How we treat a check-in.
Feneri Inc. Last updated 12 September 2026. This page describes the product as it works today. It is not legal advice.
The short version: you talk in the browser. We analyse that sitting to write a reflection for you. You choose how long the raw recording stays. We do not sell sessions. We do not use personal check-ins to train a public model. Questions: contact@feneri.xyz.
- Who we are
- What this covers
- What a check-in collects
- Footage and retention
- Account data
- Website, waitlist, contact
- Cookies and analytics
- Why we process it
- Who we share with
- How long we keep it
- Security
- Your rights
- International transfers
- Children
- What we do not do
- Changes
- Contact
Who we are
Feneri Inc. runs feneri.xyz, the Interface at /app, and the developer pages. We work from San Francisco, Riyadh and Cairo. There is no public street address on this site yet. Write to contact@feneri.xyz.
For personal check-ins, Feneri Inc. is the organisation that decides why and how that data is used. If you use the developer platform under a contract, that contract may name a different arrangement. This page is written for people using the Interface and this website.
What this covers
This policy covers:
- The personal Interface (the guided video check-in in the browser).
- This marketing website, including waitlist and contact forms.
- Sign-in at /login and /app.
It does not replace a data-processing agreement for API customers. Platform billing and logs for builder accounts are described in those contracts when they exist.
What a check-in collects
A sitting is a guided conversation of up to six minutes of recorded time, usually five questions. The browser asks for camera and microphone only when you press Begin. Until then, nothing is captured.
For each sitting we may process:
- Video and audio of you answering the prompts (face, voice, background of the room you chose).
- A transcript of what you said, produced by speech-to-text on that clip.
- Model outputs from face, voice and language together: emotion labels and strengths, sentiment, a balance score, timestamped moments, a short narrative, and related signals used to draw Insights.
- Session metadata: when it started, how long you recorded, template, language, the retention mode in force at the start, and whether the report is ready.
Distress cues in a sitting can surface local crisis resources in the Interface. That is a safety feature, not a diagnosis, and it is not an emergency service. See Policy.
Footage and retention
Raw media is uploaded so the engine can analyse that sitting. It is not a public gallery of faces. You pick one of three modes in the Interface (Start screen and You). The mode in force when you begin is copied onto that session.
| Mode in the app | What happens to raw video and audio |
|---|---|
| After 30 days (default) | Media is deleted by a daily sweep once the sitting is older than 30 days. |
| Right after analysis | Media is deleted when the sitting is finalised, after the reflection is written. |
| Kept until I delete | Media stays until you delete it or you ask us to delete the account. |
The reflection itself (scores, transcript of what you chose to say, narrative, Insights derived from completed sittings) stays in your private account so the last few weeks can be shown. Deleting media does not by itself erase that written record. Ask us if you want the account and its sittings removed.
A share link, if you create one, points at the written report and expires after 24 hours. A PDF is a file you download; once it leaves our servers, you control that copy.
Account data
When you create an account we store:
- Email, and display name and photo if the sign-in provider sends them (email and password, or Google).
- A personal workspace id, locale, last seen time, and your retention preference.
- Plan (
freeorpro). Free is two sittings per UTC day. Pro is not on sale yet; some team emails are on Pro while we build. - Access state (
waitlistoractive). New public accounts start on the waitlist until we admit them. - A session cookie so the Interface can call our API without sending your password on every request. The cookie is HttpOnly, Secure, SameSite=Lax, and lasts 14 days unless you sign out.
There is no self-serve “delete my account” button yet. Write to contact@feneri.xyz from the address on the account. We will delete or anonymise the profile, sittings and media we hold, except where we must keep a record (for example a fraud or abuse investigation, or a legal hold).
Website, waitlist, contact
The marketing site is public. If you join the waitlist we store the email (and name, if you give one) in a create-only waitlist collection, with the time and the page you used. We use that to tell you when access opens. We do not sell that list.
If you write via /contact or email, we receive the message, your email, and any name you left. Mail is sent with our email provider so we can reply. A copy may be stored so we do not lose the thread.
Cookies and analytics
We use a small set of cookies and similar storage:
- Sign-in. Firebase Auth keeps you signed in in this browser. The Interface session cookie is described above.
- Analytics. Firebase Analytics (Google Analytics 4) records page views and a few named events (for example a primary-button click, or a waitlist submit). It uses a Google measurement id on this site. We use it to see which pages work, not to build an advertising profile of your check-ins.
- Errors. Sentry receives crash reports from the website and our servers. A report can include a URL, browser version, and technical details of a failed request. We do not put raw check-in video in Sentry on purpose.
You can block analytics cookies in your browser. The Interface still needs the session cookie to run a sitting while you are signed in. Sign out to clear that cookie from this device.
Why we process it
We process this data to:
- Run the check-in you asked for, write the reflection, and show you Insights and past sittings.
- Enforce daily caps, the six-minute sitting limit, and the waitlist.
- Keep the service up, debug failures, and stop abuse.
- Reply when you write to us, and email waitlist people when access opens.
- Meet the law if we are required to.
Where a privacy law asks for a “legal basis,” the usual bases are: performing the service you request (the sitting and the account); our legitimate interest in running a secure, limited-alpha product; and consent where you optionalise a share link, a contact form, or a waitlist signup. If you are in a place that requires consent for analytics, treat the analytics section as optional and block it in the browser until we ship a finer banner.
Who we share with
We do not sell check-ins. We do not rent the waitlist. We use processors who run parts of the stack. They only get what that job needs.
| Processor | Job | Typical region |
|---|---|---|
| Google (Firebase Auth, Firestore, Cloud Storage, Analytics) | Sign-in, database, media files, page analytics | United States (Google Cloud) |
| Modal | Runs the analysis models on a sitting (video, audio, speech-to-text, text) | United States |
| Render | Hosts this website and the Interface | United States |
| Resend | Sends mail when you use the contact form | United States |
| Sentry | Error and crash reports | United States |
We may also disclose information if the law requires it, if we must protect someone from serious harm, or if we sell or merge the company (you would still have these commitments or a notice of change).
Feneri staff can use admin tools to keep the service running. Watching a private sitting is not a product feature. We do not put your face on a marketing page. Homepage screenshots use fixture copy and an invented name (Soren).
How long we keep it
- Raw media: according to the retention mode on that session (immediately after analysis, 30 days, or until you delete).
- Reflection and Insights: for as long as the account exists, unless you ask us to delete.
- Account: until you ask us to delete it, or it is closed for abuse.
- Waitlist and contact notes: until we have used them for that purpose and no longer need a record of the conversation, or you ask us to erase them.
- Share links: the token expires after 24 hours.
- Server logs and error reports: as long as we need them to operate and secure the service, then they age out.
Security
Sign-in uses Firebase Auth. API calls from the Interface use the session cookie. Media uploads use short-lived signed URLs to Cloud Storage. Analysis runs on our engine, not in your browser. No method is perfect. If we learn of a breach that affects your check-ins, we will write to the email on the account and say what we know.
Your rights
Depending on where you live (including the EU, UK, and some US states), you may have the right to access, correct, delete, or export personal data, to object or restrict certain processing, and to withdraw consent. California residents may also have rights to know, delete, and correct, and to not be discriminated against for asking.
We do not sell personal information as that term is used in the CCPA. We do not share it for cross-context behavioural advertising.
To use these rights, email contact@feneri.xyz from the address on the account. We may need to verify it is you. We will not charge a fee unless a request is excessive, and we will say so first. If a data-protection authority in your country is the right place to complain, you may do that as well.
In the Interface today you can already: change retention mode, download a PDF of a reflection, create a 24-hour share link, and sign out. Full account export and self-serve deletion are not in the app yet; email us.
International transfers
You may use Feneri from outside the United States. Processors above mostly run in the US. If you are in the EEA, UK or Switzerland, that is a transfer of personal data to the United States. We rely on the processors’ own transfer tools (such as Standard Contractual Clauses) where they offer them. If you do not want a sitting processed in the US, do not start one.
Children
The Interface is for people 18 or older. We do not knowingly collect check-ins from children. If you believe a person under 18 has an account, write to us and we will delete it.
What we do not do
- We do not sell your sessions or waitlist emails.
- We do not use personal check-ins to train a public model.
- We do not show your face on this website.
- We do not use a sitting as medical, legal or financial advice. The Policy says this again, because it matters.
Changes
When this policy changes in a way that affects how we treat check-ins, we will update the date at the top and, if the change is material, say so in the app or by email. The live page is the current version.
Contact
Privacy questions, access, correction, deletion: contact@feneri.xyz or the contact form.
Related: Policy (terms of use).