What BYOA collects
- Your recordings (audio). When you record a note on Apple Watch, the audio is uploaded to the BYOA server so it can be transcribed. The server returns "accepted" right away and transcribes in the background.
- Your transcripts (note text). The text of your notes, with the time you recorded them and a device label (for example, "apple-watch"), so the note can wait for you or your agent.
- Account identifiers. Signing in with Apple gives BYOA a private account space. BYOA stores only a one-way hash of your Apple identity (
SHA-256of the Apple subject) — never your Apple password, and never the raw subject identifier. If you join with a one-time code instead, BYOA stores the code only as a hash. - Device tokens. Each iPhone or Watch you pair gets its own device token. Only a hash is stored; the token itself lives in your device's Keychain. You can revoke a device at any time.
- Agent tokens. If you connect an agent, BYOA issues that agent a scoped key (read waiting notes, mark them handled). Only a hash is stored. You see the real key exactly once, and you can revoke it at any time.
- Usage counters. Per-day counts of notes and audio volume, used to enforce fair-use limits (see "Limits" below). These are operational counters, not an activity history of your note content.
- Feature requests (optional). If you use Request a feature, BYOA stores your title, details, area (Watch, iPhone, Agents, Account, Other), the app version and device you sent it from, and a contact email only if you type one. Sending a request does not imply it will be built.
What BYOA does not collect
BYOA does not collect your location, contacts, photos, health data, browsing history, advertising identifiers, or purchase history. The app contains no third-party analytics or advertising SDKs, does not track you across other apps or websites, and does not sell or broker your data. BYOA never asks for, or stores, your agent's password.
How your notes are used
Your notes are used only to provide the app's functionality: capture, transcription, holding the note as waiting, showing it to you, and — only if you connect an agent and choose it for new notes — delivering it to that agent. Your notes are not sold, not used for advertising, and not used by BYOA to train models.
Transcription. Audio is transcribed by a cloud speech-to-text service running in BYOA's own cloud account (currently Cloudflare Workers AI, Whisper). Your audio is sent there only to be turned into text.
Retention: the relay rule
BYOA is a relay, not an archive. Handled notes are deleted from BYOA immediately and cannot be recovered from BYOA.
- Raw audio is deleted from the server after transcription succeeds. If a note is handled before transcription finishes, its audio is deleted with the note.
- Waiting notes stay in BYOA only until handled. When you tap Handled, or your connected agent acknowledges a note, BYOA deletes its copy of that note and its audio immediately. Handled notes are not kept as history and cannot be recovered from BYOA.
- Your agent's copy is separate. If you connect an agent, what that agent keeps after it reads a note is governed by that agent's own privacy practices, not this policy. Revoking an agent stops it from reading new notes; it does not reach into the agent's own storage.
- No saved-note archive or export. BYOA does not keep handled-note history or offer note export.
- Usage counters are retained as daily operational records for limit enforcement and are removed when you delete your account.
- Feature requests are kept in the developer's review queue until the request is resolved or the account is deleted.
Sharing with agents you connect
Connecting an agent is optional; BYOA is fully usable with no agent. If you connect one:
- The agent can read waiting notes for your account only, and mark them handled, under the scopes you approved (
notes:read,notes:ack). - You choose which connected agent new notes go to. Changing the choice affects new notes only; it does not move notes already waiting.
- You can revoke any agent in the Agents tab. Revocation takes effect on the server immediately; the agent's key stops working.
- Agent connections are labeled by type (for example Muse, ChatGPT / Codex, Instinct, OpenClaw, or another MCP agent). The label describes the key BYOA issued for the BYOA MCP endpoint; it is not a password and not a login inside that other product.
Your controls
- Delete a note (Waiting): permanently deletes that note and its audio from BYOA.
- Handled (Waiting): tells BYOA you are done with the note; BYOA deletes its copy right away.
- Revoke an agent (Agents) or remove a device (Account): cuts off that agent's or device's access.
- Delete my account and data (Account): after confirmation, deletes your notes and audio, agents and their token records, devices, usage counters, feature requests, and your Apple identity mapping. This cannot be undone.
- Sign out on this device removes that device's credential from its Keychain. It does not delete your account.
Deletion is performed on BYOA's primary stores at the time of the request. Because BYOA uses eventually consistent storage, a deletion or revocation may take a short time to propagate everywhere; if something reappears, contact us and we will complete the deletion.
Limits
To keep the service sustainable, BYOA enforces per-account caps on audio size and daily volume (currently 20 MB per recording and about 250 MB / 500 notes per day). Over-limit uploads are rejected with an explanation in the app; no note content is collected when an upload is rejected for size.
Children
BYOA is not directed at children under 13, and accounts are created through Sign in with Apple under Apple's own age controls.
Changes to this policy
If a future feature changes what data BYOA handles, this policy will be updated and the effective date changed before that feature ships. Material changes will be noted in the app's release notes.
Contact
Contact: support@byoa.me
BYOA is operated by Flighted Technologies LLC.