Privacy Policy
Last updated: June 10, 2026
Ounie, a service of TabTab LLC (“we”, “our”, “us”), helps you build a private AI second brain: you add files, links, and notes; we turn them into an interlinked wiki your brain can answer questions from, with citations. This Privacy Policy describes the personal data we collect from or about you, how we use and disclose it, how long we keep it, and the rights and controls you have. It applies to ounie.com and all Ounie services and clients — the web app, the iOS app, the ChatGPT app, the Claude and MCP connectors, the chat bots (Telegram, Slack, Discord, WhatsApp), the e-commerce integrations (Shopify, WordPress), and sites and widgets you publish through Ounie. The Chrome extension has its own focused policy: Extension Privacy Policy.
You are responsible for making sure you have the right to add the content you upload to your brains.
1. Personal data we collect
Data you provide to us:
- Account information: your name, email address, username, password (stored only as a bcrypt hash), plan and transaction history, and an avatar if you upload one.
- Content: the files, links, notes, voice captures, and imports you add to your brains, and what we derive from them to make them answerable — extracted text, transcripts, synthesized wiki pages, vector embeddings, and the knowledge graph. Edits you make to wiki pages and feedback you give on answers are Content too.
- Questions and answers: the questions you ask a brain (from any client) and the answers produced, so you can review history and we can meter plan usage.
- Payment information: payments are handled by Stripe (web) or Apple / RevenueCat (iOS). We store your plan, credit balance, and a ledger of credit transactions. We never see or store full card numbers.
- Communication information: if you contact us (for example through our contact form or by email), we collect your contact details and the contents of your message.
- Connection credentials: if you connect Telegram, Slack, Discord, WhatsApp, Shopify, or WordPress, we store the tokens needed to operate that connection, encrypted at rest (AES-256-GCM).
Data we receive from your use of the services:
- Log data: information your browser or device sends automatically — IP address, browser type and settings, and the date and time of your request.
- Usage data: which features you use and basic activity across the service, used for operating the product, metering plan limits, and preventing abuse.
- Device information: device and operating system type, and app version.
- Approximate location: we may determine the general area you connect from based on your IP address, for security and abuse prevention. We do not collect precise location.
- Cookies and similar technologies: we use a session cookie to keep you signed in (essential), Google Analytics cookies on our marketing and dashboard pages, and a short-lived referral cookie if you arrive through an invite link. Sites and pages you publish through Ounie are served to your visitors without cookies or analytics scripts.
Data we receive from other sources:
- Sign-in providers: if you sign in with Google or Apple, we receive your basic profile and email address. We never see your password for those accounts.
- Platforms you connect: if you connect a chat or e-commerce platform, we receive the content you send through it — for example a link you save from Telegram, or products from a Shopify store you sync.
2. How we use personal data
We use personal data for the following purposes:
- To provide the service: extract text, synthesize wiki pages, build your knowledge graph, embed content for search, and answer questions from your sources, with citations.
- To operate features you turn on: widgets, published sites and landing pages, marketplace listings, auto-research, imports and exports, assets, and connections.
- To administer your account: authentication, plan limits and credits, payments, and receipts.
- To communicate with you: service emails (for example billing or security notices) and responses to your support requests.
- To keep the service safe: prevent fraud, abuse, and unauthorized access, and enforce our terms.
- To improve the service: understand how features are used, debug problems, and develop new features, using operational and aggregated data.
- To comply with legal obligations and protect the rights, safety, and property of our users, Ounie, or others.
We may aggregate or de-identify personal data so it no longer identifies you and use that information for the purposes above; we do not attempt to re-identify it.
We do not sell your personal data, we do not use your content for advertising, and we do not use your content to train AI models — ours or anyone else’s. Your content is processed by AI models only at your direction, to run the feature you invoked.
3. Legal bases for processing
Where laws like the GDPR (EU/EEA and UK) apply, we rely on the following legal bases:
- Performance of a contract: providing the service you signed up for — ingesting your content, answering your questions, operating features you enable.
- Legitimate interests: securing the service, preventing fraud and abuse, debugging, and improving the product.
- Consent: where required — for example analytics cookies — which you can withdraw at any time.
- Legal obligation: tax, accounting, and lawful requests.
4. Disclosure of personal data
We disclose personal data in the following circumstances:
- Vendors and service providers, who process it only on our instructions to run the service:
- Neon — our Postgres database (account data, content, embeddings, usage records).
- Amazon Web Services (S3) — file storage. The bucket is private; files are never publicly addressable.
- Vercel — application hosting and request logs.
- AI model providers (via OpenRouter, and OpenAI for embeddings and audio transcription) — receive only the specific content being processed (a document being synthesized, a question plus the retrieved pages needed to answer it, an audio file being transcribed), only when you use a feature that needs it. These are API integrations; we do not permit content we send to be used to train their models.
- Stripe — payments and subscriptions (web); Apple and RevenueCat — purchases on iOS.
- Google — sign-in (if you choose it) and Google Analytics; Apple — sign-in (if you choose it).
- Exa— if you enable Auto-Research, your research brief queries are sent to Exa’s web search. Your brain content is not.
- Platforms you connect (OpenAI/ChatGPT, Anthropic/Claude, Telegram, Slack, Discord, WhatsApp, Shopify, WordPress): when you use Ounie through another platform, that platform receives the data described in the next section, governed by its own terms and privacy policy. Make sure you understand those policies before connecting.
- People you share with: if you invite someone to a brain, they can see its content and activity per the role you give them. Things you choose to publish are covered in section 6.
- Legal reasons: we may disclose personal data to government authorities or other third parties if required by law, or as necessary in good faith to comply with a legal obligation, protect and defend our rights or property, address fraud or violations of our terms, or protect the safety of our users or the public.
- Business transfers: if we are involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your personal data may be disclosed during diligence and transferred to the successor, who must continue to honor this policy or notify you of changes.
We may also share aggregated or de-identified information that cannot reasonably be used to identify you.
5. Ounie in ChatGPT, Claude, and other AI assistants
The Ounie app for ChatGPT and the Ounie connector for Claude and other MCP clients let an AI assistant read from and save to your brains. You connect by signing in to your Ounie account (OAuth); the assistant holds an access token scoped to your account, which you can revoke at any time in Settings → API keys → Connected apps.
Each tool sends us only what it needs and returns only what it says:
- List brains— input: none. Output: your brains’ names, ids, emoji, and source counts.
- Ask a brain / ask a brain set— input: a brain (or brain set) id and your question. Output: an answer drawn only from that brain’s sources, with citations and links to the cited pages.
- Search — input: a brain id and a search query. Output: matching wiki pages with excerpts.
- Get context — input: a brain id and a topic. Output: the relevant wiki pages so the assistant can answer with your material.
- Add a note / add a link / add to brain — input: the note text, URL, or chat content you ask to save (with optional title and source URL). Output: confirmation that it was saved, and it then goes through the same ingestion as any other source.
Anything a tool returns becomes part of your conversation with that assistant and is handled by its provider (e.g. OpenAI for ChatGPT, Anthropic for Claude) under that provider’s privacy policy. Likewise, content you ask the assistant to save is sent to us by that provider. We receive your questions and the content you save; we do not receive the rest of your conversation.
6. Things you choose to publish
Private brains are visible only to you and people you explicitly invite. Some features publish data, always at your initiative:
- Public brains become readable by anyone with the link and may be indexed by search engines. You can make a brain private again at any time.
- Widgets and Ask-in-bio pages let visitors ask your brain questions. Visitor questions are unauthenticated; we log them for your review and for abuse and quota control.
- Marketplace listings make a brain answerable by paying users and agents.
- Forkable brains let others copy the synthesized wiki layer (never your original files) into their own account.
- Sites and landing pages you publish are public web pages built from the brain content you selected.
7. Retention
We keep personal data only as long as we need it to provide the service, or for legitimate business purposes such as resolving disputes, security, or complying with legal obligations:
- Information we keep until you delete it: your content (sources, wiki pages, embeddings, graph) and ask history are kept until you delete them. Deleting a source, page, or brain removes the content and its derived data from our production systems; database backups expire on a rolling basis within 30 days.
- Information we delete automatically: export archives are short-lived — download links expire quickly and the archive files are swept within hours. Operational logs are retained for no more than 12 months; most are much shorter-lived.
- Information we keep longer for legal or safety reasons: billing and transaction records are kept as long as tax and accounting law requires; we may retain limited records needed to address fraud or abuse, enforce our terms, or comply with a legal obligation, and we keep an audit record of erasure requests to show we honored them.
- Account deletion: deleting your account immediately and irreversibly deactivates it. To have the underlying content fully erased as well, delete your brains first or contact us and we will erase it within 30 days, except records we must keep by law.
In setting retention periods we consider the purpose of processing, the amount and sensitivity of the data, the potential risk of harm from unauthorized use, and the legal requirements we are subject to.
8. Your controls
- Delete any source, page, or brain at any time from the dashboard, and delete your account from Settings.
- Export everything — your brains export as an Obsidian vault, Markdown, or JSON from the dashboard.
- Edit any synthesized wiki page directly; your edits override what the AI wrote.
- Control visibility — brains are private by default; public, widget, marketplace, fork, and site exposure are each separate, reversible switches.
- Revoke access — API keys, connected AI assistants (ChatGPT, Claude), and chat/e-commerce connections can each be disconnected in Settings.
- Keep content verbatim— flag any upload “keep verbatim” and it is stored unchanged, with no AI synthesis applied.
- Unsubscribe from non-essential emails using the link in those emails.
9. Your rights
Depending on where you live (for example the EU/EEA, UK, or a U.S. state with a privacy law), you may have statutory rights to:
- access your personal data and information about how it is processed, often in a portable format;
- correct or update your personal data;
- delete your personal data;
- restrict or object to how we process it;
- withdraw consent where consent is the legal basis; and
- lodge a complaint with your local data protection authority.
The controls in section 8 cover most of these directly. For anything else, reach us through our contact form; we may ask you to verify your identity, and we will respond within 30 days (or the timeframe your local law requires). You will not be treated differently for exercising your rights, and depending on where you live you may have the right to appeal a decision by replying to our response.
A note about accuracy: answers are generated by AI models from your sources and may not always be factually accurate. If an answer contains inaccurate information, you can edit the cited wiki page directly or use the feedback tools to correct it.
International transfers: we are based in the United States and process and store data on servers there and in countries where our service providers operate. We apply the protections in this policy wherever the data is processed, and where the law requires we rely on lawful transfer mechanisms such as standard contractual clauses.
10. Additional U.S. state disclosures
We do not “sell” personal data or “share” it for cross-context behavioral advertising, we do not process personal data for targeted advertising, and we do not process sensitive personal data to infer characteristics about you (as those terms are defined under U.S. state privacy laws). The categories of data we collect, our purposes, our disclosures, and our retention practices are described in sections 1, 2, 4, and 7 above. You can exercise the rights in section 9 directly through the product or by contacting us, including through an authorized agent where your state allows it.
11. Security
We implement technical and organizational measures designed to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. All traffic is encrypted in transit (TLS) and data is encrypted at rest by our storage providers. Connection tokens are additionally encrypted at the application layer; passwords are bcrypt-hashed; API keys are stored only as SHA-256 hashes; files live in a private bucket and are only ever served through access-checked endpoints. No internet transmission is ever fully secure, so take care in deciding what you add.
12. Children
Ounie is not directed at children under 13 (or the higher minimum age in your country), and we do not knowingly collect their personal data. If you believe a child has provided us personal data, let us know through our contact form and we will investigate and delete it where appropriate.
13. Changes to this policy
We may update this policy from time to time. When we do, we will publish the updated version and date on this page, and for material changes we will notify you in the product or by email.
14. Contact us
Ounie is operated by TabTab LLC, a United States company, which is the controller responsible for the personal data described in this policy. Questions, or want to exercise a right not covered by the in-product controls? Use our contact form.