Salon Privacy Policy

Effective date: August 30, 2026

What we collect

Salon stores your conversations so the authors can remember what you have discussed. Your chat history, the topics the authors remember about you, and your reading preferences are saved. Your display name, if you provide one during onboarding, is stored on your device.

Anonymous identity

We do not require an account. The app identifies you through an anonymous device identifier provided by RevenueCat, our subscription manager. This identifier is a random string and contains no personal information.

What stays on your device

Your name, reading preferences, tone settings per author, and your daily usage count never leave your device, unless you deliberately share your reading tastes when subscribing to our email dispatch (see below). Clearing the app data or uninstalling removes them permanently.

Email, if you offer it

The app and this website invite you to subscribe to the Sunday dispatch, a weekly email letter. If you subscribe, we store your email address, a record of your confirmation, and any reading tastes you deliberately share with us so the letters can be relevant. Email is delivered through Resend. Subscription is double opt-in: nothing is sent until you confirm from the first email, and every email carries a one-click unsubscribe link. If you subscribe from inside the app, your anonymous app identifier is linked to your address so product moments (for example, running out of free messages) can trigger relevant letters; that link is removed when you unsubscribe, and unsubscribed addresses are deleted on our regular hygiene cycle.

What is sent to our servers

When you send a message, the app sends your conversation history and what the author remembers about you to our server so the author can respond in context. The author's reply is generated by Anthropic's Claude through OpenRouter.

Generated audio

If a Premium reader asks to hear a supported author voice, our server sends the selected author reply to ElevenLabs to create the audio. We do not send your name, subscription identifier, or conversation history with that request. The server does not cache the audio. The app may keep a limited audio cache on your device for up to seven days; signing out or uninstalling clears that app-managed cache.

Book information and covers

If the optional book-data integration is enabled, our server sends a book title or an author's public name to Hardcover to retrieve book details and cover art. We do not send your messages, reading history, device identifier, or subscription status with those requests. The app loads cover images through our server, so your device does not connect directly to Hardcover or its image host.

Reports and legal requirements

If you report a conversation, the reported portion may be reviewed by the developer. Content connected to a report about child safety, or to a legal request, is retained and may be disclosed to the National Center for Missing and Exploited Children or to law enforcement as required by United States law (18 U.S.C. 2258A). We never use your conversations to train models.

Subscriptions

Premium subscriptions are processed entirely by Apple through the App Store. We never see your payment details. RevenueCat helps us verify your subscription status using an anonymous identifier.

Data retention and deletion

Conversations are kept until you ask us to delete them so the authors' memory and your history survive reinstalls. To request deletion of everything tied to your anonymous identifier, email joeytowbin@gmail.com and we will remove your conversations, memories, and session records. Signing out from Settings revokes your session but does not by itself delete stored conversations; emailing us deletes them for good. The only exception is content we are legally required to preserve after a safety report.

Contact

Questions about this policy: joeytowbin@gmail.com