Effective July 28, 2026
Privacy Policy
Logos is a personal AI wellness and planning assistant. This policy explains what information Logos handles, how it is used, and the choices you have.
Information We Collect
Account information may include your email address, Supabase user identifier, sign-in provider, subscription status, and operational account records. If you choose to subscribe, Stripe handles payment details and provides Logos with billing status, customer identifiers, and receipt-related metadata.
With your permission, the iOS app can read selected Apple Health, Calendar, Reminders, Location, Microphone, and Speech Recognition data. Health, calendar, reminder, speech, and local wellness summaries are used to provide app features you request.
If you connect Gmail, Google Calendar, Google Drive, Slack, or Notion, Logos uses Composio Cloud to manage authorization, access and refresh tokens, and connected-account lifecycle. OAuth tokens remain with Composio. Logos invokes only a fixed set of tools for tasks where you explicitly attach an account, and requires confirmation before sending, creating, or changing external data. Google Drive access is read-only. The iOS app manages connections but does not execute connected-service tools or provide a dedicated Gmail inbox.
How Logos Uses Information
Logos uses information to authenticate your account, run requested assistant features, maintain subscription access, sync supported account data, prevent abuse, debug service issues, and respond to support requests.
Cloud AI And Third-Party Processing
Logos does not send your personal data for Cloud AI processing until you give permission in the app. Before the first send, Logos identifies the information included in the request, names the recipients, and asks you to choose whether to send it.
Depending on the feature you request and the permissions you grant, the information sent may include:
- Your messages and prompts;
- Earlier turns of the same assistant conversation, together with any running summary of it, so that follow-up requests keep their thread. This travels with the request itself and is not governed by the Memory settings below; you can clear it by deleting the conversation;
- HealthKit summary metrics you select;
- Native or connected Google Calendar and Reminders summaries you select;
- Messages, files, metadata, channels, and pages returned from Gmail, Google Drive, Slack, or Notion when you explicitly attach that account to a task;
- Approximate location context when relevant to your request;
- Saved responses, check-ins, or memory facts carried across separate conversations, when Memory is enabled for that area. Memory is off until you turn it on, and can be enabled separately for general chat, health, and planning; and
- Account identifiers and request metadata needed to authenticate, secure, and operate the service.
This information is sent first to the Logos backend and then to OpenAI, our third-party AI processor. OpenAI processes the information to generate the AI response you requested. Logos may also retain operational logs needed to secure, troubleshoot, and maintain the service. These logs exclude connected content, tool arguments, OAuth tokens, and raw connected-account identifiers. Logos does not use this information for advertising, does not sell it, and does not use connected-app data to train or improve generalized AI models.
You can review private context before sending it, allow future sends for selected context types, or decline to send it. You can revoke a previous permission, turn off Cloud AI sharing, or disable Cloud AI at any time in the app's Privacy settings. Turning off Cloud AI prevents new assistant requests and their associated context from being sent to the Logos backend or OpenAI; supported local features remain available.
OpenAI and our other service providers process information only to provide services to Logos and are required by contract to protect it with the same or an equivalent level of privacy protection.
Google API Services Limited Use
Logos's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Logos requests the minimum Google permissions needed for enabled features, uses Google data only for the user-facing feature you requested, and does not transfer it for advertising, creditworthiness, surveillance, or generalized AI model training.
Health And Sensitive Data
Logos uses HealthKit data only to provide user-facing wellness summaries and assistant context. Logos does not use HealthKit data for advertising, marketing, use-based data mining, or sale to data brokers. Logos is not a medical device and does not provide diagnosis, treatment, emergency support, or clinical monitoring.
Sharing
Logos uses service providers for authentication, hosting, connected-app authorization and execution through Composio, payments, email delivery, operational logs, and AI processing. AI processing is provided by OpenAI. Payment processing is provided by Apple In-App Purchase on iOS and by Stripe for web subscriptions. These providers process data so Logos can operate the service and are required to protect that data under terms that provide the same or equal protection. We do not sell personal information.
Retention And Controls
You can export local app data, delete local analysis history, delete local wellness history, reset local state, sign out, and request account deletion from the app. Task inputs, connected-service results, run artifacts, and tool outcomes remain in run history until you delete that history or your account, except for limited security, backup, billing, fraud-prevention, and legal records. OAuth tokens remain with Composio rather than Logos.
Disconnecting an app asks Composio to revoke the provider credential before removing its connected-account record. If a provider does not support programmatic revocation, Logos tells you to finish revocation in that provider's security settings. Account deletion attempts this cleanup before removing Logos account data; a temporary provider failure leaves the account available so deletion can be retried safely. Stripe records may be retained for billing, tax, receipt, dispute, fraud prevention, and compliance obligations.
Children
Logos is not intended for children under 13. If you believe a child has provided personal information, contact us so we can review and delete it where required.
Changes
We may update this policy as Logos changes. The effective date above shows when this policy was last updated.
Contact
Questions or privacy requests can be sent to [email protected].