Fouro
AboutPrivacyTermsSupportFeedback

Privacy

Your data in Fouro

This notice explains the information Fouro needs to provide GPT-4o chat, saved history, optional memory, and subscriptions.

Last updated September 4, 2026

Your choices at a glance. Guest chats are not saved to Fouro history or Memory. Signed-in history and Memory belong to your account. AI-provider processing needs your permission; optional analytics has a separate choice. You can manage saved data in the app and change your analytics choice below.
InformationProvidersAnalytics choicesRetention and deletion

Information Fouro handles

When you create or use an account, Fouro receives identity details from Clerk, such as your account identifier, name, and verified email address. Fouro stores your account, conversations and messages, usage counters, subscription status, paid AI name and custom instruction settings, memories you save, conversation-local rolling summaries, and pending Memory suggestions that you can approve or dismiss. Fouro does not turn a suggested memory into a saved memory without your approval.

The iPhone app uses a random installation identifier for guest allowance and Clerk uses a native device identifier to protect sign-in sessions. After sign-in, device and account identifiers can be linked to your Fouro account for authentication, abuse prevention, synchronized history, and account security. Fouro does not use them for cross-company advertising tracking.

Signed-out visitors can use up to 5 guest requests per UTC day and 10 per UTC month per signed browser installation. Guest prompts, limited in-tab chat context, and responses are processed to answer the request but are not stored as Fouro conversation history or Memory. Refreshing or closing the page clears that guest context, and signing up does not import earlier guest chats.

To enforce guest and free-plan limits and reduce account-rotation abuse, Fouro uses a signed, pseudonymous browser-installation identifier and a one-way keyed network-address hash. These identifiers may be associated with your account for enforcement. Fouro does not store the raw network address or build an invasive device fingerprint. The browser identifier expires after one year. Inactive guest trial records are deleted after about 400 days; inactive shared security counter records become eligible for deletion after 45 days. Provider-attempt and completed reservation records are also retained only for a bounded operational period, while longer-lived aggregate usage events are periodically removed.

When you arrive through a tagged campaign link, Fouro may store the bounded source, medium, campaign, and content labels with that pseudonymous browser identifier. If you later sign in on the same browser, the first-touch labels may be associated with your account so Fouro can measure whether a campaign led to signup and product use. Fouro does not store the full referring page URL for this purpose. Attribution records are removed after about 400 days.

How providers process information

  • Clerk provides sign-in and account identity services.
  • OpenRouter receives your prompts and the conversation context needed to generate a response from its upstream GPT-4o provider, OpenAI, only after you explicitly allow this AI-provider processing. Triggered saved memories, a short conversation-local summary, and relevant excerpts from your own earlier signed-in conversations may be included in that context. When you explicitly request deeper recall, a bounded older portion of that same conversation may also be included. For an active Pro account, the AI name and custom instructions you save are also included. If you decline, Fouro sends no prompt or context to OpenRouter or OpenAI and chat stays disabled. You can revisit or revoke this permission from the chat surface on web or Settings on iPhone; revocation prevents future messages from being sent but cannot undo processing already requested.
  • Stripe handles checkout, payment methods, invoices, and subscription management. Fouro sends your verified account email and display name to Stripe so it can deliver receipts, invoice PDFs, and billing notices. Fouro stores billing identifiers and subscription status, not full card details.
  • Apple processes iPhone App Store purchases, subscription renewals, refunds, and subscription management. Fouro sends Apple a random account token when you purchase or restore Fouro Pro, verifies Apple-signed transaction and notification data, and stores the product, original transaction identifier, entitlement status, renewal status, and expiration date needed to synchronize Pro across iPhone and web. Fouro does not receive your full Apple Account credentials or payment-card details.
  • Cloudflare hosts the service and may process routine request, security, and diagnostic information needed to operate it. Cloudflare Workers AI creates numerical embeddings from signed-in conversation excerpts, and Vectorize stores those vectors under account-isolated namespaces. The vector index stores opaque chunk IDs, not the conversation text; Fouro resolves a match through its account-scoped database before it can be used. Cloudflare Web Analytics also measures page-load timing, Core Web Vitals, route paths, browser/operating-system categories, and affected layout elements. Its performance beacon does not use cookies or local storage and does not fingerprint individual visitors. Worker operations also produce structured diagnostic logs with a request identifier, normalized route, status, duration, release, and bounded error category. D1 keeps a content-free incident history with kind, severity, normalized route, occurrence count, release, timestamps, and recovery status. These operational records do not contain prompts, responses, account identity, cookies, or payment payloads.
  • Sentry receives minimized application errors, stack traces, release identifiers, and request correlation labels so Fouro can investigate incidents. Fouro removes request bodies, cookies, query strings, direct user identity, and conversation text before error events are sent. Sentry does not receive feedback form text or screenshots, and prompts and responses are not attached automatically.
  • PostHog receives, only after analytics permission, an explicit allowlist of product events, such as an app view, completed chat, quota result, upgrade view, checkout start, or feedback submission, plus content-free signup and subscription milestones. It may assign one of Fouro's approved interface or signup-prompt timing variants and receive the flag key and assigned variant so Fouro can compare those experiences. Fouro also records a 10% sample of production sessions whose visitors have explicitly allowed analytics to diagnose layout, navigation, focus, and stuck-state problems. Before replay data is uploaded, Fouro masks all text, form values, and element attributes. Conversation history, messages, the composer, account identity, sign-in and sign-up forms, Memory, AI settings, and feedback forms are blocked entirely. Console output, network timing and payloads, request headers, canvas content, cross-origin frames, and mouse movement are not recorded. Autocapture and person profiles remain disabled, and Do Not Track is respected. Fouro disables GeoIP enrichment, removes full URLs and referrers before business-event capture, and configures PostHog not to store client network addresses. Fouro does not send readable prompts, responses, feedback text, emails, account identifiers, or billing payloads to PostHog.
  • Meta receives the limited website-funnel events described below only after analytics permission, using its browser Pixel and server-side Conversions API with matching event IDs for deduplication.

Feedback and launch measurement

The optional feedback form stores your selected use case, two numeric ratings, the text you choose to submit, and whether a signed-in user consented to an interview. It does not attach chat prompts or responses. If you opt in while signed in, the founder dashboard may show your account email only for that interview request. Pseudonymous device labels and bounded campaign tags are used to prevent feedback spam and understand which launch messages lead to useful product use. Launch feedback is removed after about 400 days.

The Feedback button opens Fouro's signed-in feedback form for product problems, concerns, and suggestions. Submissions are stored in Fouro's database and shown only in the private founder dashboard. Do not include passwords, payment details, or private conversation text.

Optional product and advertising measurement starts only after you choose “Allow analytics” below. You can return to this page and withdraw that permission at any time. Without permission, Fouro does not initialize PostHog or the Meta Pixel and does not send funnel events through Meta's Conversions API.

When allowed, managed product analytics uses a pseudonymous browser analytics identifier stored by PostHog. It is not joined to your Fouro account identity. Fouro's own database also keeps a content-free experiment ledger containing the assigned variant, prompt-timing arm, prompt view or dismissal, signup start, random event ID, pseudonymous installation label, optional opaque account label, and timestamps. Synthetic and administrator activity is excluded from experiment reporting. Browser Do Not Track is respected. Fouro may also send Meta a deduplicated, content-free funnel event for a landing view, guest-chat start or completion, signup completion, first signed-in chat, or second active UTC day. Browser and server copies share a random event ID so the same action is counted once. Those events can include the page origin and path, timestamp, browser user agent, transport network address, and a one-way browser identifier as documented by Meta; they never include prompts, responses, conversation titles, Memory, email, Clerk IDs, Stripe IDs, or payment details. Clearing site data resets the browser analytics identifier and saved choice.

Product and advertising analytics are currently off.

Retention and your choices

Your AI-provider permission is stored with your Fouro account when signed in, or with the pseudonymous installation record when using guest chat. Fouro asks again if the disclosure materially changes. A denied choice is retained so Fouro can honor it without repeatedly sending or prompting, and can be changed at any time.

Signed-in conversations, semantic chunk pointers, rolling thread summaries, approved memories, pending suggestions, and paid AI settings are stored in Fouro's per-user database until you delete or replace them, subject to limited retention needed for security, billing, legal obligations, or reliable service operation. Memory suggestions are limited to explicitly stated, lasting, non-sensitive details and require your approval. Each account can keep up to 20 memories, with no silent eviction at the limit. Each chat receives only a compact, triggered subset of saved memories under a fixed context limit. You can assign a category and retrieval phrases to each memory. Signed-in chat uses the latest 10 messages as working context, keeps a compact thread summary refreshed periodically, and may retrieve a small relevant excerpt from older saved conversations. Explicit requests for same-thread recall can load a larger but bounded part of that thread. The Memory activity view stores only retrieval counts and modes, never prompt or response text. Semantic indexing runs in bounded daily batches, so very recent messages or large existing histories may take time to become searchable. Delete a conversation from its history row, and review, edit, or delete individual saved memories from Memory in the sidebar. For an account-level data request, follow the current guidance on the Support page. Signed-in users can permanently delete their Fouro account from Account settings on the web or Settings on iPhone. Account deletion removes Fouro's account-scoped data and sign-in identity, but deleting Fouro does not cancel an Apple subscription; manage or cancel an Apple-billed subscription through Apple first if you do not want it to renew. Saved chat storage has per-account conversation, message, and byte ceilings; reaching a ceiling does not silently delete existing conversations.

Security and changes

Fouro limits access to account data through authenticated, account-scoped requests, but no online service can guarantee absolute security. This notice may change as the product or its legal requirements change; the date above will be updated when it does.

Privacy | Fouro