SENTIENT
How It WorksSentient AISentient HelpPricingFor BusinessesCompanyBlogFAQContact
Home →

LEGAL

Privacy Policy

Effective September 25, 2026. This Privacy Policy explains how Sentient Digital, Inc. ("Sentient," "we," "us," or "our") handles information in connection with our websites, applications, business services, and related features (collectively, the "Services").

ON THIS PAGE

ScopeInformation we collectHow we use informationSentient AIHow information is sharedRetentionSecurityYour choicesChildrenAge eligibility and guardian linkingChangesContact

1. Scope

This Policy applies to information Sentient processes when you visit getsentient.io, use a Sentient consumer application, interact with a verified organization through Sentient, use Sentient AI features, submit a business application or demo request, contact us, or otherwise use the Services.

Third-party websites, applications, communications services, and other products that you may use before sending information to Sentient are governed by their own privacy practices. This Policy does not control those third parties.

2. Information we collect

Information you provide

Depending on the feature you use, you may provide account information, profile information, age or date-of-birth information, recovery-related information, contact or support submissions, business application information, demo requests, messages or attachments, and information you choose to submit for Sentient AI analysis.

Communications and service activity

The Services may process information needed to deliver messaging, calling, callback, business communication, attachment, read-state, assignment, notification, and account-management functionality. Depending on the feature, this can include participants, timestamps, delivery information, call or conversation status, and other service metadata.

Account, authentication, and recovery information

When the app first connects to our backend, it creates an anonymous authentication session with a random identifier so the app can communicate with our services. This happens before you create an account or enter any personal information. When you create an account, that session is associated with your account, and Sentient creates account and device-credential identifiers for it. An anonymous session that is never associated with an account does not contain your name or date of birth. Sentient does not currently apply a fixed automatic deletion period to those sessions. Your recovery PIN and recovery phrase are used to recover your account. They are sent to us over an encrypted connection when you set or use them, and we store them on our servers only as one-way hashes, not in readable form. Keep them somewhere safe.

Device, security, and technical information

We process device and account-security information needed to operate and protect the Services. This includes identifiers that Sentient generates for your account and for each device you use (such as a device-credential identifier and an installation identifier used for trusted devices and account security); an identifier provided by your device's operating system, described under "Device recognition" below; your device's platform (iOS or Android); push-notification tokens and related app-installation identifiers issued by the notification services described below; the IP address and technical request information that our servers and infrastructure providers receive when your device connects; and service logs used to secure and troubleshoot the Services. This information is used for authentication, trusted-device management, fraud prevention, and abuse detection.

Device recognition

To keep one trusted Sentient identity per device, recognize a device after the app is reinstalled, and help prevent account takeover and abuse, the app uses two identifiers: an installation identifier that Sentient generates and keeps in your device's secure storage, and an identifier provided by your device's operating system. On Android this is the Android ID (ANDROID_ID), which is specific to the app, the user, and the device. On iOS it is the identifier for vendor (IDFV). These are sent to Sentient over an encrypted connection, including before you create an account, when the app checks whether the device is already linked to a Sentient account.

Sentient stores the operating-system identifier only as a one-way hash. The installation identifier is stored with your device credential and, as a one-way hash, in Sentient's trusted-device records. Records of pre-account checks are pruned once they are older than two days. Trusted-device records are kept while the device is linked to your account and are deleted when the account is permanently deleted. These are not advertising identifiers. Sentient does not use them for advertising or to track you across other companies' apps or websites.

Device integrity checks

Sentient may use platform integrity services, namely Google Play Integrity on Android and Apple App Attest on iOS, to help confirm that requests come from a genuine, unmodified copy of the Sentient app on a genuine device. These checks are used for security, fraud and abuse prevention, and to strengthen device recognition. When a check runs, your device communicates with Google or Apple under their own terms, and Sentient receives a signed result.

From each result Sentient keeps a short summary. It records the platform and service used, whether the check passed, the integrity level, and, for Play Integrity, the coarse labels Google returns: device and app recognition, app-licensing status, app version, Play Protect status, and whether apps that could capture the screen or control the device were detected, without the names of those apps. Sentient also keeps one-way hashes of the installation and device identifiers the check was tied to, and a one-way hash of the result token so the same token cannot be reused. It does not keep the raw token. For App Attest, Sentient also stores the public key that your device generated for Sentient. Sentient's systems prune one-time check challenges older than 2 days, result summaries older than 90 days, and App Attest keys that were never linked to an account after 7 days. Remaining records are deleted when the account is permanently deleted.

Camera, microphone, and calling

Camera. Sentient uses the camera only to scan QR codes, for example to add a contact, link a parent or guardian to a dependent, or sign in to a business account. The camera image is processed on your device to read the code and is not saved or uploaded; only the information encoded in the QR code is sent to Sentient to complete the action you requested. The current version of Sentient does not offer video calling and does not use the camera for calls. Sentient does not take photos or video with your camera; when you send a photo or file, you choose it from your device.

Microphone and calling. Sentient asks for microphone access for voice calls. During a call, your voice is transmitted to the other participant as audio using WebRTC. To help calls connect across different networks, Sentient uses connectivity services, including Cloudflare's TURN relay service and, as a fallback, a Google STUN server. These services, and the other participant's device, may receive network information such as your IP address as part of establishing and carrying the call. Sentient also processes call signaling and call-history information (such as who called whom, when, and the call's status) to route and display calls.

Connection metadata processed by relay infrastructure such as Cloudflare's TURN service may include client IP addresses, network port information, and session timing or other connection metadata needed to relay call traffic. The call media relayed this way is encrypted WebRTC traffic, and a TURN relay forwards it without being able to decrypt it.

Push notifications

To deliver message, call, missed-call, and contact-request notifications, Sentient uses push-notification services, including Expo's push notification service, Google Firebase Cloud Messaging on Android, and Apple's push notification service on iOS. Sentient stores push tokens and related app-installation identifiers issued by these services, together with your platform, so notifications can be sent to your device, and shares them with those services as needed to deliver notifications. Some notifications include the sender's name; for example, a new-message notification shows who it is from, along with a generic line rather than the message text. On Android, the Google Firebase Cloud Messaging components that support push delivery are part of the app and may create an app-installation identifier when the app starts, including before you create an account. You can turn notifications off in your device settings.

Firebase Cloud Messaging uses app-installation identifiers to direct a notification to the correct installation of the app. To provide push delivery, Google may process those identifiers, push registration information or tokens, app and device information associated with notification delivery, and notification-routing and delivery information. Expo may likewise process and store the push tokens needed to route notifications, and processes notification payloads as necessary to deliver them. According to Expo's documentation, notification contents are not stored in Expo's databases as part of normal push delivery, although they may be visible to the provider during active troubleshooting.

Encryption and conversation reports

Message content and attachments in ordinary one-to-one conversations are end-to-end encrypted in the normal service flow, so Sentient's servers are designed to store and relay them in encrypted form. This does not apply to information that is not part of an encrypted conversation, such as profile information, private contact notes, account and contact records, and service information like participants and timestamps, or to content you choose to share with us directly.

If you choose to report a conversation, the app may decrypt the available conversation content and attachments on your device and send copies to Sentient for moderation review, including messages from the other participant, so that reviewers can see what was reported. This happens only when you submit a report, and the reporting screen tells you what will be submitted.

Website and business-service information

If you contact Sentient, request a demo, apply for a business account, or use a business-facing service, we may process the information contained in those submissions and information needed to administer the relevant organization, departments, users, permissions, conversations, callbacks, calls, audit activity, and support requests.

Our website (getsentient.io) loads fonts from Google Fonts, so when you visit, your browser may request font files from Google, which receives standard request information such as your IP address and browser details. Some website features use your browser's local or session storage on your device. For example, the Sentient AI chat pages keep chat history in your browser's local storage until you clear it, and signed-in business users' session information is kept in session storage for the browser session.

3. How we use information

We may use information to:

  • provide, maintain, and improve the Services;
  • create and administer accounts, trusted devices, contacts, and business relationships;
  • route and deliver messages, calls, callbacks, attachments, notifications, and other requested communications;
  • authenticate users and devices and help detect fraud, abuse, compromise, or unauthorized activity;
  • operate business-account, support, registry, and administrative functionality;
  • respond to questions, applications, requests, and support matters;
  • analyze information you intentionally submit to Sentient AI features;
  • debug, secure, monitor, and evaluate the performance and reliability of the Services;
  • comply with applicable law, enforce our terms, and protect users, Sentient, and others; and
  • carry out other purposes that we describe when information is collected or that you direct us to perform.

4. Sentient AI and submitted content

Sentient AI features are designed to let users intentionally submit content such as recorded audio, recorded video, screenshots, or imported conversations for analysis. That content may contain personal information about you or other people.

We process submitted content and related technical information as needed to provide the requested analysis, maintain security and reliability, prevent abuse, and support the feature. Analysis may evaluate signals associated with synthetic or manipulated media and language or conversational patterns associated with fraud, scams, phishing, impersonation, or social engineering.

Do not submit content that you do not have the right or lawful authority to provide. Avoid including unrelated passwords, authentication codes, financial credentials, identity documents, or other sensitive information that is not necessary for the analysis.

When you submit content to Sentient AI, Sentient Help, or the Deepfake Detector, the text you enter and any images, videos, documents, or other files you provide are sent through Sentient's backend services and may be processed by AI-model and retrieval services operated by Sentient or by third-party service providers to perform your request. For questions that need current information, search terms drawn from your question may also be sent to public search and reference services, such as web search engines and Wikipedia, and the results may be used in the answer. These features are general-purpose tools and are not specifically designed for children.

Important: AI analysis is probabilistic. A result may be incomplete or incorrect and should not be treated as definitive proof that a person, communication, account, or piece of media is authentic, fraudulent, synthetic, or manipulated.

5. How information may be shared

We may disclose information in the following circumstances:

  • At your direction. For example, when you communicate with another user or organization or otherwise ask us to transmit information.
  • Service providers. We may use vendors and infrastructure providers to help host, secure, deliver, support, or operate the Services. They may process information for the services they provide to us. These include Supabase (backend hosting, database, authentication, file storage, and server functions); Cloudflare (call relay and related network services); Google (a STUN server for call connectivity, Firebase Cloud Messaging, Play Integrity, and Google Fonts on our website); Apple (push notifications and App Attest); Expo (push notification delivery); and the AI and search services described in Section 4.
  • Business and organization accounts. Information you send to an organization through Sentient may be available to authorized users of that organization according to its permissions and workflows.
  • Legal, safety, and integrity purposes. We may preserve or disclose information when we reasonably believe doing so is required by law or necessary to protect rights, safety, security, prevent fraud or abuse, investigate misuse, or enforce applicable agreements.
  • Corporate transactions. Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable law.

Sentient does not sell personal information and does not share personal information for cross-context behavioral advertising. This includes the personal information of users under 16. Sentient does not show third-party advertising. The app does not include advertising or behavioral-analytics SDKs, and it does not collect advertising identifiers, precise location, your device's address book, or biometric identifiers. Contacts are added only through Sentient's own pairing features.

If our practices materially change, we will update this Policy and provide additional notice when required.

6. Data retention

We retain information for as long as reasonably necessary for the purpose for which it was collected, to provide and secure the Services, to comply with legal obligations, to resolve disputes, and to enforce agreements. Different categories of information may have different retention periods because the operational, security, and legal reasons for keeping them differ.

Specific periods that currently apply:

  • Account deletion in the app. The account is deactivated immediately. You can cancel within 30 days by signing back in with your recovery information. After 30 days, the account is permanently deleted. That removes the data Sentient holds for it, including profile information, contacts, messages and attachments stored by Sentient, device credentials, push tokens, keys, recovery information, and trusted-device records, except as described in this list. A placeholder record with a random identifier, labelled "Deleted Account," remains so that other people's conversation history and required safety records stay consistent. Copies already delivered to other people's devices may remain on those devices.
  • Safety and moderation records. Reports, warnings, restrictions, and moderation actions involving a deleted account are kept, linked only to the placeholder record. Reported content is kept as evidence only while the report is open or supports an active restriction. If a suspension or permanent disable was in force when the account was deleted, Sentient keeps a one-way hash of the device's installation identifier while that restriction would have applied, or indefinitely for a permanent disable, so that deleting an account cannot be used to evade it.
  • Deletion requests made on our website. The identifying details in a request are cleared 30 days after the request is closed, or when the account is permanently deleted if that happens first. A record of the request's type, status, and dates is kept. Optional feedback and any follow-up contact details given with an account-deletion request are deleted at the same time. The hashed rate-limiting identifier is kept for 24 hours.
  • Under-13 sign-up block. This is kept only on the device, for 72 hours (see Section 9).
  • Pending guardian sign-ups (ages 13 to 17). The name and date of birth are deleted from Sentient's servers when the linking window ends. That is 24 hours after linking starts or, if a guardian has approved but the account has not yet been created, 24 hours after approval. The remaining session record, which contains no name or date of birth, is deleted within about three more days (see Section 9A).
  • Device recognition and integrity checks. These follow the periods described in Section 2.
  • Service providers. Providers such as Supabase, Cloudflare, Google, Apple, and Expo keep their own operational records, such as request, delivery, and security logs, under their own retention schedules, which Sentient does not control.

Some features may be designed to remove or reduce server-side content after delivery or completion of a workflow. Where a product interface gives you a deletion or retention control, the behavior described in that interface applies to that feature, subject to technical, security, backup, fraud-prevention, and legal requirements.

7. Security

Sentient uses administrative, technical, and organizational measures intended to protect information against unauthorized access, loss, misuse, or alteration. Security measures vary by the nature of the information and feature and may include access controls, encryption, device security features, authentication protections, logging, monitoring, and other safeguards. For example, database access rules are designed to limit the app to the information your signed-in account needs, and the public key built into the app cannot be used to read other people's profiles, dates of birth, or device records. Changes to your date of birth or account status are made only by Sentient's backend processes.

No system can guarantee absolute security. You are responsible for protecting your devices, recovery information, credentials, and other information used to access your account.

8. Your choices and requests

Depending on the Services available to you and applicable law, you can:

  • review and change certain profile information and settings in the app, such as whether your date of birth is shown on your profile;
  • manage trusted devices and device-level permissions;
  • delete messages, attachments, contacts, and saved organizations where the app provides those controls;
  • delete your account in the app under Settings > Account > Delete account. The account is deactivated immediately and permanently deleted after 30 days, and you can cancel by signing back in during that period;
  • if you cannot use the app, request deletion of your account or of specific data through the forms on our website (getsentient.io/delete-account and getsentient.io/delete-data); and
  • ask to access or correct your information, or make another privacy request, by contacting Sentient as described in Section 11.

Sentient does not currently offer an automated tool to download or export your data. Access and correction requests are handled manually. Your date of birth cannot be changed in the app, so a request to correct it is reviewed by Sentient, and we may ask for information to confirm the correction.

We may need to verify a request before acting on it, and some information may be retained when required or permitted by law or when necessary for security, fraud prevention, dispute resolution, or other legitimate purposes.

Deletion requests submitted through our website

If you cannot use the app, you can request deletion of your account or of specific data through the forms on our website. To help confirm that a request comes from the account holder, the form asks either for your Sentient recovery PIN and recovery phrase, or for account-identifying details for manual review, such as your name, date of birth, approximate account-creation month, device type and model, approximate last use, contacts or trusted devices you remember, business-connection information, and a description of the data you want deleted.

Recovery credentials entered in the form are used only to verify the request: they are compared against the stored hashes and are not saved in the deletion-request record. To help protect the forms from abuse, we also keep a short-lived hashed identifier derived from technical request information for rate limiting. We may be unable to act on a request if we cannot establish that it comes from the account owner.

When you request account deletion on the website, you may also, optionally, tell us why you are leaving. You may also agree that we can contact you about that feedback, by email or phone. This is separate from the request itself. It does not affect whether or how the request is processed, it is not used to identify or verify your account, and any contact details are used only to follow up about your feedback.

9. Children

The Services are not directed to children under 13, and children under 13 are not eligible to use Sentient. If the date of birth entered during sign-up shows that the person is under 13, sign-up stops on the device. The name and date of birth entered are not sent to Sentient and no account is created. Sentient does not create a server-side record, device identifier, or list of blocked users for that attempt. Instead, the app keeps only a local marker on the device, holding the time the block ends, which pauses sign-up on that device for 72 hours. The technical information described in Section 2 that is processed for every installation before sign-up, such as the anonymous session and the device-recognition check, may already exist. It does not include the name or date of birth and is not marked as belonging to a child.

If we learn that an existing account belongs to a child under 13, we may disable it and permanently delete the account and its data through an internal process, without the 30-day cancellation period that applies to ordinary deletion. If you believe a child under 13 is using Sentient, please contact us.

9A. Age eligibility and guardian linking

Sentient is intended for people age 13 and older. Users under 13 are not eligible to use this version of Sentient. During account setup we ask for a date of birth. If it shows that the person is under 13, account setup stops on the device, as described in Section 9.

Users ages 13 through 17 must complete parent or guardian linking as part of account setup, and the account is not created until linking succeeds. The parent or guardian's role is to consent to the dependent creating and using a Sentient account. The dependent separately agrees to the Terms of Service and acknowledges this Privacy Policy when the account is created. Guardian approval is tied to an adult Sentient account, meaning one whose stated date of birth shows the account holder is 18 or older:

  • the person setting up the account displays a temporary QR code that changes every few seconds;
  • a parent or guardian scans it from their own Sentient account in Settings > For families, after confirming consent for the child or dependent to create an account; and
  • the parent or guardian then enters their date of birth on the device being set up, and Sentient checks it against the date of birth on the adult account that scanned the code.

Sentient checks that the scanning account is an adult account and that the date of birth entered matches it. Sentient does not independently verify that the adult is the dependent's legal parent or guardian.

To make this work, Sentient keeps a record of the relationship between the guardian account and the dependent account, including when consent was given, when the check was completed, and whether the dependent is currently allowed to use Sentient. While linking is in progress, the name and date of birth entered for the new account are held temporarily on Sentient's servers so they can be used when the account is created. Until the server-side linking session starts, the app keeps them in the device's secure storage. If linking does not finish, the name and date of birth are deleted when the linking window ends. That is 24 hours after linking starts or, once a guardian has approved, 24 hours after approval if the account has not been created. The rest of the linking session, which holds no name or date of birth, is deleted within about three more days. Nothing about the attempt prevents starting again. The date of birth typed by the parent or guardian is compared and is not stored.

While a dependent is under 18, the linked parent or guardian may control whether the dependent can continue to use Sentient, using a setting in Settings > For families. When access is turned off, the dependent cannot use Sentient until access is turned back on. Turning access off does not delete the dependent's account, contacts, or messages. This control is separate from any safety or moderation measures Sentient may take.

When a dependent turns 18, the guardian's access-control authority ends and the account continues as an independent adult account. Sentient may keep a record that the guardian relationship existed.

If the linked parent or guardian deletes their own Sentient account while the dependent is under 18, the dependent's account and data are not deleted because of it. From the time the guardian requests deletion, the dependent can use Sentient only to link a new parent or guardian, through the same QR code, consent, and date-of-birth process. Normal access returns once a new guardian is linked, or if the original guardian cancels their deletion within the 30-day period. If the dependent is already 18, no new guardian is needed.

When users ages 13 through 17 use supported Sentient features, service providers may process the technical information described elsewhere in this Policy as necessary to provide those features. For example, this can include push-notification delivery, QR-based linking or contact pairing, network communications, and voice-call relay infrastructure.

10. Changes to this Policy

We may update this Privacy Policy as the Services, our practices, or legal requirements change. When we make changes, we will update the effective date above and provide additional notice when required by applicable law.

11. Contact us

Sentient Digital, Inc. is responsible for this Privacy Policy. For privacy questions or requests, use the Contact section of our website and identify your request as a privacy matter so it can be routed appropriately.

Contact Sentient →
SENTIENT

Rebuilding trust in communication.

CompanyBlogNewsroomFAQSentient AISentient HelpPrivacyTermsContact
© 2026 Sentient Digital, Inc.All rights reserved.