How Necory protects what you tell it
A second brain only works if you can trust it. Here is exactly what we do — and one thing we deliberately don't, explained honestly.
Your data is kept safe
Everything travels between the app and us over a protected connection, and it's stored safely on Google's cloud — scrambled so it can't simply be read if someone got at the storage. Your uploaded photos and files get the same protection.
Only you can see your things
Everything you save — every note, message, file, reminder, and money record — belongs to your account, and no other user can reach it. When the assistant does something for you, it can only ever touch your own account. It has no way to open anyone else's, even if it tried.
The AI can act, but not lie about it
Necory's assistant is powerful, so we box it in on purpose:
- When it says it's done, it's done. If the reply says "saved" or "deleted", that exact thing really happened — it's checked, not just claimed.
- Necory does the money math, not the AI. It adds up your balances itself from the full history. The AI only writes down what happened; it never works out a total on its own.
- Nothing big is deleted without your yes. When you clear out a lot at once, it only happens after you confirm. The AI can't delete your things on its own.
- What you save is your content, never commands. Text hidden inside your files, images, or notes can't secretly give the assistant orders.
Signing in safely
- The one-time codes we email you are random, expire in 10 minutes, work only once, and are protected against guessing. We store them in a scrambled form we can't reverse, so even we never hold your actual code. Phone codes are handled by Google's secure sign-in — we never see them.
- When you set a password, we check whether it has appeared in known data breaches — without your actual password ever leaving your control.
- Signing in with Google or Apple uses their own standard, secure sign-in.
- You can require Face ID / fingerprint unlock to open the app. That check happens entirely on your phone and is never sent to us.
Your saved things check the app is real
Everything in your vault — every note, file and photo — sits behind a check that the app asking for it is the genuine Necory app from the official app stores, not a tampered-with or fake copy.
What we deliberately don't do — and why
Necory is not "end-to-end encrypted." That would mean sealing your content so that not even we could read it — but the assistant has to read it to answer you, and that's the whole point of the app. Your data is protected on the way to us and while it's stored, and only you can reach it, but our systems (and the AI that answers you) do see it in readable form to do their job. If you have something that no service should ever be able to read, a dedicated end-to-end-encrypted notes app is the right home for that particular thing. We'd rather tell you this straight than pretend otherwise.
Your controls
- Export your entire vault as a downloadable archive from Settings, on any plan.
- Delete individual items (30-day trash), whole conversations, all data, or your entire account — permanently, with a 30-day recovery window.
- Review the AI's memory: every learned observation is listed in Settings where you can confirm, dismiss, or lock it.
Reporting a vulnerability
If you believe you've found a security issue in Necory, email support@necory.com with the details. We read every report and will respond as quickly as we can. Please don't access other users' data while researching.