Foreglow/Privacy
PRIVACY
The complete data path.
Foreglow holds intimate plans and reflections. This page separates what stays in your private library, what must travel to make a note or voice, and the anonymous product events that help us see whether the app works.
Do you need a Foreglow account?
No. The app does not ask for an email address, password, phone number, or social sign-in. It creates a random installation ID and an install credential so the protected generation service can enforce limits. Those values are not your name and are not shared with advertising companies.
What stays in your local library?
Your saved notes and scripts, finished audio and recordings, written answers, corrections, vision board and photos, practice history, reminders, preferences, and app-lock setting are stored on your device. Foreglow does not keep a server-side copy of that library.
On iOS, those durable files are protected by iOS Data Protection and remain eligible for your encrypted iCloud device backup when you enable device backup. Deleting the app removes local data that has not been exported or restored by your device backup.
What is sent to make a note?
When you ask Foreglow to generate a note, the answers needed to write it are sent through Foreglow’s protected service to the configured text provider. The generated note text is then sent to Fish Audio to create its audio. Foreglow does not store those answers, note text, or generated audio on its servers; the response is returned to the app and saved in your local library. Providers process the material needed to return the requested result. Foreglow does not use it for advertising.
Your board, photos, saved library, and practice history are not sent for note generation. The website board maker processes chosen images in your browser and does not upload them.
What about a copy of your voice?
A voice copy is created only after explicit consent and a spoken consent phrase. The consented sample is sent to Fish Audio, which keeps a private voice model so future audio can use it. You can delete that model from Settings. Five prepared voices and your own locally recorded read-aloud also work without a copied voice.
What anonymous app analytics are collected?
The app sends a closed list of event names for actions such as opening the app, completing onboarding, selecting a voice, generating or playing a note, seeing a paywall, purchasing, exporting a board, and encountering a failure. A random installation ID lets Foreglow count distinct installs and understand a funnel without creating a user account.
Analytics events do not accept notes, answers, scripts, transcripts, recordings, names, email addresses, contact details, advertising identifiers, or arbitrary free text. Allowed properties are narrow operational values such as a numbered step, a preset slot, a plan, a duration, a success flag, or a bounded failure code.
You can turn this collection off at any time in Settings using “Help improve Foreglow — anonymous usage data.” Turning it off immediately stops new analytics events from being queued or uploaded and deletes the pending analytics queue on your device. Turning it back on resumes collection from that moment only; events suppressed while it was off are never sent later.
How long are analytics kept?
Raw app analytics events are kept for 180 days. A daily job then deletes those raw rows. Aggregate daily counts may be kept longer for long-term product trends; they contain an event name, day, count, and distinct-install count, not an installation ID.
Does this website track you?
The website sets no analytics cookies, fingerprints no browser, and loads no third-party analytics or advertising tag. It records a closed list of events for page views, active engagement, scroll depth, sample-audio playback, App Store or availability interest, and opening or exporting a free tool. Events may include the public page path, referring website domain, bounded campaign labels, coarse country code, device category, browser and operating-system family, and language. They never include a page query, form value, email address, image, board content, or arbitrary free text.
A random tab-session identifier is stored in session storage and clears when that tab closes. It supports visit and journey measurement without an account. A separate local-storage preference remembers whether you allowed PostHog analytics so the site does not ask on every page. You can change that choice at any time using “Analytics choices” in the footer.
Cloudflare processes network information needed to serve and protect the site. At the edge, Foreglow uses a secret-keyed, one-way transformation of the connecting IP, browser user-agent, UTC date, and tab-session identifier to create a daily-rotating website identifier. Raw IP addresses and user-agent strings are not stored with analytics.
First-party website measurement is stored by Foreglow. If you allow analytics, the Foreglow Worker also sends PostHog’s EU service a sanitized copy of the same event and temporary identifier. PostHog receives no form content, direct contact details, raw IP address, raw user-agent string, or browser script access. Automatic click capture and session replay are disabled, and PostHog geolocation is disabled because Foreglow supplies only Cloudflare’s coarse country code.
Raw first-party website events follow the same 180-day retention period described above. PostHog’s EU service applies its own cloud retention policy to the sanitized copy. Older anonymous first-party daily totals may be kept longer. Choosing “Essential only” stops future PostHog copies; it does not remove events already sent to PostHog or aggregated counts.
Who handles purchases and the launch waitlist?
Apple processes App Store purchases and RevenueCat receives an anonymous app user ID, purchase history, and subscription status so Foreglow can unlock paid features. Foreglow does not receive your card number. The launch waitlist is closed. If you joined it before launch, Foreglow retains the email address you submitted only for the promised launch message.
How do you export or delete your data?
Any saved note can be exported as an ordinary audio file through the system share sheet. The in-app “Erase everything” action requests deletion of raw analytics for that installation and removes local notes, recordings, board items, settings, the installation credential, and a copied voice. If the network deletion fails, Foreglow tells you before offering a local-only erase. Aggregate daily counts cannot be rewound because they no longer contain an installation ID.
You can delete a copied voice separately. You must cancel an App Store subscription through Apple; erasing app data does not cancel billing.
Foreglow cannot restore a local library it never received. Providers necessarily receive the material needed for the generation or voice-copy action you request, and anonymous app events remain server-side for the retention period above. If these trade-offs do not fit your needs, do not put sensitive material into Foreglow.
Service providers and purpose
Cloudflare hosts the protected service, database, rate limits, and website. The configured text and speech providers process generation requests. Fish Audio creates and serves private copied-voice models when chosen. Apple and RevenueCat process subscription state. These services receive only the information needed for their role; Foreglow does not sell personal data or use third-party advertising analytics.
Security and contact
Transport uses HTTPS. Access to the internal analytics dashboard requires a separate administrator token; the page is excluded from indexing and its responses are not cached. No security measure is perfect. Questions or deletion concerns can be sent to support@getforeglow.com.
Last updated: 7 August 2026.