Privacy policy

Sutyo AI Privacy Policy

Updated: August 20, 2026
Effective Date: August 20, 2026


Introduction

This App is operated by Sutyo Futurestyle Inc. (registered address: 5900 Balcones Drive STE 100, Austin, TX 78731, USA), which acts as the data controller of your personal data (hereinafter referred to as the "App" or "we"). We recognize the importance of your personal data. We strictly comply with applicable laws and regulations and adhere to industry-standard security practices to protect the security of your personal data. This Privacy Policy is intended to explain how we collect, use, store, share, and protect your personal data, as well as the rights you have regarding your personal data.

Applicability across platforms: This Policy applies to both the iOS and Android platforms. The Android Google Play version (listed as "Sutyo AI") delivers push notifications via Firebase Cloud Messaging (FCM); the iOS version delivers push notifications via Apple Push Notification Service (APNs).

Before using this App, please carefully read and fully understand this Privacy Policy, in particular the clauses highlighted in bold. This Privacy Policy helps you understand how we process your personal data and the rights you have. We rely on different legal bases for different types of processing (see Section 2); where processing relies on your consent (such as audio recording, usage analytics, and push notifications), we obtain that consent separately in the relevant context, and you may withdraw it at any time. If you do not agree with any provision of this Privacy Policy, please discontinue use of this App.


1. Information We Collect

1.1 Information You Voluntarily Provide

Information Type Details Purpose of Collection
Account Information Mobile phone number or email address Account registration, login verification, identity authentication
User Profile Nickname, avatar (provided as a URL), country code Enhancing user profile and providing personalized services
Feedback Opinions, suggestions, complaints you submit Service improvement and issue resolution

1.2 Information Collected Automatically During Use

Information Type Details Purpose of Collection
Device Information Device model, operating system version, device identifiers (Firebase Installation ID, Mixpanel distinct ID) Push services, app analytics, device adaptation, account security
Log Information App operation logs, user behavior logs Troubleshooting, service optimization, security auditing
Crash Information Stack traces and device state at the time of a crash Problem identification and resolution, app stability improvement
Network Information IP address, network connection status, carrier information Network optimization, security protection
Audio Processing Data Recording duration, audio format, number of channels, sample rate Optimizing audio processing quality and improving user experience
Location Information Precise location based on device GPS (collected only when you use the relevant features) To present content relevant to your location

1.3 Audio Data (Core · Sensitive Personal Data)

Audio recording is the core functionality of this App, and recorded audio constitutes sensitive personal data.

  • Collection method: Audio is recorded via the phone's microphone.
  • On-device processing: Your audio recordings are transcribed to text entirely on your device. The audio itself is never uploaded to our servers or shared with any third party. We do not perform voiceprint recognition and do not create biometric identifiers from your voice.
  • Purpose of use: Audio is used solely to generate a transcript on your device. The resulting transcript text (not the audio) is then used for AI processing such as summaries, memory, insights, and conversations.
  • Local storage and retention: Audio recordings are stored only on your device. By default they are automatically deleted after 7 days, and you can delete any recording yourself at any time within that period. Once deleted from your device, a recording cannot be recovered.
  • Consent: When you first enable the recording feature, this App displays a separate prompt to inform you and obtain your explicit consent. If you decline, the recording feature will be unavailable, but this will not affect your use of other features of this App.

1.4 Derived Data from Speech Recognition and AI Processing

Derived Data Type Details Generation Stage
Transcription Text Text content generated by on-device speech recognition (ASR) Recording transcription
AI-Generated Content Meeting summaries, memory, insights, AI conversation replies, etc. AI processing

2. How We Use Collected Information

The personal data we collect will be used for the following purposes:

Purpose Description Legal Basis (GDPR)
Provide core services On-device speech recognition (ASR), meeting summary generation, memory and insight extraction, AI conversations, etc. Performance of a contract (Art. 6(1)(b)); processing of audio recordings is additionally based on your consent (Art. 6(1)(a))
Account security Identity verification, anomalous login detection Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Push notifications Sending you sync reminders and service update notifications Consent (Art. 6(1)(a))
Service improvement Analyzing app usage to optimize features and user experience Consent (Art. 6(1)(a))
Crash analysis Monitoring app operational status to quickly identify and resolve issues Legitimate interests (Art. 6(1)(f)); consent (Art. 6(1)(a)) where required by law
Compliance and security Satisfying legal and regulatory requirements and ensuring network and information security Compliance with a legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))
Location-based content Presenting relevant content based on your precise location Consent (Art. 6(1)(a))

De-identification / anonymization: We may, on the premise that specific individuals cannot be identified and the data cannot be restored after technical processing, use de-identified data for statistical analysis, product optimization, and other purposes.


3. System Permissions

To provide full service functionality, this App requires the following system permissions.

3.1 Android (Google Play Version) Permissions Table

Permission Purpose Required
INTERNET Network communication; access to cloud AI services and file storage Yes
ACCESS_NETWORK_STATE Detect network status Yes
RECORD_AUDIO Record audio for real-time speech recognition Yes
READ_MEDIA_AUDIO / READ_EXTERNAL_STORAGE (maxSdk32) Read audio files for import and transcription No
POST_NOTIFICATIONS Push notifications (sync reminders / service updates) No
FOREGROUND_SERVICE + FOREGROUND_SERVICE_DATA_SYNC + FOREGROUND_SERVICE_MICROPHONE Process recording transcription / cloud inference / live recording in a foreground service so that tasks continue when the App goes to the background Yes
WAKE_LOCK Prevent the device from sleeping during transcription / inference Yes
ACCESS_FINE_LOCATION Obtain precise location to present content relevant to your location No
BLUETOOTH_CONNECT Connect Bluetooth devices (such as Bluetooth headphones) to use their microphone for audio recording No

Note: This App has removed the advertising ID permission (AD_ID) and does not collect advertising identifiers. This App does not request permissions related to the Companion Device Manager. Location and Bluetooth permissions are used only for optional features; you may decline them without affecting core functionality.

3.2 iOS Permissions Table

Permission Purpose Required
Microphone Record audio for real-time speech recognition Yes
Speech Recognition Automatically convert recordings to text Yes
Notifications Remind you to sync recording data and push important information No
Location (While Using the App) Obtain precise location to present content relevant to your location No
Bluetooth Connect Bluetooth devices (such as Bluetooth headphones) to use their microphone for audio recording No

You may enable or disable these permissions at any time in your device's system settings. However, disabling required permissions will prevent the corresponding features from functioning properly.

3.3 Foreground Services Disclosure

The Android Google Play version of this App uses the following 3 foreground services:

Foreground Service Type Purpose
OfflineTranscriptionForegroundService dataSync Offline speech transcription
ContentJobCloudInferenceForegroundService dataSync Cloud inference
SenseMicForegroundService microphone Keeps the microphone active during live "Sense" recording
  • Purpose description: After you initiate a recording / transcription / inference task, the foreground service ensures that the task completes and no data is lost even if the App goes to the background. While the foreground service is running, a persistent notification is displayed in the system notification bar.
  • Scope of data processing: The foreground service only processes the audio/text data involved in tasks you have actively initiated. It does not proactively activate the microphone, nor does it collect any data without your action.

4. Third-Party SDKs and Information Sharing

This App integrates the following third-party SDKs to deliver specific functionality. Details of the data collected by each SDK are as follows:

4.1 Push Notifications

SDK Provider Personal Data Involved Purpose Privacy Policy Link
Firebase Cloud Messaging Google LLC Device identifiers (Firebase Installation ID), device information Push notifications Link

4.2 App Analytics and Crash Reporting

SDK Provider Personal Data Involved Purpose Platform Privacy Policy
Mixpanel Mixpanel Inc. Device identifiers (Mixpanel distinct ID), app usage data Product analytics and user behavior analysis Android + iOS Link
Firebase Crashlytics Google LLC Device information, app crash logs, device identifiers Crash monitoring and analysis Android + iOS Link

Note: Analytics and crash reporting data collection is controlled by user consent toggles (see "Consent Management for Data Collection" below). For EU/EEA users, these are opt-in only. This App does not use the advertising ID.

4.3 Speech Recognition and Audio Processing

Speech-to-text transcription runs entirely on your device. Your audio is not sent to any third-party speech recognition provider, and it is not used to create voiceprints or other biometric identifiers.

Engine Provider Personal Data Involved Purpose Privacy Policy
On-device speech recognition (Android) Open-source model Audio data (processed entirely on-device, not uploaded) On-device speech-to-text —
System speech recognition (iOS) Apple Inc. Audio data (processed on the iOS device) On-device speech recognition Link

4.4 AI Services

Service Provider Personal Information Involved Purpose Privacy Policy
Third-party Large Language Model API Third-party AI service provider based in the United States Transcript text, AI conversation content (does not include raw audio) Memory generation (summaries, to-dos, key points), AI chat responses
AI Workflow Engine Self-hosted server Text transcription content (does not include raw audio) AI workflow orchestration, content processing pipeline — (self-hosted)

We may change the third-party AI model provider based on service quality, availability, or business needs.

How AI Processing Works

Because AI-powered memory generation is central to Sutyo's functionality, we want to be transparent about how your data flows through AI systems:

  • On-device transcription: Speech-to-text conversion runs locally on your device. Your audio recordings are not sent to our servers or any third party for transcription purposes.
  • Server-side AI processing: Your transcript text (not audio) is sent to a third-party AI service provider to generate summaries, extract key points, create to-dos, and power AI chat responses. This processing is orchestrated through our self-hosted AI workflow engine.

AI Data Handling

  • Your content is transmitted to the AI service provider via encrypted connection (TLS 1.2+).
  • The AI service provider may temporarily retain your data for a limited period for safety and abuse monitoring purposes, in accordance with their applicable terms of service, after which it is deleted.
  • Processing may occur in the United States or other countries where the provider maintains infrastructure. For transfer safeguards, see Section 5.4.
  • We contractually require that our AI service providers do not use your content to train, improve, or fine-tune their general-purpose AI models.

Important: Our current AI service provider processes your data under their API Terms of Service. We cannot independently verify all aspects of the provider's internal data handling.

4.5 Data Storage

Your audio recordings are not stored in the cloud. They are kept only on your device and, by default, are automatically deleted after 7 days.

4.6 Consent Management for Data Collection

To ensure you have control over your personal data collection, this App provides the following consent management mechanisms:

Consent Options

This App seeks your consent before collecting data in the following three areas:

Consent Option Related Service Default (EU/EEA) Default (Non-EU) Legal Basis
Analytics Data Collection Mixpanel product analytics Off (opt-in required) On (can be turned off) Consent (GDPR Art. 6(1)(a))
Crash Reporting Firebase Crashlytics Off (opt-in required) On (can be turned off) Consent or legitimate interest (GDPR Art. 6(1)(a)/(f))
Push Notifications FCM (Android) / APNs (iOS) Off (opt-in required) On (can be turned off) Consent (GDPR Art. 6(1)(a))

Note: Crash reporting serves our legitimate interest in maintaining app stability and security (GDPR Art. 6(1)(f)). Where consent is required by law (EU/EEA), we collect crash data only after you opt in. In all regions, you may disable crash reporting at any time.

Regional Differences

  • EU/EEA Users: On first launch, a consent dialog is displayed with options defaulting to off. You must actively check each option to enable the corresponding data collection. This approach ensures compliance with the GDPR's requirement for freely given, specific, informed, and unambiguous consent.
  • Non-EU Users: All options are enabled by default. You may disable any option at any time in Settings.

EU/EEA region detection is based on your SIM card country code or system language region setting.

How to Manage Consent

You can manage the above consent options at any time in the App under "Settings → Privacy & Security". Each option has an independent toggle. Disabling any option triggers a confirmation dialog informing you of the impact.

Withdrawing Consent

You may withdraw your consent at any time by disabling the corresponding option in Settings. Withdrawing consent does not affect the lawfulness of data collection and processing carried out based on your prior consent.

4.7 Sharing Features

Sutyo allows you to share memories with others via share links. When you create a share link:

  • The memory content you choose to include becomes accessible to anyone who has the link.
  • Share links are accessible on the public internet. If a link is posted publicly, it may be discoverable by others.
  • Shared content does not include your original audio recording unless you explicitly choose to include it.
  • To revoke a share link, delete the original memory from your account. Once the memory is deleted, all associated share links become immediately inaccessible.
  • Once you share content via a link, you cannot control what recipients do with it (e.g., copy, screenshot, forward).

Please treat share links as you would any publicly accessible URL. Do not share links containing sensitive information in public forums or with untrusted parties.


5. Information Storage and Protection

5.1 Storage Location

Your audio recordings are stored only on your device and are not uploaded to our cloud servers. Other data, such as your account information and the memories generated from your transcripts, is stored on cloud servers. The service used for AI workflow orchestration is deployed on our self-hosted servers.

5.2 Retention Period

We retain your personal data only for the minimum period necessary to fulfill the purposes of collection, unless otherwise required by applicable laws and regulations. Once the necessary period has expired, we will delete or anonymize your personal data.

In particular, audio recordings are stored only on your device and are automatically deleted after 7 days by default. You may also delete any recording yourself at any time within that period.

5.3 Security Measures

We have adopted security measures consistent with industry standards to protect your personal data. All data transmission is encrypted. Specific measures include, but are not limited to:

  • Encrypted data transmission: Data transmission between the App and servers is encrypted using HTTPS/TLS;
  • Access control: Strict access permission controls are implemented on servers and databases;
  • Security auditing: Regular security assessments and vulnerability scanning are conducted;
  • Security incident response: An information security incident response plan is in place. In the event of a security incident, you will be notified in a timely manner.

Despite adopting the above protective measures, please understand that due to technical limitations and potential malicious attacks, we cannot guarantee the absolute security of information. If your personal data is compromised due to a security incident, we will notify you in a timely manner and report to the relevant regulatory authorities as required by law.

5.4 Cross-Border Data Transfer

Your audio recordings are processed and stored only on your device and are not transferred across borders. For other personal data, this App uses service providers located in the United States (Google, Mixpanel, Firebase). Such data may be transferred to and processed in the United States or other countries where these providers maintain infrastructure. We ensure that such transfers are governed by appropriate safeguards, including but not limited to Standard Contractual Clauses (SCCs) approved by the European Commission, in accordance with GDPR Chapter V.


6. Your Rights

Under the GDPR and applicable data protection laws and regulations, you have the following rights:

Right Description How to Exercise
Right of access You have the right to access the personal data we hold about you View within the App under "Settings – Profile"
Right of rectification You have the right to request correction of inaccurate personal data Modify within the App or update under "Profile"
Right of erasure You have the right to request deletion of your personal data under certain circumstances Contact customer support via email to apply
Right of account deletion You have the right to delete your account and all data associated with the account Use "Settings – Account – Delete Account" within the App, or contact customer support. After deletion, all your data will be permanently removed within 30 days
Right to withdraw consent You have the right to withdraw previously given consent Disable the corresponding option in Settings → Privacy & Security, or contact customer support
Right to data portability You have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to have it transmitted to another data controller where technically feasible Contact customer support via email to apply
Right to restriction of processing In certain circumstances, such as while you contest the accuracy of your data, you have the right to request that we restrict the processing of your personal data Contact customer support via email to apply
Right to object Based on your particular situation, you have the right to object at any time to our processing of your personal data that is based on legitimate interests Contact customer support via email to apply
Right to lodge a complaint If you believe our processing of your personal data infringes applicable law, you have the right to lodge a complaint with the data protection supervisory authority in your place of residence or habitual residence Contact the relevant data protection supervisory authority directly

In-App Controls

Control Where to Find It
Push notifications Settings → Notifications
Analytics data collection Settings → Privacy & Security
Crash reporting Settings → Privacy & Security
Don't save local audio Settings → Privacy & Security
Delete all recordings Settings → Privacy & Security
Delete a specific memory Enter any memory card → Delete
Edit your name Settings → Account
Delete your account Settings → Account → Delete Account
Revoke a share link Delete the original memory

We will respond to your request within one month of receipt. We may extend this period by two further months where necessary, taking into account the complexity and number of the requests. We will inform you of any such extension within one month of receipt of the request. We may ask you to provide relevant information to verify your identity.

Please note: Withdrawal of consent does not affect the lawfulness of personal data processing carried out based on your prior consent. Prior to completing deletion or account cancellation, we have an obligation to retain certain necessary information as required by applicable laws and regulations.

We may be unable to respond to your request under the following circumstances:

  • Related to obligations under applicable laws and regulations;
  • Directly related to national security or national defense;
  • Directly related to public safety, public health, or significant public interests;
  • Directly related to criminal investigations, prosecutions, trials, or enforcement of judgments;
  • We have sufficient evidence that you are acting with subjective malice or abusing your rights;
  • Necessary to protect the life, property, or other significant legitimate interests of you or another individual, where obtaining consent from the individual is difficult;
  • Responding to your request would cause serious harm to the legitimate interests of you or another individual or organization;
  • Involving trade secrets.

7. Protection of Minors

7.1 This App is primarily intended for adults. If you are a minor under the age of 18, please read this Privacy Policy with the accompaniment and guidance of your legal guardian, and obtain the explicit consent of your legal guardian before using this App.

7.2 For children under the age of 16 in the EU/EEA (or such lower age as may be set by applicable member state law), the processing of their personal data is only lawful where consent is given or authorized by the holder of parental responsibility.

7.3 For users in the United States: This App is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental or guardian consent, we will delete it as soon as possible. If a parent or guardian believes their child has provided us with personal information without their consent, they may contact us using the details at the end of this Privacy Policy to review or delete that information or to refuse its further collection.

7.4 We do not proactively collect personal data from minors. If we discover that we have collected personal data from a minor without verifiable guardian consent obtained in advance, we will delete the relevant data as soon as possible.

7.5 If a minor's guardian has questions about our processing of the minor's personal data, please contact us using the contact details at the end of this Privacy Policy.


8. Cookies and Related Technologies

This App itself does not use cookies. When you access web content through the in-app WebView, the relevant websites may use cookies and similar technologies. The use of such technologies by those websites is governed by their respective privacy policies.


9. Updates to This Privacy Policy

9.1 We may update this Privacy Policy from time to time. When updated, we will notify you within the App via pop-up or notification and publish the latest version on this page.

9.2 For material changes, we will provide more prominent notice (including but not limited to in-app pop-ups, in-app announcements, email notifications, etc.).

Material changes referred to in this Privacy Policy include but are not limited to:

  • Significant changes in our service model, such as changes in the purposes of personal data processing, types of personal data processed, or methods of using personal data;
  • Significant changes in our ownership structure or organizational framework, such as changes of owner due to business adjustments, bankruptcy, mergers and acquisitions, etc.;
  • Changes in the primary recipients with whom personal data is shared, transferred, or publicly disclosed;
  • Significant changes in your rights regarding personal data processing and how to exercise them;
  • Changes in the department responsible for personal data security, our contact information, or complaint channels.

9.3 If you do not agree with the updated Privacy Policy, please discontinue use of this App. Your continued use constitutes acceptance of the updated Privacy Policy.


10. Contact Us

If you have any questions, comments, or suggestions regarding this Privacy Policy, or if you wish to exercise your personal data rights, please contact us at:

  • Company: Sutyo Futurestyle Inc.
  • Address: 5900 Balcones Drive STE 100, Austin, TX 78731, USA
  • Email: dev@sutyo.ai
  • Website: https://www.sutyo-eyewear.com/
  • GDPR inquiries: Please contact us at the email above.

We will respond to your request within one month of receipt, in accordance with GDPR Article 12. We may extend this period by two further months where necessary, taking into account the complexity and number of the requests. We will inform you of any such extension within one month of receipt.


Appendix A: iOS Permission Prompt Reference

To help you better understand the purpose of each permission, the following are the original prompt messages displayed when the iOS system requests permissions:

Permission Prompt Message
Microphone Sutyo AI needs access to your microphone for voice recording.
Speech Recognition Sutyo AI needs speech recognition permission to automatically convert recordings into text.
Notifications Sutyo AI needs to send notifications to remind you to sync your recording data.
Location Sutyo AI needs your location while you use the relevant features to present content relevant to your location.
Bluetooth Sutyo AI needs to connect Bluetooth devices (such as Bluetooth headphones) to use their microphone for audio recording.

Appendix B: Android Permission Prompt Reference

To help you better understand the purposes of each permission in the Android Google Play version, the following are the prompt descriptions for the relevant permissions:

Permission Prompt Message
Microphone (RECORD_AUDIO) Sutyo AI needs access to your microphone for voice recording and real-time speech recognition.
Notifications (POST_NOTIFICATIONS) Sutyo AI needs to send notifications to remind you to sync your recording data and service updates.
Foreground service (runtime system notification bar text) Sutyo AI is performing a speech transcription / cloud inference / data synchronization task. Tap to return to the App.
Location (ACCESS_FINE_LOCATION) Sutyo AI needs your precise location to present content relevant to your location.
Bluetooth (BLUETOOTH_CONNECT) Sutyo AI needs to connect Bluetooth devices (such as Bluetooth headphones) to use their microphone for audio recording.

Last updated: August 20, 2026

Sutyo AI Privacy Policy

dev@sutyo.ai  ·  sutyo-eyewear.com