Privacy Policy
Last updated: September 18, 2026
1. Who We Are
philter.io is operated by Philter Inc., a Delaware corporation (“philter,” “we,” “us,” “our”). We build and run a workspace for each client engagement, where meetings, notes and mail come in and decisions, tasks, deliverables and briefs come out. This policy covers the workspace and the public site at philter.io, including the access-request form: what information we hold, how we use it, and who processes it on our behalf.
2. Information We Collect
Account information
Your name, email address, language, timezone and notification preferences, and your sign-in credentials. Access is by invitation only; there is no public sign-up. Sign-ins and access to shared material are recorded in an audit log.
Content you bring in
Meeting transcripts and recordings (from Fireflies.ai or pasted in), notes, email you forward to the workspace and its attachments (documents, images, audio), WhatsApp chat exports, voice notes, spreadsheets you share with our service account, and files behind share links you paste (Dropbox, Google Drive). From this material the platform derives decisions, tasks, deliverables, deadlines and briefs, which members review.
Connected services and forwarded mail
When you connect Fireflies.ai, we access what the API key you provide permits, and we store that key encrypted. When you forward or copy mail to the workspace’s intake address, we receive the message and its attachments, including the names and email addresses of its senders and recipients, and we check the message’s authentication before acting on it. Where a message is held for a member’s review, the review card shows the sender’s address and the recipients’ names and domains only.
Usage data and error reports
On the public site, PostHog collects anonymous usage data (page views, clicks) under a random identifier stored in your browser. In the workspace, analytics are tied to your membership identifier — a random id, not your name or email — and reset when you sign out. Error reports are collected via Sentry with the same identifier and a scrubbed description of the page, never the content on it. We do not sell this data or share it for advertising.
Access requests
When you request access through philter.io, we collect your name, work email, company, role, an indication of project scale and any message you write. The request is stored, sent to us by email, and added to our contact list at Resend so that we can answer you and, unless you ask us not to, tell you about philter.
Cookies
In the workspace, strictly necessary cookies keep you signed in. On both the public site and the workspace, PostHog stores an analytics identifier in your browser (a cookie and local storage). We set no advertising cookies.
3. How We Use Your Information
- Provide, maintain and improve the workspace
- Analyze the material you bring in with AI and propose decisions, tasks, deliverables and deadlines for your team’s review; a few measured, reversible kinds of update the platform applies itself and marks as its own
- Send briefs, digests and notifications by email, in your language and timezone
- Keep an auditable record of what was decided, by whom, and from what
- Answer access requests and, unless you ask us not to, contact requesters about philter
- Respond to support requests
- Protect the service, including rate limiting and abuse prevention
4. Data Storage and Security
Your data is stored on Supabase (PostgreSQL and file storage) in the United States. The application server is the only path to the database; browsers never reach it directly. All data is encrypted in transit (TLS) and at rest, credentials for connected services are stored encrypted, access is tiered per member, and every access to shared material is logged.
5. Data Sharing
We do not sell your data. We share data only with the service providers necessary to operate the platform, each processing it only to deliver its service and under its data processing agreement:
- OpenAI (AI processing — the runtime provider; processes your content to return a result and does not train on it)
- Anthropic (AI processing — the failover provider, on the same terms)
- Supabase (database and file storage)
- Vercel (application hosting)
- Trigger.dev (background processing — the AI analysis and scheduled sends run there)
- Resend (email — sending, receiving mail forwarded to the intake address, and holding the contact list of access requesters)
- Deepgram (speech-to-text for voice notes)
- Langfuse (AI observability — records the prompts and outputs of AI runs for quality review)
- PostHog (product analytics)
- Sentry (error monitoring)
- Upstash (rate limiting — request identifiers and IP addresses only)
These providers run primarily in the United States. Fireflies.ai, Google Drive and Dropbox are sources you connect or link; we read from them and send them nothing of yours.
6. Data Retention and Deletion
Your data is retained for the duration of your engagement. Items you delete are archived: they leave every view but remain in the workspace’s record so that a decision can be traced to what produced it. Permanent deletion of an item, an account or the whole workspace happens on request, and at the end of an engagement as agreed. An access request is kept for as long as we may follow it up; you may ask us to delete it, or to stop contacting you, at any time. To request deletion, contact us at founders@philter.io.
7. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us. If you are in the EU or EEA, you also have the right to lodge a complaint with your data protection authority. You may end a connected service at any time by revoking its key with the provider or asking us to remove it, which ends our access to that service’s data.
8. Changes
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice.
9. Contact
Questions about this policy? Email us at founders@philter.io.