Privacy
Policy.

Last updated

Prio is the app. It is made by UAB Agentic labs (“we”, “us”), a company registered in Lithuania, company code 307629422. We are the data controller for the personal data described in this policy.

This policy explains what data Prio collects, why, where it goes, how long we keep it, and what you can do about it. If something is unclear, email us at help@justprio.com.

1What Prio does

Prio connects to messaging accounts you already have — WhatsApp, LinkedIn, Telegram, Instagram, and email such as Gmail or Outlook — and shows your conversations in one inbox. It then reads those conversations to find things you owe people (a reply, a decision, a promised file), ranks them, and presents them one at a time as cards.

To do this, Prio has to read your messages, keep them, and show them to an AI model. There is no way to provide the service without that, so most of this policy is about what happens to your messages — and, above all, where it happens.

We can’t read your messages — we never receive them. Prio reads your inbox on your phone and asks Google’s Gemini to make sense of it. What our servers hold is your account, your push tokens, the encrypted Lock Screen card we deliver but can’t open, and the short list of other things set out in section 4.2 — never a message. Two things that claim does not say, and section 4 spells out: Google does see the messages it is asked to rank, and the platform you connect still passes them through a bridge on the way to your phone.

2Data we collect

2.1 Account data

  • The identifier, name and email address Apple hands us when you use Sign in with Apple. There is no Prio password. Your name — the one Apple gives us or the one you type — is also sent to our analytics provider, PostHog, with your Prio user id, so that we can tell whose app we are looking at; your email address is not. When you first sign up, your name, the email address Apple hands us and your time zone are also posted to a private channel in our team’s Slack, so that we know who has joined; Slack (Slack Technologies, LLC, United States) acts as our processor for it, under the EU Standard Contractual Clauses for the transfer.
  • Account settings and preferences: your time zone and quiet hours, which notifications you want, and which chats you have muted — held on our servers only as a keyed hash of each conversation’s identifier, never the identifier itself. Priority rules, your standing context and your cold-outreach preferences stay on your phone.
  • Subscription status: when Prio first asked you to subscribe, which plan you chose, whether it is in its free trial, whether it is active and when the current period ends. We do not see or store your card details; Apple handles payment.
  • What you tell us about yourself when you ask for access. Prio is invite-only for now, and we ask everyone the same questions before they sign in: your role, the name and size of your company — or that you don’t work at one — an email address, and which messaging networks you use. We use these answers to decide who we let in first, to tell you when you’re in (by that email and, if you allow it, a notification), and to learn what to build next. The address is never sold. Your email address and your company’s name are never sent to our analytics provider (PostHog); of these answers it receives only your role and your company’s size (each chosen from a fixed list), how many messaging networks you ticked, whether an answer was given and, as a yes or no, whether you work at a company. Your answers — your email address and your company’s name included — are posted with your signup to our team’s private Slack channel (above), and so is the platform you connect first. If you are on the waitlist, we keep your answers and the date you joined it until you are let in or you delete your account.

2.2 Connected platform data

Prio connects to a platform through a messaging bridge, Unipile (section 4.4), which holds the connection on our behalf. When you connect a platform, the following is collected:

  • Session credentials. The tokens, cookies, or linked-device keys that keep your connection alive. Depending on the platform this may be an OAuth token or the equivalent of a logged-in session. They are held by the bridge, encrypted at rest. Our servers hold the connected account’s identifier and whether it is working; they never hold the credentials themselves. Your phone reads your inbox from the bridge with a short-lived access key issued for your accounts alone, kept in the phone’s keychain.
  • Messages. The content of conversations in the connected account: text, sender and recipient identifiers, timestamps, read status, and attachments (images, documents, voice notes) where the platform provides them. Read by your phone from the bridge and stored on your phone.
  • Contact and profile data. Names, handles, profile pictures, and phone numbers or email addresses of the people you talk to, as provided by the platform. Stored on your phone.
  • Account metadata. Your own profile on the platform, folder or label structure, and similar. Stored on your phone.
  • Calendar events, when the account you connect is a Google account. Connecting Gmail also grants Prio read-only access to that account’s calendar: event titles, times, locations and attendees. Your phone reads the diary so a meeting you have already agreed is recognised as settled rather than surfaced as a fresh decision. Prio never creates, edits or deletes an event.

On first connection your phone syncs recent history from the bridge, then keeps syncing as new messages arrive. When a message arrives, the bridge notifies a small relay service of ours; the relay passes on only identifiers — which account, which conversation, which message — and our servers use those to wake your phone. Neither the relay nor our servers keep or read the message itself. A conversation’s identifier can contain a phone number: on WhatsApp it is the other person’s number. It passes through the relay, our servers and Apple’s push service to reach your phone, and from your phone when it tells us which chats you muted and which card is on top; we hash it as it arrives and do not store it. Where we must remember a conversation — a chat you muted, the card at the top of your Lock Screen — we keep only that keyed hash, from which the number cannot be read back without a secret key we keep apart from the database.

2.3 Data Prio generates

  • Cards. The tasks and obligations Prio detects, the priority it assigns, and the reason for the ranking. Built and kept on your phone.
  • Your actions on cards (done, later, ignored). Kept on your phone and used there to improve ranking for you.
  • A message you schedule to send later stays on your phone, like every other message. We are told only that your phone should wake up at a particular minute — an identifier that means nothing on its own, and a time. At that minute we send your phone a silent signal, and your phone sends the message itself. If it is off or offline, it sends as soon as it is back; the app tells you that before you schedule.

2.4 Device and usage data

  • Device model, OS version, app version, language, time zone.
  • Push notification tokens, the record of which Lock Screen card was last delivered to your phone and when, and any times you have asked your phone to be woken (an identifier and a minute — see section 2.3).
  • Encrypted Lock Screen cards. Your phone writes the card shown on the Lock Screen and encrypts it with a key that never leaves the phone. We store and deliver the encrypted copy so it can be pushed while the app is closed; we cannot open it. Alongside it we hold a keyed hash of the top item’s conversation identifier, used only to tell whether it changed.
  • App events — screens opened, features used, errors — collected through PostHog. The events we define carry no message content.
  • Taps. We record which controls you tap, automatically, and a tap is labelled with the text that was on the control. Every surface that can draw a message — a card, a chat row, a conversation, and the lists and sheets that quote them — is marked so that a tap anywhere inside it is not recorded at all. So the labels we receive name buttons and tabs, and not anybody’s words.
  • Session replay. A recording of your screen inside the app. It is off by default and can only be enabled for your account from our side, one account at a time. Where it is on, it can capture whatever is on screen, including message content. You can ask us to turn it off, or to confirm whether it was ever on for you, at any time.
  • IP address and the approximate location derived from it, in server logs.

2.5 Data we don’t collect

  • We don’t collect precise location.
  • We don’t access your phone’s contacts, photos, or other apps unless you explicitly attach something.
  • We don’t collect anything from platforms you haven’t connected.

3Why we process it, and on what legal basis

Under GDPR we need a legal basis for each purpose.

PurposeData usedLegal basis
Creating and running your accountAccount dataContract (Art. 6(1)(b))
Syncing and showing your messages in one inbox, on your phoneSession credentials (at the bridge), messages, contactsContract
Detecting obligations and ranking them, on your phoneMessages, contacts, cards, your actionsContract
Sending messages you choose to send, from your phoneSession credentials (at the bridge), message contentContract
Waking your phone — for a new message, or at a time you chose — and showing Lock Screen cardsPush tokens, message identifiers, encrypted cardsContract — you can turn notifications off in Settings
Deciding who we let in while Prio is invite-only, and telling you when you’re inYour answers to the access questions, your email address, push tokensLegitimate interest in admitting people at a pace we can support (Art. 6(1)(f))
Improving Prio’s ranking for you based on how you act on cardsCards, your actionsLegitimate interest in making the product work better for you (Art. 6(1)(f))
Product analyticsDevice and usage dataLegitimate interest in understanding and fixing the product
Security, fraud prevention, abuse detectionAccount data, logs, IPLegitimate interest in keeping the service secure
Responding to support requestsWhatever you send usContract / legitimate interest
Finding out why Prio isn’t working on your phone, when you report a bugThe diagnostics included with every bug report: versions, counts, times and error types — never message content, subjects or namesLegitimate interest in fixing what you reported (Art. 6(1)(f))
Tax, accounting, and responding to lawful requestsAccount and billing dataLegal obligation (Art. 6(1)(c))

We may use aggregated, de-identified statistics (for example, average cards handled per day across all users) to improve Prio. This data cannot be tied back to you.

What we don’t do:

  • We don’t use your messages to train AI models — ours or anyone else’s.
  • We don’t sell your data.
  • We don’t show ads and don’t share your data with advertisers.

4Where your data goes

4.1 Your phone

Your messages, the people in them, the cards Prio builds and everything you decide about those cards live in a database on your phone, protected by iOS data protection — encrypted on disk until the phone is first unlocked after a restart — and readable only by Prio and its own extensions. Deleting the app deletes it.

4.2 Our servers

Our servers are in the European Union, hosted by Google Cloud in europe-west1 (Belgium). They never receive your messages — not a word of one, not a subject line, not the name of a person who wrote to you. What they hold is: your account; the identifiers and status of the platforms you connected; your push tokens and the record of what was last pushed to your phone; encrypted Lock Screen cards we cannot open; your notification preferences, with muted chats named only by a keyed hash of their identifier; the times you asked your phone to be woken; the identifiers of notifications we have already passed on, so that a repeat does not reach you twice; the identifiers of the messages you sent in the last thirty days — never their words — so that a reaction to one of yours can reach you and a reaction to somebody else’s does not; when Prio first asked you to subscribe, and, if you subscribe, which plan it is, whether it is in its free trial, whether it is active, whether it renews and when its period ends; the answers you chose to give when you set Prio up (section 2.1); the record of a WhatsApp pairing you start in the app, kept for a day; and support reports and diagnostics reports you send us (section 4.6). That is the whole list. Everything on it is encrypted at rest and in transit. Two things pass through without being kept: conversation identifiers, which for WhatsApp contain the other person’s phone number — on their way to your phone in a notification, and from your phone when it tells us which chats you muted and which card is on top, where we hash them as they arrive (section 2.2); and the phone number you type to pair WhatsApp, which our servers send to the bridge to ask for your pairing code.

There is no exception to that, and there is no back door to it either: we could not show you your own messages from our side if you asked us to, because we do not have them.

4.3 AI processing

Google does see your message content. Gemini is the model that decides what needs you, and to do that it is given the conversations it is ranking. Your phone sends them to Google’s Gemini model through Firebase AI Logic, directly: our servers are not in that path and do not see what is sent. Apart from this, and session replay where it has been turned on for you (section 2.4), message content does not leave your phone. When a message contains a link, your phone fetches the preview — its title and picture — directly from the linked site; our servers are not involved, and the site sees your phone’s address as it would if you opened the link.

Google processes this data as our processor under the Google Cloud terms that govern its Agent Platform (Vertex AI) services. Under those terms they do not use your data to train their models, and they do not keep it after answering. Requests are processed in Google’s European Union multi-region, which may be a data centre other than Belgium.

4.4 The messaging bridge

Prio reaches the platforms through Unipile, a SOC 2 compliant messaging bridge that holds your connections and relays messages between them and your phone. How you sign in depends on the platform: Gmail and Outlook take you to Google’s or Microsoft’s own page, WhatsApp and Telegram are paired with a code or a QR shown in the app, and LinkedIn and Instagram ask for your username and password inside the app, which sends them from your phone to Unipile in a single request and does not keep them. Our servers never see your password, and nothing of ours keeps it — they hold the connected account’s identifier and whether it is working, never the credentials, as section 2.2 describes. The bridge necessarily sees the content of what passes through it and holds those credentials; it processes them on our behalf, and its access to your accounts ends when you disconnect a platform, when you delete your account, or when Prio disconnects it about a day after your access to Prio ends (when a free trial or subscription ends, or a free period you had without one).

4.5 Payments

Prio is a paid subscription, bought through Apple’s in-app purchase system. We never see your card. Apple takes the payment, holds the payment details, and tells us only whether a subscription is active, which product it is for, and when the current period ends.

We use RevenueCat, Inc. (United States) to receive that answer from Apple and pass it to us. What reaches them is your Prio user id, the identifier Apple gives the transaction, and the dates and status of the subscription — never your name, your email, your card, or anything from your messages. They process it as our processor, under the EU Standard Contractual Clauses for the transfer.

What we store on our own servers is the same short answer: which plan, whether it is active, whether it renews, and the date the period ends, beside the date Prio first asked you to subscribe. It is in section 4.2’s list because it is one of the things our servers hold.

4.6 Support reports and diagnostics

When you send a bug report or a feature request from inside Prio, we store it, email it to our support address and post it to a private channel in our team’s Slack. Both carry what you typed, your Prio user id, a reference for the report, the app’s version and your phone’s operating system, and — when you report a problem from a screen that failed — which screen it was. It does not carry your messages.

Diagnostics. Every bug report you send from inside Prio — from Settings, or from “Report a problem” where something failed — always includes a report of how its syncing on your phone is doing: the app and iOS versions; whether its database on your phone opened, and if not, what kind of fault stopped it; for each platform you connected, its identifier, whether it is working, how many conversations and messages it holds and when it was last read; how many cards and tasks Prio is tracking; whether notifications are allowed; and a log of its recent sync steps, with the kind of error and the status code where one failed. It never contains message text, subjects, the names of people or groups, or the identifiers of your conversations or messages. The app builds it only from counts, times and a fixed list of words. The report form says it is included; if you would rather it were not included, email us at help@justprio.com instead of using the form. A feature request does not include it. We store it, email a summary to our support address, post its one-line headline to our team’s Slack, and delete it after 90 days.

That email is sent through Resend, and the Slack post through Slack (Slack Technologies, LLC, United States), each acting as our processor for it — Slack under the EU Standard Contractual Clauses. If neither is configured the report is still stored and simply not sent on; nothing you write is lost either way.

Crash reports. When Prio crashes, or hits an error it cannot recover from, the app sends a crash report to Sentry (Functional Software, Inc., United States), who act as our processor for it, under the EU Standard Contractual Clauses for the transfer. A report says what kind of error it was and where in Prio’s own code it happened, the app and iOS versions, your phone’s model, and the app’s recent lifecycle (opened, sent to the background). For an error in Prio’s JavaScript the error’s text is replaced, before it leaves your phone, by a number that only groups identical errors, because that text can quote whatever the code was handling; a report carries your Prio user id, so a crash can be matched to a bug report you send, but never your name, your email address or any record of what you tapped or loaded. A crash in iOS or in Prio’s native code is reported as iOS records it — the kind of fault, the memory address involved and the system’s one-line reason — and that reason is written by the code that failed, not taken from your messages. Sentry deletes reports after at most 90 days.

4.7 The platforms you connect

When you send a message through Prio, it goes out through the platform you’re sending from (WhatsApp, Gmail, and so on) exactly as if you’d sent it from their app. Their privacy policy governs what happens from there.

Prio is not affiliated with, endorsed by, or partnered with any of these platforms.

A note on encryption. Some platforms, such as WhatsApp, encrypt messages end-to-end between devices. When you link Prio to such an account, the bridge acts as one of your linked devices. That means messages are decrypted at the bridge and on your phone, and are no longer protected solely by the platform’s end-to-end encryption — though they are never stored on our servers. If that matters to you for a particular account, don’t connect it.

4.8 Nobody else, except

We’ll share data outside the above only if:

  • you ask us to;
  • we’re legally required to — a court order or lawful request from a competent authority. We’ll tell you unless we’re prohibited from doing so;
  • it’s needed to protect the rights, safety, or property of Prio, our users, or others;
  • we are involved in a merger, acquisition, or sale of assets. Your data may transfer to the successor under this same policy, and we’ll notify you.

5People who message you

Your inbox contains messages from people who haven’t signed up for Prio and haven’t read this policy. Here’s what we do with their data:

  • It is processed only to show you your conversations and to build your cards — on your phone, and by the AI model your phone asks. We don’t contact them, build profiles of them across users, or use their data for anything else. Our servers never receive what they write or their names. The one thing of theirs that passes through our servers is a conversation identifier, which on WhatsApp is their phone number, on its way to your phone in a notification; we keep it only as a keyed hash, and only for a chat you muted or the card at the top of your Lock Screen.
  • Their data is held under the same protections as yours: on your phone, and at the bridge for as long as the platform is connected. It goes when you disconnect the platform in Prio, delete the app, or delete your account.
  • If you are someone who messages a Prio user and want to know what we hold about you, or want it deleted, email help@justprio.com. We may need to verify your identity, and in some cases we may need to route the request through the user whose account holds the data.

If you use Prio for work, you may have your own obligations under GDPR or your employer’s policies towards the people you correspond with. Those are yours to meet — see the Terms of Service.

6Your rights

Under GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct it if it’s wrong.
  • Erasure — have it deleted. Account deletion does this for everything we’re able to delete.
  • Restriction — have us pause processing in certain situations.
  • Portability — receive your data in a machine-readable format. There is no export button in the app: email us and we’ll send the account data we hold as JSON. Your messages and the cards built from them are on your phone, and the messages can also be exported from the platform they came from.
  • Objection — object to processing based on legitimate interest. If you object to analytics, we’ll stop.
  • Withdraw consent — where processing relies on consent, withdraw it at any time without affecting what happened before.

Email help@justprio.com. We’ll respond within one month, or tell you if we need longer (up to three months for complex requests). We may ask you to confirm your identity. Requests are free unless clearly excessive.

If you’re unhappy with how we’ve handled something, you can complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) or to the data protection authority in your own EU country.

7How long we keep it

  • Account data. For as long as you have an account. When you delete your account, we delete it.
  • An account that never subscribes. If you never start a subscription — Apple’s free trial counts as one — your account is deleted 30 days after Prio first asked you to subscribe — the same deletion as the one in Settings, which also disconnects every platform you connected. We tell you the date on the screen that asks you to subscribe, and by notification a week before and the day before. A free trial or subscription that you started and let lapse does not start this clock.
  • Messages, contacts, and the cards built from them. On your phone, until you disconnect the platform in Prio or delete the app, either of which removes them. When Prio itself disconnects a platform because your access ended, what is already on your phone stays there, and reading starts again when you subscribe and reconnect; reconnecting the same account replaces what was kept with its history read again from the platform. At the bridge, until you disconnect the platform or delete your account, or until Prio disconnects it about a day after your access to Prio ends (when a free trial or subscription ends, or a free period you had without one).
  • Session credentials. At the bridge, until you disconnect the platform or delete your account, or until Prio disconnects it about a day after your access to Prio ends (when a free trial or subscription ends, or a free period you had without one), or until the platform itself invalidates them. The short-lived key your phone uses to read from the bridge expires within an hour. Disconnecting a platform removes that account from the bridge, so no key can reach it afterwards; deleting your account deletes the keys themselves and withdraws the permission they were issued under.
  • Scheduled messages. On your phone, until your phone sends them. What we hold is an identifier your phone chose and the minute at which to wake it. Your phone re-sends its whole list of pending wakes each time it syncs, and one it has stopped listing — because it sent the message, or you called it back — is deleted then. Signing out deletes the pending ones from your phone and their minutes from our servers; deleting your account deletes everything.
  • Encrypted Lock Screen cards and push tokens. Replaced every time your phone updates them; removed when you sign out or delete your account. A card your phone sealed for a moment in the future is removed within seven days of that moment passing.
  • Identifiers of the messages you send. Thirty days, then deleted — and at once when you disconnect that platform or delete your account. Identifiers only, never the words, used for one thing: telling whether a reaction is to your message.
  • Support reports and diagnostics. A bug report or feature request you send is kept while you have an account, so we can follow it up; deleting your account deletes it. The diagnostics included with a bug report (and a diagnostics report sent on its own from an older version of the app) are deleted after 90 days.
  • Billing and accounting records. Where law requires us to keep invoices and accounting records, we keep them for the period Lithuanian law requires, even after you delete your account.

Deletion is not instantaneous everywhere. Copies can persist in encrypted backups for a short period before those backups rotate out, and in server logs until they expire. Nothing in a backup is used for any purpose other than restoring the service.

8Automated decisions

Prio uses automated processing, including AI, to rank your messages. It does not make decisions that have legal or similarly significant effects on you. Every card is a suggestion; nothing is sent unless you tap send. You can always see why a card was ranked where it was, and you can override it.

9Security

  • Your messages stay on your phone, under iOS data protection, and are encrypted in transit everywhere they travel. Our servers never receive them, so there is nothing of them there to breach.
  • The Lock Screen card is encrypted on your phone with a key that never leaves it; our servers store and deliver only the encrypted copy.
  • Access to production systems is limited to our own named staff, each with individual credentials and multi-factor authentication. Google Cloud records that access, so it can be audited.
  • We cannot read your messages. If you report a problem, we may ask you to share what you are seeing, and we look only at what you choose to send.
  • If a breach affects your data, we’ll notify you and the supervisory authority within 72 hours of becoming aware of it, as GDPR requires.

No system is perfectly secure. Your phone holds your messages and a key to read your inboxes from the bridge, which makes it the thing to protect: keep it locked with a passcode or biometrics, and keep iOS up to date.

10Children

Prio is for adults. You must be 18 or older to use it. We don’t knowingly collect data from anyone under 18; if we learn that we have, we’ll delete it. Messages from minors who correspond with adult users are handled as described in section 5.

11Changes to this policy

We’ll update this policy when the product or the law changes. Small changes — wording, a provider’s name — take effect when posted. Material changes — new purposes, new categories of data, new recipients of message content — we’ll announce in the app at least 14 days before they take effect. Continuing to use Prio after that date means you accept the new version. Previous versions are available on request.

12Contact

UAB Agentic labs

Sodų g. 15-13, LT-01313 Vilnius

Company code: 307629422

Email: help@justprio.com