-text providers (for example, Deepgram) to transcribe your voice and video journal entries into text.
- Live voice-conversation transport (for example, Vapi) — which carries the call audio and uses Deepgram for speech-to-text — to run real-time spoken conversations with your AI companion; your audio is processed to run the call.
- Confidential AI inference for live calls (Morpheus) — a network that runs the conversational model inside a hardware secure enclave (a trusted execution environment). During a live call, the relevant past entries our server transiently decrypts in memory (see Section 5) are sent to this enclave so the model can respond with your memories in context.
- Emotion-analysis providers (for example, Hume AI) used to estimate the emotional tone of an entry.
- Subscription-management providers (for example, RevenueCat) to process purchases and manage your subscription and entitlement status.
- An image provider (for example, Unsplash) used to match a themed photograph to your daily insight card; photographer attribution is shown on the card.
- Apple, for sign-in, subscriptions, and in-app purchases.
We do not sell your personal information, and we do not share your journal content with third parties for their own marketing.
7. Sharing you control
The Service lets you generate a shareable Daily Insights card. Sharing is always initiated by you. Any entry you mark as excluded from sharing is left out of the card and of the insights it summarizes. When you choose to share a card through your device's share sheet, the receiving app or service handles that content under its own terms.
8. Data retention & deletion
We retain your information for as long as your account is active. You can delete individual entries at any time. You can also delete your account, which permanently removes your entries, derived AI data, and media. Some limited records may be retained where required to comply with legal, tax, or security obligations.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise many of these rights directly in the app, or by contacting us at the address below.
10. Children
The Service is not directed to children. You must meet the minimum age required by your jurisdiction and the App Store to use it, and in any case be at least 13 years old (or older where local law requires). We do not knowingly collect personal information from children below the applicable age.
11. Security
We use technical and organizational measures — including encryption and access controls — to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and to limit who can access it.
12. International transfers
Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
13. Open source
The Argo iOS app and backend are publicly available on GitHub. Our privacy practices are not only a promise — much of the implementation can be read and verified in the code.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you in the app.
15. Contact us
Questions about this policy or your data? Email us at konradmgnat@gmail.com.
Terms of Service
These Terms of Service (“Terms”) govern your use of the Argo application and related services (the “Service”). By creating an account or using the Service, you agree to these Terms. If you do not agree, do not use the Service.
1. The Service
Argo is a private, AI-assisted journaling app. It lets you capture entries in text, voice, video, and photos, and provides AI-generated transcripts, summaries, insights, prompts, daily insight cards, and text or live-voice conversation with an AI companion grounded in your own entries. Features may change, improve, or be discontinued over time.
2. Eligibility
You must be at least 13 years old (or older if required by your jurisdiction or the App Store) and able to form a binding contract to use the Service.
3. Your account
You access the Service by signing in through a supported provider. You are responsible for activity under your account and for keeping your sign-in method secure. Notify us promptly of any unauthorized use.
4. Subscriptions, billing & Voice Credits
- The Service is offered as a monthly or annual subscription. Subscriptions are sold and managed through the Apple App Store and are billed to your Apple account.
- Subscriptions renew automatically unless cancelled at least 24 hours before the end of the current period. Manage or cancel your subscription in your App Store account settings.
- Live voice calls are powered by consumable Voice Credits purchased separately. Credits are consumed as you use them and are generally non-refundable once used, except where required by law.
- Prices may change; we will give notice as required. Refunds, where applicable, are handled according to Apple’s policies.
5. Your content & ownership
You own your journal entries and the content you create. You grant us only the limited license needed to host, process, encrypt, transcribe, analyze, and display your content in order to provide the Service to you. We do not claim ownership of your content and we do not use it to train AI models.
6. Acceptable use
You agree not to:
- Use the Service for any unlawful purpose or to upload content you do not have the right to use.
- Attempt to access other users’ data, breach security, or disrupt the Service.
- Reverse engineer or misuse the Service except as permitted by its open-source license.
- Use the Service to harm yourself or others, or in place of emergency or professional help.
7. AI features & no professional advice
AI-generated insights, prompts, summaries, emotional analysis, and conversation are for personal reflection only. They may be inaccurate or incomplete and are not professional, medical, psychological, legal, or financial advice, diagnosis, or treatment. The Service is not a crisis or mental-health service. If you are in distress or in an emergency, contact a qualified professional or your local emergency services.
8. Privacy
Your use of the Service is also governed by our Privacy Policy, which describes how we collect, use, and protect your information.
9. Intellectual property & open source
The Argo name and brand are our property. The application and backend source code are made available on GitHub under their applicable open-source license; your use of that code is governed by that license.
10. Third-party services
The Service relies on third-party providers (such as hosting, authentication, AI, and the App Store). We are not responsible for third-party services, and your use of them may be subject to their own terms.
11. Disclaimers
The Service is provided “as is” and “as available,” without warranties of any kind, whether express or implied, including fitness for a particular purpose and non-infringement, to the fullest extent permitted by law. We do not warrant that the Service will be uninterrupted, error-free, or that AI output will be accurate.
12. Limitation of liability
To the maximum extent permitted by law, Argo and its operators will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of data, profits, or goodwill. Our total liability for any claim relating to the Service will not exceed the amount you paid for the Service in the twelve months before the claim.
13. Indemnification
You agree to indemnify and hold harmless Argo and its operators from claims arising out of your misuse of the Service or violation of these Terms.
14. Termination
You may stop using the Service and delete your account at any time. We may suspend or terminate access if you violate these Terms or to protect the Service. Provisions that by their nature should survive termination will survive.
15. Changes to these Terms
We may update these Terms from time to time. Material changes will be reflected by an updated date and, where appropriate, in-app notice. Continued use after changes take effect constitutes acceptance.
16. Governing law
These Terms are governed by the laws of the operator's principal place of business, without regard to conflict-of-laws rules, except where mandatory local consumer-protection laws apply to you.
17. Contact
Questions about these Terms? Email konradmgnat@gmail.com.