Privacy Policy
What One Incense collects, what leaves your device, what does not, and what you can do about it.
Last updated: 2026-08-27
This policy describes what One Incense actually does with your data. It is written to be checked against the product rather than to cover us — where something leaves your device, it says so plainly.
The short version
- Camera video never leaves your device. Face detection runs entirely in your browser. No frame is uploaded, stored, or seen by us.
- What you type as your intent, and your session statistics, are sent through OpenRouter to the configured model provider so the companion can say something about your sitting. That is the only product purpose for which we send them.
- We store your sittings and a short note the companion keeps about your pattern. Your sittings are always visible in your focus record. The companion's note is a Hall feature; you can also request access to or deletion of the data we hold.
- We do not sell your data, and there is no advertising model here. You are the customer.
What we collect
Account. Your email address and name, and a password hash if you signed up with a password. If you signed in with Google or GitHub, we receive your email and profile name from them.
Sittings. For each focus session: what you typed you would work on, the length you chose, when it started and ended, how much of it you were present for, how many times you drifted, and whether you finished or left early.
Presence events. A timeline of moments during a sitting — when you switched
away, when you came back, when your phone left the room. These are timestamps
and a short label such as tab or camera, never content.
The companion's note. A short paragraph the companion writes about your pattern after a sitting — how you tend to work, what you keep avoiding. It is regenerated over time and never contains anything you did not do in the product.
Payments. If you subscribe, our payment provider processes the payment. We receive the order and subscription status. We never see or store your card details.
Technical. Ordinary server logs, and analytics if it is enabled on this deployment.
What leaves your device, and what does not
This is the section most policies are vague about.
The camera — nothing leaves
Camera presence is optional and off unless you turn it on. When it is on, face detection runs on your own machine using a model downloaded to your browser. Video frames are processed in memory and discarded. No image is uploaded, transmitted, or stored anywhere, by us or anyone else. The only thing that ever reaches our server is a timestamped label meaning "present" or "away".
We also removed the detection library's own analytics from our build, so it does not report to its vendor either.
The companion's words — these do leave
To generate what the companion says, we send OpenRouter: the text you typed as your intent, the length of the sitting, how long you were present, how many times you drifted, whether you finished, your current streak, and aggregate sitting counts. For Hall members, the request can also include the companion's existing note about you; free requests do not read or send that note. We do not send your name, your email, or your account identifier.
OpenRouter routes the request to the model provider selected in our configuration. OpenRouter and that model provider therefore process the fields listed above to return one or two sentences. Your intent text is handled by our prompt as a description of your work, never as an instruction to the model.
If no AI provider is configured on a deployment, the companion is simply silent — everything else still works.
Speech — depends on your browser
If you use voice input, speech recognition is performed by your browser, which on most desktop browsers means the audio is sent to that browser vendor's servers. This is your browser's behaviour, not ours, and we label it next to the control that turns it on. Text-to-speech uses only voices installed on your device; we deliberately refuse network voices.
Sound — nothing leaves
Ambience is either generated in your browser or loaded from our own server as a plain audio file. No listening, no microphone, no analysis.
Legal basis, if you are in the EEA or UK
We process your account and sitting data to perform the contract you entered into by creating an account. Analytics, where enabled, relies on consent. Sending your intent through OpenRouter to the configured model provider is part of providing the companion, which is the service itself.
Who else processes your data
- OpenRouter and the configured model provider, for the companion's lines, as described above.
- Our payment provider, if you subscribe.
- Our email provider, for account emails such as password resets.
- Our hosting provider, which stores the database.
We do not sell personal data, and we do not share it for advertising.
How long we keep it
Sittings and the companion's note are kept while your account exists. Delete your account and they go with it. Server logs are kept for a short operational period.
What you can do
- Read every sitting we hold about your focus at your focus record. Hall members can also read the companion's current note there. You may request access to all personal data we hold regardless of your plan.
- Delete your account, which deletes your sittings, your presence events and the companion's note. Contact us and we will action it.
- Export or correct your data, and object to processing, if you are in a jurisdiction that grants those rights.
- Turn the camera off at any time, or never turn it on. Everything except chair-level presence works without it.
Children
This service is not directed at children under 13, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects what leaves your device, we will say so specifically rather than only updating the date at the top.
Contact
Questions about this policy, or a request about your data: contact us through the details on the site.