Privacy
Your data in Fouro
This notice explains the information Fouro needs to provide GPT-4o chat, saved history, optional memory, and subscriptions.
Last updated August 9, 2026
Information Fouro handles
When you create or use an account, Fouro receives identity details from Clerk, such as your account identifier, name, and verified email address. Fouro stores your account, conversations and messages, usage counters, subscription status, paid AI name and custom instruction settings, and memories you add or that Fouro automatically selects from signed-in chats when a detail appears useful across future conversations.
Signed-out visitors can use up to five guest chats per UTC day and 10 per UTC month per signed browser installation. Guest prompts, limited in-tab chat context, and responses are processed to answer the request but are not stored as Fouro conversation history or Memory. Refreshing or closing the page clears that guest context, and signing up does not import earlier guest chats.
To enforce guest and free-plan limits and reduce account-rotation abuse, Fouro uses a signed, pseudonymous browser-installation identifier and a one-way keyed network-address hash. These identifiers may be associated with your account for enforcement. Fouro does not store the raw network address or build an invasive device fingerprint. The browser identifier expires after one year. Inactive guest trial records are deleted after about 400 days; inactive shared security counter records become eligible for deletion after 45 days. Provider-attempt and completed reservation records are also retained only for a bounded operational period, while longer-lived aggregate usage events are periodically removed.
When you arrive through a tagged campaign link, Fouro may store the bounded source, medium, campaign, and content labels with that pseudonymous browser identifier. If you later sign in on the same browser, the first-touch labels may be associated with your account so Fouro can measure whether a campaign led to signup and product use. Fouro does not store the full referring page URL for this purpose. Attribution records are removed after about 400 days.
How providers process information
- Clerk provides sign-in and account identity services.
- OpenRouter receives your prompts and the conversation context needed to generate a response from GPT-4o. Relevant saved memories may be included in that context. For an active Pro account, the AI name and custom instructions you save are also included in that context.
- Stripe handles checkout, payment methods, invoices, and subscription management. Fouro sends your verified account email and display name to Stripe so it can deliver receipts, invoice PDFs, and billing notices. Fouro stores billing identifiers and subscription status, not full card details.
- Cloudflare hosts the service and may process routine request, security, and diagnostic information needed to operate it.
- Sentry receives minimized application errors, stack traces, release identifiers, and request correlation labels so Fouro can investigate incidents. Fouro removes request bodies, cookies, query strings, direct user identity, and conversation text before error events are sent. If you deliberately use the Feedback & issues button, Sentry receives the report text, optional reply email, page path, and release identifier you submit. Screenshots are disabled, and prompts and responses are not attached automatically.
- PostHog receives an explicit allowlist of product events, such as an app view, completed chat, quota result, upgrade view, checkout start, or feedback submission. Autocapture, session recording, and person profiles are disabled, and Do Not Track is respected. Fouro disables GeoIP enrichment, removes full URLs and referrers before capture, and configures PostHog not to store client network addresses. Fouro does not send prompts, responses, feedback text, emails, account identifiers, or billing payloads to PostHog.
Feedback and launch measurement
The optional feedback form stores your selected use case, two numeric ratings, the text you choose to submit, and whether a signed-in user consented to an interview. It does not attach chat prompts or responses. If you opt in while signed in, the founder dashboard may show your account email only for that interview request. Pseudonymous device labels and bounded campaign tags are used to prevent feedback spam and understand which launch messages lead to useful product use.
The separate Feedback & issues button is managed by Sentry and is intended for product problems, concerns, and suggestions while you use the app. It sends only what you enter, an optional reply email, the current page path, and release context. Do not include passwords, payment details, or private conversation text.
Managed product analytics uses a pseudonymous browser analytics identifier stored by PostHog. It is not joined to your Fouro account identity. Browser Do Not Track disables this capture, and clearing site data resets the identifier.
Retention and your choices
Signed-in conversations, memories, and paid AI settings are stored in Fouro's per-user database until you delete or replace them, subject to limited retention needed for security, billing, legal obligations, or reliable service operation. Automatic Memory is designed for stable preferences, relationships, routines, goals, and similar lasting context; it excludes transient details and sensitive information unless you explicitly ask Fouro to remember it. Each account can keep up to 20 memories, with no silent eviction at the limit. Each chat receives only a compact, recent subset of saved memories under a fixed context limit. Delete a conversation from its history row, and review, edit, or delete individual saved memories from Memory in the sidebar. For an account-level data request, follow the current guidance on the Support page. Saved chat storage has per-account conversation, message, and byte ceilings; reaching a ceiling does not silently delete existing conversations.
Security and changes
Fouro limits access to account data through authenticated, account-scoped requests, but no online service can guarantee absolute security. This notice may change as the product or its legal requirements change; the date above will be updated when it does.