Effective August 18, 2026

Privacy Policy

Refractive is designed to know a great deal about you — that is the product, not a side effect. This page is a plain account of what that means in practice: what is stored, where it goes when the agent answers you, and how to take all of it back or erase it.

Refractive is operated by Ordinary Company, LLC(“we”). This policy covers refractive.tech and the Refractive application.

The short version

What we collect

Things you tell us on purpose

Your email address and password (stored hashed, never in readableform) or, if you sign in with Google, your Google account's email address and identifier. Everything you say to the agent by voice or text. Your answers to the onboarding interview. The agent personality settings you choose. Anything you enter in a life domain — health check-ins, reflective sessions, financial figures, career notes, and so on. If you upload a bank or card statement in Finances, the transactions in it.

Things the agent works out

Refractive runs a background pass over conversations to extract structured notes — which life domain something belongs to, recurring themes, values, patterns, people who come up repeatedly. These become your Context Graph and YOU-node profile. They are inferences about you, generated by a model, and they can be wrong. You can read all of them under Profile and in your data export, and correcting the agent in conversation updates them.

Things you connect, only if you connect them

If you connect Google Calendar, we read event times and titles to understand your week. If you connect a contact source, we read names, relationships, and birthdays for the Relationships domain. If you bring your own model API key, we store it encrypted (AES-256-GCM) and decrypt it only in memory, only to make a request on your behalf. None of these are required to use Refractive, and disconnecting one stops the reading immediately.

Things we deliberately do not keep

Voice recordings. Audio is transcribed and the transcript is what gets stored; the audio itself is never written to disk. We do not collect location data, we do not read files on your device, and we have no advertising identifiers because we run no advertising.

Where your words actually go

This is the section most privacy policies bury, so it is near the top here. To answer you, the agent has to send what you said — and the relevant parts of what it remembers about you — to an AI model provider. There is no version of this product where that does not happen.

We do not train models. We have no model of our own to train, and we do not sell or supply your content to anyone for that purpose. On the default path we go further than not doing it ourselves: the no-training, no-retention constraint above is sent with every request, so it binds the company actually running the model and not just us. Where you have connected your own key, what that provider does under its own commercial terms is between you and them — which is the honest limit of what a policy on this domain can promise, and one of the reasons the product is built to run on a key you control.

Worth being precise about why the default path can promise more. Open weights separate two things that are welded together on a closed model: who trained it, and who sees your prompt. Refractive runs models published under open licences on hosts that agree to the terms above — so choosing DeepSeek V4 Pro, GLM-5.2, or Kimi K2.6 is not a statement about trusting whoever trained them. They never see your conversation.

The Emotions & Meaning domain

This one deserves its own paragraph because of what people put in it. Reflective sessions are stored like any other conversation and are included in your export and your deletion. Refractive is not a therapist, not a medical service, and creates no doctor-patient relationship; the domain is not covered by HIPAA and we make no clinical claim about it. Sessions you mark private are excluded from cross-domain context, and you can delete any individual session without deleting your account.

Shared households

A Finances household can have more than one member, and members see the household's income, budgets, and transactions — including statements uploaded by someone else. That is the point of the feature, but it is worth stating plainly before you invite anyone. If you delete your account while another member remains, the household and its records stay with them; ownership passes to the longest-standing remaining member. If you are the only member, the household is deleted with you.

Cookies

One purpose: keeping you signed in. Supabase sets a session cookie when you authenticate and it is read on each request to know who you are. There are no analytics cookies, no advertising cookies, and no third-party tracking pixels anywhere on this site — which is why you have not seen a consent banner.

How long it is kept

For as long as your account exists. Refractive's usefulness comes from memory that accumulates, so nothing expires on a schedule. Deleting your account removes it. Backups taken by our database host before a deletion roll off on that host's own retention schedule, which is measured in days, and are not accessible to us as a way to restore a deleted account.

Your rights, and how to actually use them

Depending on where you live you may have rights of access, portability, correction, and erasure — under the GDPR, the CCPA/CPRA, and comparable laws elsewhere. Rather than asking you to email a request and wait thirty days, both of the ones that matter are buttons:

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

Children

Refractive is not intended for anyone under 18 and we do not knowingly collect information from children. If you believe a child has created an account, write to us and we will delete it.

Security

Data is encrypted in transit. Every table enforces row-level security in the database itself, so one account cannot read another's rows even if the application asks it to. API keys you connect are encrypted at rest with a key the application holds separately. No system is perfectly secure and we will not pretend otherwise; if we ever learn of a breach affecting your data we will tell you.

Changes

If this policy changes in a way that affects what we do with your data, we will update the effective date at the top and note it in the changelog.

Contact

Ordinary Company, LLC chazvandemotter@gmail.com. Privacy questions and requests both go here.