Invitation-only research beta

Privacy Policy

Last updated: August 31, 2026

The Sente iOS beta is a private, voice-first thinking companion. It has no user accounts, advertising, or public profiles.

The hellosente.com website

When you request a beta spot, the website collects your email address, the free-text answer you choose to share, how you currently work through that kind of thought, and whether your iPhone runs iOS 26. A Cloudflare Pages Function processes the submission and sends it through Resend to the Sente operator. After that delivery succeeds, Resend sends one automated confirmation email to the address you provided.

Sente uses this information only to evaluate and administer beta access and to reply to you. The operator's copy remains in the receiving email account until it is no longer needed for the beta. Cloudflare and Resend process related request or delivery data under their own service policies. To request deletion of the operator's copy, email [email protected]. You do not need to repeat the private thought text in that request.

What stays on your iPhone

Audio is transcribed on the iPhone. Raw audio is deleted after the transcript is saved or you cancel. If recording or transcription is interrupted, a protected temporary recording can remain until you retry or discard it.

Conversation history, derived memory, response ratings, and beta research evidence are stored in the app's local archive. Sente does not provide cloud conversation sync. Durable app data can be included in normal encrypted iOS device backups that you control through Apple.

What is sent to write a response

When you request a response, the app sends the current conversation, bounded excerpts from selected prior conversations, the current derived memory narrative, and request metadata through a stateless Cloudflare Worker to the provider configured for the current release—Anthropic or OpenAI. The beta access code is sent as authorization and is not treated as a user identity. One request goes to one configured provider; the gateway does not automatically retry it with another provider.

The Worker has no conversation database. Its explicit diagnostics contain route, method, status, duration, and a validated request identifier—not thought text, model output, audio, memory excerpts, or authorization values.

Under the standard API postures, Anthropic deletes API inputs and outputs within 30 days, while OpenAI may retain abuse-monitoring logs containing prompts and responses for up to 30 days. OpenAI does not use API content to train or improve its models unless the API customer explicitly opts in. Sente sets store to false on OpenAI Responses requests to avoid optional response application-state storage. Longer retention can apply for Usage Policy enforcement, safety, legal compliance, or provider-specific exceptions. Before distribution, Sente verifies the exact configured provider account or project posture.

Beta research evidence

The app derives content-free counts for captures, active days, responses, ratings, memory-source use, bounded failures, and foreground-to-record timing. It does not automatically upload product analytics or a cohort report.

A beta report leaves the app only when you choose the iOS share sheet. The preview contains aggregate evidence and no participant or device identifier, transcript, response, audio path, request identifier, conversation title, or memory excerpt.

Tracking and advertising

Sente does not track you across apps or websites, sell personal data, show advertising, or use third-party advertising identifiers.

Your controls

Contact and changes

Use TestFlight's Send Beta Feedback action for support, privacy questions, or deletion questions. Do not include private thought text unless you deliberately choose to share it.

A material change to these practices requires a new in-app disclosure version before beta use continues. The updated date above identifies the current policy.