Privacy Policy
Change Order AI · Effective 7 August 2026
The short version.
- The app works completely without an account, a network, or a backend.
- Backup is opt-in. Nothing leaves your device until you turn it on.
- Analytics is off until you turn it on, and can never carry document content — there is nowhere in the data model to put it.
- Raw audio is never saved.
- Photographs are never sent to the AI provider.
- The AI is never asked for a price and cannot return one.
- Cancelling a subscription locks nothing.
Who we are
Change Order AI is published by Memoize Studio. For the purposes of the GDPR we are the data controller for the limited data described below. Contact: support@memoize.studio.
What is stored on your device
This is the great majority of everything the app holds. It lives in the app's own protected storage and is encrypted at rest by iOS.
| Data | Why it exists |
|---|---|
| Company profile, logo, licence number | Document headers |
| Client names, emails, phone numbers, addresses | To address and deliver the document |
| Projects, contract amounts, dates | To compute the contract ledger |
| Change orders, revisions, line items, prices | The product itself |
| Photos, receipts, imported contracts | Evidence |
| Signatures | Proof of agreement |
| Transcripts of what you dictated | The source the document was written from |
| Audit history | What happened and when |
None of it goes to a server unless you turn on a feature that needs one.
What leaves your device, and when
| What leaves | When | Where it goes |
|---|---|---|
| Nothing | By default, with no account | — |
| Records and photos | Continuously, once you turn on cloud backup | Our Google Firebase project |
| Your note text, photo captions, contract excerpts | Only when you tap Draft | Our server, then OpenAI — or Anthropic if OpenAI is unavailable |
| Audio | Only while dictating, and only if your device lacks on-device speech recognition | Apple |
| The frozen document snapshot | Only when you send an approval link | Our server, so your customer's browser can display it |
| Your customer's email address and the approval link | Only when you send an approval by email | Resend, our email delivery provider |
| Analytics counts | Only if you turn analytics on | Our analytics |
The capture screen tells you at the time whether speech recognition is running on your device or going to Apple. Settings → Privacy → “What the AI sees” lists all of the above in plain language inside the app.
What is never sent
- Photographs, to the AI provider. Only captions you wrote yourself.
- Raw audio, to us or to anyone we operate. Buffers go to the speech recognizer and are released.
- Prices, to the AI as something to produce. Its response format has no field for one.
- Document content, to analytics. This is structurally impossible — see below.
Analytics, precisely
Analytics is off unless you turn it on, and it is designed so that it cannot carry your content even by mistake. Events are a fixed, closed list defined in the app's source code. The only companion data an event can carry is a duration, a count, a blocker count, a warning count, and a true/false flag. There is no free-form event name and no string dictionary.
That means a client name, an address, a scope description, or a price has nowhere to go — not “we filter it out”, but “the structure does not permit it”. The complete list of events is shown inside the app under Settings → Privacy, so you can audit the claim yourself.
AI drafting
When you tap Draft, the app sends your note text, the captions you wrote, and any contract excerpts you imported to our own server, which holds the provider credentials and then calls OpenAI (or Anthropic as a fallback). No AI key ships inside the app.
We do not use your content to train AI models, and our providers are used under terms that do not permit training on API content. If you have no network connection, drafting falls back to on-device extraction rather than failing.
Accounts and sign-in
No account is needed to use the app. If you turn on cloud backup, sign-in is Sign in with Apple only. We never see or store a password, and Apple's private email relay means we often never see a real email address either.
Third parties
| Party | Receives | Why |
|---|---|---|
| Apple | Speech audio, only when on-device recognition is unavailable; sign-in identity | Transcription and authentication |
| OpenAI | Note text, captions, contract excerpts, on your explicit request | Drafting (primary) |
| Anthropic | The same, only when OpenAI is unavailable | Drafting (fallback) |
| Google (Firebase) | Records and attachment bytes when backup is on; the frozen snapshot of anything sent for approval | Backup, multi-device, and serving your customer's browser |
| Resend | Your customer's email address and the approval link | Email delivery |
There is no advertising SDK, no tracking SDK, and no data broker. In the app's privacy
manifest, tracking is declared as false and the tracking-domains list is empty.
We do not sell or share personal information as those terms are defined by the California
Consumer Privacy Act.
Legal basis for processing (GDPR)
- Contract. Storing your records, delivering approval links, and processing your subscription — necessary to provide what you asked for.
- Consent. Cloud backup, AI drafting, and analytics are each off until you turn them on, and you can turn them off again at any time.
- Legitimate interests. Keeping the service secure and preventing abuse.
Retention and deletion
- Local records stay until you delete them.
- Cloud copies live in our Firebase project once backup is on. Turning backup off stops the copy updating and never deletes anything on your device.
- Approval tokens expire (30 days by default) and can be revoked.
- Signed revisions are archived rather than deleted, because deleting a signed record destroys evidence your customer may also be relying on. The app states this where it applies.
- Account deletion removes your cloud data. The app offers a full local export first. Request it in the app or by emailing us.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, to receive a copy in a portable format, and to withdraw consent at any time. California residents have the right to know, to delete, to correct, and not to be discriminated against for exercising those rights.
Most of these you can exercise yourself, immediately, in the app: everything is exportable from Settings, and cloud data can be deleted from the same place. For anything else, email support@memoize.studio and we will respond within 30 days. If you are in the EEA or the UK and you are not satisfied with our response, you may complain to your local supervisory authority.
Children
The app is a business tool for contractors and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or under 16 in the EEA). If you believe we have, contact us and we will delete it.
International transfers
Our servers and providers are located in the United States. If you use the app from outside the United States, data you choose to send to a server-backed feature is transferred there. Where required, those transfers rely on Standard Contractual Clauses or an equivalent approved mechanism.
Security
On-device data is protected by iOS file encryption. Data in transit uses TLS. Cloud records are scoped to your organization and enforced by server-side security rules, not only by the app — a revision your customer has already been sent or approved cannot have its terms changed, even by a modified client or a stale write replayed later. No system is perfectly secure, and we do not claim otherwise.
Changes to this policy
We will change the effective date at the top of this page when this policy changes, and we will give notice in the app for material changes before they take effect.
Contact
Memoize Studio
support@memoize.studio
See also the Terms of Use (EULA).