The short version. Ori is built local-first: your journal lives on your device. To generate readings and insights, some of your content is sent to trusted AI providers that process it on our behalf. Our own server keeps no copy of your journal — only a note you choose to send us, a push token if you allow notifications, and the locked backup if you switch it on. We don't sell your data, and we don't use it for advertising.
What Ori collects
Ori only handles what you put into it or choose to connect:
What you write and say — journal entries, and voice recordings that are transcribed to text.
Daily check-ins — your responses to a short daily wellbeing check-in.
Connected data you choose to link — health and activity data from Oura, Apple Health (on iPhone) or Health Connect (on Android) — such as sleep, heart rate, heart-rate variability, respiratory rate, blood-oxygen, temperature, steps and workouts — and calendar event metadata, only if you connect those services.
Basic technical information needed to run and maintain the app.
You don't need to create an account or give us your name to use Ori's core journal.
Where your data is stored
Your journal entries and related data are stored primarily on your device. Ori does not maintain a central copy of your journal unless you turn on the optional locked copy described next.
The optional locked copy. If you turn on A locked copy with Ori in Export & privacy, your journal is locked on your device before it leaves and saved on Ori's server, so a recovery code can bring it back on a new phone. Ori's server then stores: the locked copy, a copy of its key wrapped under Ori's own key, and a record of each time the key was handed to a device (with the request's IP address, kept for abuse prevention). Ori never opens your copy without you. Because Ori holds a key, someone with full access to Ori's server could technically open it, which is why that access is limited to the founder and why the app says "Ori keeps the key" rather than "Ori cannot read it". The locked copy is off by default, never includes your Oura sign-in, and is deleted from Ori's server the moment you turn it off or erase Ori.
Health data — Apple Health, Health Connect, and Oura
If you choose to connect a health source, here is exactly what happens:
What Ori reads. With your permission, Ori reads sleep (including stages), heart rate, resting heart rate, heart-rate variability, respiratory rate, blood-oxygen, body temperature, steps, distance, floors, calories, exercise sessions, mindfulness minutes, and blood-pressure readings you've logged. It also reads VO2 max, walking heart-rate average, heart-rate recovery and sleeping-wrist temperature where your device records them. On Android, Health Connect may also ask you separately to allow access to your past data so Ori can build your personal baseline from your existing history.
Your cycle, only if you turn it on. If you turn on Cycle & change, Ori asks for one further Apple Health permission of its own — menstrual flow — and reads only the dates marked as the start of a period. You can also log those dates by hand instead. Ori is not a period predictor and does not forecast your cycle.
Where it lives. Your health history is stored on your device. Ori's server does not keep a copy of it.
What leaves your device. When Ori writes your daily letter (and only if you've chosen the mode that uses your health data), a summary of your recent days — which can include actual readings such as your heart-rate variability, resting heart rate, respiratory rate, sleep duration and temperature trend — is sent with your journal content to our server and on to Anthropic to compose that letter. Any note you gave your ring, such as a rest-mode reason or how a session felt, travels with it. With Cycle & change on, the counted facts of your cycle — which day you are on, and how long past cycles ran — go too, so the day's line can be phrased; the dates themselves stay on your phone. If you open a reading in Family, the thread for that person, which is the lines you yourself wrote about them, is sent to be read back to you. All of it is used to write what you asked for, not to build profiles, advertise, or train models on your data.
Retention. Ori's server does not store your health readings. Anthropic may retain API inputs for a limited period for safety and abuse monitoring under its own policies.
Your control. You can disconnect a health source at any time in Ori's Sources screen, revoke permissions in Apple Health or the Health Connect app, and delete Ori's data from within the app. Reflect mode uses no health data at all.
Health data is never sold, never used for advertising, and never shared with anyone except the service providers below, strictly to provide the feature you're using.
Service providers we use
To power specific features, certain content is sent to the following providers, which process it on our behalf to deliver the service:
Anthropic — generates the narrative "Letter" and other insights from your text and, if you've connected a health source in full mode, the daily health summary described above.
Deepgram — converts your voice recordings to text (primary).
AssemblyAI — automatic voice-transcription failover when Deepgram is unavailable.
OpenAI, ElevenLabs, and Google Speech-to-Text — batch transcription fallbacks if live transcription fails, plus OpenAI for text embeddings and fallback AI processing.
Oura — accessed only to read the biometric data you authorize.
Firebase App Check (Google) — confirms that a request comes from a real copy of Ori rather than a script. It checks the app, not you, and carries no journal content.
These providers are bound by their own terms and privacy practices. We share only what's needed to provide the feature you're using.
What Ori's own server keeps
Ori's server is a relay: it passes your words to the providers above and keeps no copy of your journal. Three things are the exception, and none of them is your journal.
A note you send us. If you use Send us a note, we store what you wrote, any screenshots you attach, your platform and app version, and the network address (IP) the note came from — the last so we can deal with abuse. The app asks for no name and no account, but a note is not anonymous in the technical sense, because that address is recorded. Ask us and we will delete it.
A device token, if you allow notifications. So Ori can wake in the background and refresh your wearable data while the app is closed. It identifies the device to Apple's push service, never you, and carries no journal content.
The optional locked copy, described above, only if you switch it on.
What we don't do
We don't sell your personal data. We don't use your journal content for advertising. We don't share it with third parties except the service providers above, or where required by law.
Your choices and deletion
You can clear Ori's data from within the app's settings, or by deleting the app from your device. If you turned on the locked copy, turning it off in Export & privacy deletes it from Ori's server at once, and Erase all of Ori does the same. You can disconnect Oura at any time to stop biometric access. For any privacy or deletion request, email us and we'll help.
Sensitive content & a note on wellbeing
Journaling can involve sensitive, personal reflection, and we treat that content with care. Ori is a tool for self-reflection — it is not a medical device and does not provide diagnosis, treatment, or clinical advice. If you are in crisis or need urgent help, please contact your local emergency services or a crisis line.
Children
Ori is not directed to children under 13, and we do not knowingly collect data from them.
Changes to this policy
As Ori adds features (such as encrypted backup), we'll update this policy and revise the effective date above.