Data Policy
Version 2026-10-08.2 · Famplified LLC · Oklahoma, United States
What we save
We save manually entered and extracted calendar-event information and summaries, reminder schedules and statuses, temporary SMS menu state and delivered-reminder references, verified contact details, settings, consent evidence, integration credentials or credential hashes, source fingerprints for deduplication, and delivery or ingestion outcome metadata. A summary can include names, locations, and other details found in your source; avoid submitting information you do not want included.
What we do not archive
Raw pasted text, API or MCP source text, complete email bodies, and attachments are not retained as application records. Email attachments are ignored. Source text exists in memory during extraction and passes through the necessary transport and AI services. To avoid duplicate reminders, OpenAI also compares incoming event summaries with your stored events for the same date. This is not a promise that no provider temporarily stores content: AWS SNS mail retries can retain an encrypted message for up to 23 days, and AI providers apply their own retention terms. We do not create a raw-email archive or raw-email dead-letter queue.
Retention and deletion
Reminder and account records persist until removed through supported operations or an account deletion request. A minimal phone-hash suppression record is retained to honor SMS opt-outs across contact or account removal; opt-out event receipts have a 90-day expiry. SMS routing and replay metadata have a 90-day expiry and do not contain message bodies. Email intake outcomes have a 30-day expiry; processing deduplication markers have a 90-day expiry; usage reservations have an approximately 93-day expiry. SMS menu choices expire after 15 minutes; menu state and recent-reminder references have a seven-day database expiry to prevent stale replies from being misinterpreted. MCP OAuth grants and refresh-token hashes expire after 30 days; access-token hashes, authorization codes and pending consent records have shorter expiries. OAuth client registrations have a 365-day expiry. Expiry marks eligibility for asynchronous database deletion and is not an instantaneous erasure guarantee. Security logs, backups, and legally necessary records follow configured operational or legal retention. When handling a deletion request, we identify remaining copies, retention exceptions, and relevant provider restrictions rather than promise immediate deletion from every system.
Contact ownership and controls
Every additional email or phone number must complete AWS code verification before reminders can be sent to it. Verification codes are managed by AWS; we do not store the codes. Code requests have cooldowns and daily limits. The app permits up to five additional contacts of each type, in addition to a verified sign-in email. Enabled, verified email destinations may also submit email for extraction when sender authentication passes. Removing a contact prevents its future use; it does not delete messages already delivered to that destination.
Agents and integrations
A user is responsible for authorizing agents and keeping API keys or machine credentials secure. Access is scoped to the account; credentials can be revoked in Settings. User-approved MCP connections use rotating refresh tokens for up to 30 days without another sign-in. Revocation or account restrictions can end access sooner. Agent and API source text follows the same extraction and retention approach as the website. Do not include passwords, private keys, or unrelated personal records in submitted text.
Requests and restrictions
Contact us for a copy of your stored information, corrections, or account deletion. Do not send passwords, verification codes, government identifiers, or other secrets with a request. We may require identity verification and may preserve records required by law or needed to address security incidents.
Contact
Privacy, legal, and support requests: info@email.famplified.com.