Privacy Policy

Last updated September 2026

1. What Epist collects

Epist collects only what the product needs to work, all of it provided by you:

  • Account details — your email address, display name, and optional profile (avatar, about). Registration is invite-only.
  • Onboarding details — your birthday, sex, and coarse region (country/state/county). Epist never requests your precise location.
  • Your content — the claims, belief systems, posts, flows, comments, and messages you create.
  • Photos you pick — avatar and content images you choose through your device's photo picker. Epist never scans your photo library.
  • Push tokens — only if you opt in to notifications; you can remove registered devices in Settings at any time.

Epist keeps ordinary server request logs for reliability and security. It does not use analytics or crash-reporting SDKs, and never collects contacts or health data. Payments are handled by Apple (iOS app), Google Play (Android app) or Stripe (web), and your card details never reach Epist's servers. Epist stores only your subscription status and the purchase reference needed to keep it up to date.

2. No tracking, no ads, no selling data

Epist does not sell your data, does not show ads, and does not track you across other apps or websites. There are no advertising or tracking SDKs in the product.

3. How your data is used

Your data is used to run Epist: authenticating you, showing your content to the people and spaces you share it with, sending the notifications you opted into, and processing subscriptions. AI-assisted features (such as chat-based authoring and claim validation) process the content you submit to them in order to respond — nothing more.

4. Service providers

Epist relies on a small set of processors, each only for the purpose listed:

  • Google Cloud — hosting, database, and media storage.
  • OpenAI and OpenRouter (and the language-model providers OpenRouter routes to) — AI features process the content you submit to them. The text of claims you create is also checked and analysed by AI models.
  • Expo & Firebase Cloud Messaging — push notification delivery.
  • Auth0 — social sign-in.
  • Stripe — subscription payments made on the web. Stripe handles your card details under its own privacy policy; Epist stores only your subscription status and Stripe customer reference.
  • Apple App Store — subscription purchases made in the iOS app. Apple handles payment under its own privacy policy; Epist receives Apple's signed transaction and renewal notifications and stores your subscription status and Apple's transaction reference.
  • Google Play — subscription purchases made in the Android app. Google handles payment under its own privacy policy; Epist receives Google's purchase token and renewal notifications and stores your subscription status and that token.

5. Retention and deletion

Your data is kept for as long as your account exists. You can delete your account from Settings in the app or via the web deletion page; deletion begins a 30-day window during which you can change your mind by signing back in. After the window ends your account and personal data are permanently purged.

6. Your choices

You control your profile and content in the app, can turn notifications on or off per category, can remove registered devices, and can delete your account entirely. Questions or requests about your data: contact the Epist team through the app or at the address listed on our website.