Privacy Policy
1. Introduction
Envisioning LLC-FZ (“Company”, “we”, “us”, or “our”) is a Free Zone limited liability company registered in the Emirate of Dubai, United Arab Emirates. We are committed to protecting your privacy and handling your personal data responsibly.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have in relation to your data when you use our website and early access sign-up page for Blink Life (“Services”).
This policy is designed to comply with applicable privacy and data protection laws, including:
- The European Union General Data Protection Regulation (GDPR, Regulation (EU) 2016/679)
- The United Kingdom General Data Protection Regulation (UK GDPR)
- The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
- The UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
Please read this policy carefully before using our Services.
2. Data Controller
Envisioning LLC-FZ is the data controller responsible for your personal data under this Privacy Policy. This means we determine the purposes and means of processing your personal data.
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, you can contact us at:
Envisioning LLC-FZ
Dubai, United Arab Emirates
Email: privacy@envisioning.group
We aim to respond to all privacy-related inquiries within 30 days of receipt, or within the shorter timeframe required by applicable law.
3. Information We Collect
We collect different categories of data depending on which features you use and the consents you provide. Some data is necessary to provide the service, some is collected on the basis of legitimate interest, and some requires your explicit consent before we collect it at all. The table below sets out everything we collect and why. Rows marked ‘Your consent’ apply only if you choose to enable that feature — they are never collected by default.
| Data Category | What We Collect | Legal Basis |
|---|---|---|
| Account & profile | Email address, display name, profile photo, auth provider ID, Stripe customer ID, onboarding status, IP address | Contract — required to provide the service |
| AI companion settings | Companion name, personality archetype, voice preferences, relationship parameters, AI-generated personality document | Contract — required to provide the service |
| Conversations | Text conversation history, messages to/from your AI companion, source channel (web, Telegram, etc.). Third party channel conversations only if you choose to connect them. | Contract — required to provide the service |
| Life organization | Goals, tasks, projects, notes, daily logs, personal knowledge you create | Contract — required to provide the service |
| Basic system data | Session timestamps, token/credit usage, authentication and system logs | Contract — required to provide the service |
| Behavioral & usage data | Feature usage patterns, priority predictions, interaction signals | Legitimate interest — service improvement and personalisation |
| Basic memory | Semantic memories (basic facts you share), procedural memory (preferences, routines) | Legitimate interest — core personalisation |
| Gmail integration | Email content and metadata accessed via Google OAuth | Your consent — requested when you connect Gmail |
| Google Calendar integration | Calendar events, schedules, attendees | Your consent — requested when you connect Calendar |
| Voice data | Voice inputs (transcribed); audio recordings only if you enable storage | Your consent — notice shown before first voice use |
| Listener sessions | Ambient audio from your microphone and, if you include it, device or tab audio — transcribed to text. May contain the voices of people who are not BlinkLife users. See Section 4 | Your consent — confirmed before your first session, including a confirmation that you have permission from everyone who will be heard |
| Screen captures | Periodic images of the screen or window you share during a Listener session; may include third-party information visible at the time | Your consent — only captured if you enable screen sharing for the session |
| Recordings | Saved screen and audio recordings, which may contain other people's voices, faces and on-screen information | Your consent — notice shown before your first recording |
| Uploaded documents | File content from PDFs or other uploads; may contain third-party information | Your consent — informed at point of upload |
| Sensitive data | Health, financial, and emotional information you choose to share | Your explicit consent — prompted in-app when you first share sensitive information |
| Deep memory | Emotional and episodic memories, and inferred preferences and routines, derived from your conversations | Legitimate interest — core personalisation. Controlled by ‘Auto-capture memories’ in Settings → Privacy, which is on by default and can be switched off at any time |
| Knowledge graph | Entity map of people, places, organisations; relationship mapping; contradiction records | Legitimate interest — core personalisation. Switched off together with ‘Auto-capture memories’ |
| Listener memory | Memories derived from what is said during a Listener session, including by people other than you | Legitimate interest — core personalisation. Controlled by ‘Listener memory extraction’ in Settings → Privacy, which is on by default and can be switched off at any time. Requires ‘Auto-capture memories’ to also be on |
| Cross-product data (Vibrantly) | Data from Vibrantly, including health-related information, used to enrich BlinkLife personalisation | Your explicit consent — separate, standalone consent step |
| Marketing Communications | Email address, first name | Your consent — provided via sign up or opt-in |
Data in the ‘Your consent’ rows above is never collected or processed unless you actively enable the relevant feature. Consent is always requested at the point where it is relevant — not bundled into general Terms acceptance or onboarding.
Rows marked ‘Legitimate interest’ work differently: they are active by default, because personalisation is the core of what BlinkLife does. You can switch them off at any time, and you have the right to object to this processing — see Section 9. The two controls are in Settings → Privacy → Memory:
- Auto-capture memories— extract and store memories from your conversations. On by default. Switching it off also stops Listener memory extraction and knowledge-graph building.
- Listener memory extraction— extract memories from what is said during Listener sessions. On by default. Switching it off leaves the rest of your memory intact, including anything you say directly to your companion during a session.
If you switch both off, BlinkLife stops building long-term memory about you, though standard service features remain available. Turning them off does not delete memories already stored: you can delete individual memories from your memory timeline in the app, or contact us using the details in Section 14 to request erasure.
3.2 Your TrueMemory Account
You sign in to BlinkLife with a TrueMemory account, and you may see that name during sign-up. TrueMemory is operated by Envisioning LLC-FZ — the same company that provides BlinkLife — and the same account can be used with our other apps. Your memories are held against that account.
If you have used another one of our apps before, we may offer to carry your existing AI companion across to BlinkLife. That happens only if you accept the offer, and you can decline and start fresh.
Because TrueMemory is ours rather than an outside provider's, none of this involves handing your data to another company. It is for that reason that TrueMemory does not appear among the service providers in Section 5, which lists only third parties.
3.3 Information We Do Not Collect
We want to be transparent about what we do not collect:
- We do not use advertising or marketing cookies, pixels, or trackers.
- We do not use analytics for advertising or to track you across other websites.
We do use privacy-respecting product analytics to understand and improve the Service, only with your consent where required — see Sections 5 and 10.
3.4 Consent
Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To withdraw your consent:
- Email us at privacy@envisioning.group with the subject line “Withdraw Consent”
- Use the unsubscribe link included in any email we send you
3.5 What We Do Not Do With Your Data
- We do not sell your personal data to any third party.
- We do not share your personal data for cross-context behavioral advertising.
- We do not make automated decisions about you that have legal or similarly significant effects. BlinkLife does draw automated inferences to run the product — ranking your tasks, scoring which emails matter, choosing what to surface on Today, and building the memory described above. None of it determines access to the Service, pricing, credit, or any legal entitlement, and you can object to it under Section 9.
- We do not use your data for any purpose other than those described in this Privacy Policy.
4. Listener, Recording, and Screen Capture
These features capture audio from your surroundings, and in some cases images of your screen or a video recording. They are the most sensitive processing BlinkLife performs, because unlike everything else in this policy they can capture information about people who are not BlinkLife users and who have no relationship with us. This section sets out exactly what happens.
4.1 Listener (ambient audio)
When you start a Listener session, BlinkLife listens through your microphone and, if you choose to include it, to audio playing on your device or browser tab. As you speak, the audio is sent to Deepgram, who turn it into text for us. The text is then read by our AI providers (Section 5) to write a summary and a title.
Before your first session you are asked to confirm that:
- you have obtained consent from every person who will be heard, to have their voice recorded, transcribed and processed by AI; and
- you will not use Listener to record sensitive, confidential or legally protected conversations without proper authorisation.
Recording other people without their consent may be unlawful where you or they are located — several jurisdictions require the consent of everyone present. That obligation rests with you, and BlinkLife cannot verify it on your behalf.
What we keep: the transcript, saved as a note in your account; a record of when the session happened and how long it lasted; and any screen captures taken during it. We do not keep a copy of the audio itself.
How long we keep it: Listener transcripts and their screen captures are deleted 90 days after the session. This happens automatically, and it removes the whole thing — the note, the images, and everything we stored alongside them.
Memory: memories may be derived from what is said in a session — including by other people present — when ‘Listener memory extraction’ is on. It is on by default and can be switched off at any time; see Section 3.
4.2 Screen capture during a Listener session
If you enable screen capture, BlinkLife periodically saves images of the screen or window you have shared, so your companion can refer to what you were looking at. These images can include anything visible at that moment — other applications, notifications, documents, and information about other people. Screen captures follow the same 90-day retention as transcripts.
4.3 Recording
Recording is a separate feature that saves a recording of your screen and audio to your account. Unlike Listener, the audio and video are kept. A notice is shown before your first recording.
How long we keep it: unlike Listener transcripts, recordings are kept until you delete them. Nothing removes them automatically, so a recording stays in your account for as long as you leave it there.
Sharing: a recording is private until you choose otherwise. You can share it by private link or make it public, and in both cases anyone who opens the link can watch it without signing in to BlinkLife. A recording can contain other people's voices, faces and on-screen information. See When You Share Something Yourself in Section 5 for how the two kinds of link differ and how to revoke them.
4.4 People who are not BlinkLife users
Anyone captured by these features has data-protection rights even though they do not have a BlinkLife account. If you are not a BlinkLife user and believe you were recorded, you can contact us using the details in Section 14 to ask what is held about you, to ask for it to be corrected, or to ask for it to be deleted. We will act on such a request in the same way we would for our own users.
If you are a BlinkLife user, the confirmation you gave before your first session — that you had permission from everyone who would be heard — continues to apply for as long as the session and its memories exist. Where that permission is withdrawn, the session and anything derived from it should be deleted.
5. Who We Share Your Information With
We do not sell or rent your personal data. We share your information only with the service providers listed below, acting as data processors on our behalf. Each provider is bound by a Data Processing Agreement (DPA) or equivalent contractual obligations.
Some of these only ever receive your data if you turn on the feature that uses them. Those rows say so.
| Service Provider | What They Do | Data Shared |
|---|---|---|
| Google Cloud Platform (GCP / Firebase / Firestore) | Cloud infrastructure — hosting, databases, and application operations. Acts as a data processor under a DPA. | All account and service data |
| AI providers (Anthropic, Google, OpenAI) | The AI models that read your message and write the reply, and that turn longer recordings into text. Under our agreements with these providers, your data is not used to train their models. | The conversation or recording being worked on |
| Deepgram | Turns speech into text, and text into spoken replies. | Voice input (when voice is enabled) |
| SendGrid (Twilio) | Delivers the emails we send you. | Your email address, your name, and the contents of that email |
| Linear | Where your support requests go so we can track and answer them. | Your message, and the contact details you send with it |
| Jina AI | When you ask your companion to read a web page, we pass that page's address to a reading service that fetches it and tidies the text up so the AI can use it. | The web address you asked about |
| Slack | Sends our own team automated alerts when something goes wrong with billing, so we can look into it. | An internal account identifier and a description of the billing event — not your conversations |
| Google Workspace— only if you connect it | Gmail, Google Calendar and Google Docs, when you choose to connect them. We only reach the parts you approve, and you can disconnect at any time. | Only the email, calendar or document data you connect |
| Telegram and WhatsApp— only if you connect them | If you choose to talk to your companion through one of these apps, your messages pass through that company's service on the way to us, and their own privacy policy applies to that leg of the journey. | The messages you send and receive on that channel |
| Stripe, Inc. | Payment processing. Stripe's privacy policy governs your payment data. We do not store your full card details. | Payment information only |
| Third-party analytics providers (e.g. PostHog) | Analytics, service improvement, troubleshooting, security monitoring, and understanding platform usage. | Device and browser information, IP-derived approximate location, session activity, feature interactions, usage metrics, crash logs, and technical diagnostics data |
When You Share Something Yourself
You can share a note, a page or a recording as a link. A private link contains a long, unguessable code, so in practice only the people you send it to can open it. A public item is visible to anyone and, because it sits at an ordinary web address, may appear in search results.
In both cases the person opening the link does not need a BlinkLife account, and a forwarded link works for whoever receives it.
Everything in the item is visible to them. A shared recording carries the other voices, faces and on-screen details it captured; a shared note carries its full contents, including a Listener transcript. Your obligations to the other people involved are set out in the Terms.
You can withdraw sharing at any time. Turning sharing off, or generating a fresh link, invalidates the previous link immediately. Generating a fresh link on a public item also returns it to private.
Your public profile works the same way. If you claim a handle and publish a profile, that page and anything you have made public on it are visible to anyone, without a BlinkLife account.
Tools You Connect Yourself
Two features let software outside the BlinkLife website reach your data, and only if you set them up:
- The desktop app.Once you sign in to it, your BlinkLife assistant can search and read files on your own computer. It only looks when you ask it to, but when it does, the part of the file it uses is sent to us so it can answer — and, like anything else in a conversation, that may then form part of your chat history and your memories.
- Connecting another AI assistant. You can allow a separate AI app to read and add to your BlinkLife content on your behalf. You choose whether to connect it, and you can disconnect it at any time.
Once another app is connected, what it does with what it reads is governed by that app's own privacy policy, not this one. Only connect tools you trust.
Legal and Regulatory Authorities
We may disclose your personal data if required by law, regulation, legal process, or a valid governmental request, including court orders and requests from law enforcement.
Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, your data may be transferred to the acquiring entity. We will notify you by email before your data becomes subject to a materially different privacy policy.
6. International Data Transfers
Envisioning LLC-FZ is registered in Dubai, UAE, but our systems do not run there. Your personal data is transferred to and processed in:
- The United States, where the service itself runs and where most of the providers in Section 5 are based
- The European Union, where our product-analytics provider stores its data
Our UAE registration is a corporate matter and does not by itself mean your data is held there.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, some of these countries may not provide an equivalent level of data protection. We protect your data by relying on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with service providers
- Supplementary measures where necessary, such as encryption of data in transit and at rest
You may request a copy of these safeguards by contacting privacy@envisioning.group.
7. Data Retention
We retain your data only as long as necessary to provide the service and fulfill the purposes described in this policy. You may delete your account to remove your data, subject to technical and legal requirements.
Where a specific period applies, it is stated in the section covering that feature. In particular, Listener transcripts and their screen captures are deleted after 90 days, while recordings are kept until you delete them — see Section 4.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit using TLS/HTTPS
- Google Cloud Platform's built-in encryption at rest
- Rate limiting on form submissions to prevent abuse
- Content Security Policy (CSP) headers to protect against injection attacks
- Least-privilege access controls for our application
No method of transmission over the Internet is completely secure, and we cannot guarantee absolute security. We will promptly notify affected individuals and relevant authorities in the event of a data breach, in accordance with applicable law.
9. Your Rights
9.1 Rights for All Users
Regardless of your location, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data.
- Withdraw consent: Withdraw your consent to processing at any time.
- Opt out: Unsubscribe from email communications at any time.
9.2 Additional Rights for EU/EEA and UK Residents (GDPR / UK GDPR)
- Restriction of processing: Request restriction in certain circumstances (e.g., while we verify accuracy).
- Data portability: Receive your data in a structured, machine-readable format (e.g., CSV or JSON).
- Object to processing: Object to processing based on legitimate interests. We will stop unless we demonstrate compelling grounds.
- Lodge a complaint: File a complaint with your local supervisory authority. A list is available at edpb.europa.eu. UK residents may contact the ICO at ico.org.uk.
9.3 Additional Rights for California Residents (CCPA/CPRA)
- Right to know: Request disclosure of the categories and specific pieces of personal information collected, sources, purposes, and third parties we share with.
- Right to delete: Request deletion, subject to legal exceptions.
- Right to correct: Request correction of inaccurate information.
- Right to opt out of sale/sharing: We do not sell your personal information. We do not share it for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your rights.
CCPA disclosure — categories of personal information collected in the preceding 12 months:
| Category of Personal Information | Source | Business Purpose | Categories of Recipients |
|---|---|---|---|
| Identifiers: name, email address, IP address, auth provider ID | Directly from you at sign-up | Account creation, authentication, and communication | GCP, Stripe |
| Payment information: Stripe customer ID, masked billing records | Directly from you at checkout | Processing your Subscription | Stripe |
| Conversation and content data: chat history, notes, goals, tasks | Directly from you through the app | Delivering the AI Assistant and core service features | GCP, AI providers |
| Internet / electronic network activity: usage logs, session data, system logs | Automatically via the app | Security, fraud prevention, and service improvement | GCP |
| Audio / voice data (with consent): voice transcripts, voice interaction logs | Directly from you when you use voice features | Enabling voice interactions with your AI Assistant | Deepgram, GCP |
| Sensitive personal information (with consent): health data, emotional state, financial insights | Directly from you or via Vibrantly (with separate consent) | Personalised assistance and insights, solely as requested by you | GCP, AI providers |
| Inferences / profiling: behavioural scoring, emotional and episodic memories, knowledge graph | Derived from your interactions, and from Listener sessions where Listener memory extraction is on. Both are on by default and can be switched off in Settings → Privacy → Memory | Deep personalisation of your AI Assistant | GCP |
9.4 Additional Rights for UAE Residents (PDPL)
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), you have the right to access, correct, and delete your personal data, and to withdraw consent.
9.5 How to Exercise Your Rights
Email: privacy@envisioning.group
Include your full name and the email address you used to sign up so we can verify your identity and locate your records. We will respond within 30 days (or within the timeframe required by applicable law). We will not require you to create an account to submit a request.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to operate, secure, and improve the platform.
We use strictly necessary cookies required for core platform functionality, such as authentication, security, session management, and keeping users logged in. These cookies do not require consent where permitted by applicable law because they are essential to providing the service.
We may also use analytics and performance technologies, including third-party analytics providers such as PostHog, to understand how users interact with the platform, improve features, monitor reliability, and enhance the user experience. Depending on your location and applicable law, these technologies may be used based on your consent.
Where required by law, users will be presented with a cookie or consent banner allowing them to manage their preferences for non-essential cookies and analytics technologies.
We may update our use of cookies and tracking technologies over time. Additional details, including categories of cookies used, retention periods, and preference management options, may be provided in a separate Cookie Policy made available through the platform.
We recognise browser-based privacy preference signals, including Global Privacy Control (GPC), where required by applicable law.
11. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@envisioning.group and we will delete it promptly.
12. Do Not Track Signals
Some browsers transmit “Do Not Track” (DNT) signals. We do not use tracking technologies for advertising purposes or to track users across third-party websites. We recognise browser-based privacy preference signals, including Global Privacy Control (GPC), where required by applicable law, as described in Section 10.
13. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. If we make any material changes to the Policy, we will endeavor to provide appropriate notice, or as required by applicable law. You can see when the Policy was last updated by checking the date at the top of this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective from when they are posted on this page.
14. Contact Us
If you have any questions, wish to exercise your rights, or have a complaint, contact us at:
Envisioning LLC-FZ
Dubai, United Arab Emirates
Email: privacy@envisioning.group
If you are not satisfied with our response:
- EU/EEA residents may file a complaint with their local supervisory authority.
- UK residents may contact the ICO at ico.org.uk.
- California residents may contact the California Attorney General at oag.ca.gov/privacy.
- UAE residents may contact the UAE Data Office.
Terms of Service · Back to BlinkLife