Privacy Policy
What SaysMee collects, why it is used, and the choices available to you.
Updated 11 August 2026 · 12 min read
Who is responsible for your data
Twenty4 operates SaysMee and is responsible for the personal data described in this policy. Questions and requests can be sent to support@saysmee.com. Do not send passwords, API keys, or sensitive chat content by email.
Data SaysMee processes
- Account data: email address, display name, avatar, authentication identifiers, and account timestamps.
- Conversation data: prompts, model responses, conversation titles, feedback, model choice, and timestamps.
- Files and projects: uploaded files, extracted text, project instructions, file metadata, and storage references.
- Optional personalization: memories, preferences, education profile fields, notification settings, and family-link settings you choose to configure.
- Technical and security data: IP-derived request information, browser or device signals available in server logs, rate-limit state, errors, and security events.
- Analytics and attribution: privacy-friendly page measurement, content-free product events when enabled, consent choices, and sanitized UTM campaign values after Marketing consent.
- Communications: contact-form messages, support emails, and delivery status for requested notifications.
Why SaysMee processes data
- to authenticate you and provide chats, files, projects, memory, notifications, and other requested features;
- to maintain continuity, recover from errors, enforce limits, and secure accounts and infrastructure;
- to respond to support, privacy, legal, and safety requests;
- to comply with law and enforce the Terms and AI Usage Policy; and
- to improve reliability using feedback and privacy-minimized operational information.
Depending on applicable law, processing may rely on performance of a contract, consent, compliance with legal obligations, protection of vital interests, or legitimate interests such as security and service improvement. Where consent is required, you may withdraw it, although earlier lawful processing is unaffected.
AI providers and other processors
SaysMee sends the minimum context needed for a requested feature to relevant service providers. These may include Supabase for authentication, database, and storage; Groq and Google for model processing; Tavily for web search; Resend for email; and the hosting provider for application delivery. Provider availability and use can vary by feature. Their processing is governed by applicable contracts and provider terms; do not assume a provider retains no data unless its current terms expressly say so.
We do not sell personal data or use private conversation text for targeted advertising.
Analytics and cookie choices
SaysMee uses Vercel Web Analytics for cookie-free page measurement. It may report aggregate page, referrer, browser, device, and broad regional information where available. Private prompts, responses, files, memory text, passwords, email addresses, and API keys are not included in product analytics events.
Optional product events require Analytics consent. Sanitized campaign attribution is retained only after Marketing consent. Essential authentication and security technologies remain active because account features cannot operate without them. You can change optional choices in Settings → Privacy & data → Cookie preferences. See the Cookie Policy for category details and the current consent version behavior.
How abusive or unsafe requests are stored
In a saved chat, the original user message is already part of conversation history. SaysMee does not create a second raw copy in the moderation table. If a rules-based safety check triggers, SaysMee may store a restricted safety event containing the account and conversation reference, category, severity, action taken, detector version, a SHA-256 content hash, and a short excerpt with common identifiers redacted. This supports abuse prevention, debugging, appeals, and lawful review while reducing duplication of harmful content.
- Low or medium safety events expire after 90 days; high or urgent events expire after 180 days unless law requires preservation.
- Guest and temporary chats do not create SaysMee conversation history, memory, or this safety-event record.
- Temporary or guest content is still processed in memory and by the selected AI provider to produce the response, and ordinary infrastructure security logs may exist.
- Safety detection is imperfect. A flag is not proof of wrongdoing and does not automatically create a report to parents, schools, police, or emergency services.
See the Safety & Moderation Policy for the response process.
Education and community trends
When an eligible student opts in, SaysMee may record a fixed topic category and broad grade band for community-wide learning insights. The trend event uses a pseudonymous daily fingerprint and excludes the prompt, response, name, email, school, class, conversation, and wellbeing data. A topic is not shown until the configured privacy threshold is met. This feature remains disabled for minor profiles unless the separate minor-account and reviewed-consent controls are enabled.
Temporary chats, memory, and sharing
- Normal signed-in chats are stored until you delete them or your account, subject to legal preservation requirements.
- Temporary chats do not create normal conversation history or memories in SaysMee's database.
- Memory is optional and can be reviewed or cleared in settings.
- A conversation becomes accessible by link only when you choose to create a share link. Anyone with that link may be able to read the shared content until access is revoked.
Retention and deletion
Account records, chats, projects, files, and preferences are generally retained while your account is active or until you delete them. Account deletion removes active records and stored files through SaysMee's deletion flow. Residual copies may remain temporarily in provider backups, security logs, or records that must be preserved by law, and are removed or isolated according to provider schedules and applicable requirements. Aggregated information that no longer identifies a person may be retained for service measurement.
Children and students
SaysMee's current public-launch configuration does not open student enrollment to people under 18. Where a user is a child under applicable law, a parent, guardian, or authorized institution must provide any consent required by that law before personal data is collected. Age assurance and guardian flows require jurisdiction-specific review before SaysMee is promoted to minors. If you believe a child used SaysMee without valid permission, contact us so the account and data can be reviewed and deleted.
Your choices and rights
You can update profile information, delete conversations and files, clear memory, change notifications, revoke shares, or delete your account from the Service. Depending on where you live, you may also have rights to access, correct, complete, erase, restrict, object to, or obtain a portable copy of personal data, withdraw consent, and complain to a regulator.
Send a request from the account email to support@saysmee.com. We may need to verify identity and will respond within the period required by applicable law. If a request cannot be completed, we will explain why where permitted.
Security, transfers, and changes
We use access controls, row-level database policies, restricted server credentials, input validation, rate limiting, and transport security provided by our hosting stack. No system is perfectly secure. Providers may process data in other countries; where required, we use an available lawful transfer mechanism and contractual protection.
We may update this policy as the product, providers, or law changes. Material changes will be communicated through the Service or email when appropriate. The updated date above identifies the current version.
