Uxen Privacy Policy
This describes exactly what the software actually does.
1. Who we are
Uxen is a personal assistant over your own correspondence. The service is operated by Ilya Romanovich Romanov, a self-employed individual (professional income tax regime), Russian Federation.
Questions about your data: privacy@rrrfirstchat.com. We answer from this address, and it is the address to use for any request described in this policy.
We deliberately do not publish a phone number here. A privacy policy is a public page that contact scrapers read, and a number published on it stays in spam databases permanently. Write to the address above and we will reply.
2. The short version
Uxen answers questions about correspondence you connected: your mail, Telegram, WhatsApp, MAX, your calendar. Nothing connects without an action by you, and any source disconnects in one step.
To answer, Uxen has to read that correspondence — and to make it searchable, the text is sent to our AI provider. That is the single most important fact in this document, and section 5 states it plainly rather than burying it.
Uxen can write to people on your behalf — but only where you switched that on yourself. By default it writes to no one: both the autoreply and the “write for me” drafts are off until you turn them on with your own hand. Since 17 August 2026 this includes email: a separate button lets you allow sending letters on your behalf and sorting them into folders (mark read, archive, apply a label). Uxen cannot delete email and does not ask for that permission. A draft never leaves without your tap. Every word said on your behalf is recorded and stays visible to you. Before 16 August 2026 the software had no such path at all; the owner enabled it then, and this paragraph describes how it works today.
3. What we collect
To sign you in. Your email address, and — if you use them — the account identifier and email that Sign in with Apple or Google Sign-In returns to us. There is no password: email sign-in uses a one-time code, and the code itself is never stored, only a keyed hash of it, usable once.
To run the app. An account identifier, a device identifier, the device name, platform and app version, and — when you allow notifications — a push token.
Your account history. A short log of sensitive account actions: when a sign-in method was linked, confirmed, declined or unlinked, and when we saw the same email on two accounts. It records what happened and when. It never contains passwords, codes or tokens.
Content of the sources you connect. Message and email text, subject lines, sender and recipient names and addresses, dates, chat names, calendar events, and — if you connect it — your Google contacts. This is the product: without the content it cannot answer a question about the content.
Attachments: files, voice messages and photos. The product extracts TEXT from what you send and stores only that. Reading files is always on; understanding voice messages and photos are separate capabilities that the service owner turns on and off, and while they are off the product does not open such attachments and sends them nowhere. As of this edition, understanding of voice messages and photos is off; when it is on, it works like this:
What this means for each kind:
- file (document, spreadsheet, presentation) — the text already inside it is extracted on our server, without sending it anywhere;
- voice message and audio — a transcript of what was said;
- photo and image — a description of what is in it, and any text visible on it.
Calls: the fact that a call happened. Since 16 August 2026 the product sees, in the messengers you connect, the FACT of a call — with whom, when, incoming or outgoing, answered or missed, how long it lasted and whether it was video. This exists so that “when did I last speak to my mother” has an answer: a voice conversation is as much a part of your connection with a person as the text is.
The content of a call is not recorded and cannot be. The product does not listen to calls, does not join them and keeps no audio: the messengers hand over only the facts listed above, and only what they hand over is stored. This record lives as long as your messages do, and is removed by the same buttons — “erase this source's data”, “delete all data”, and account deletion.
The file, the recording and the picture itself are not kept. The product stores what it understood, not what it understood it from — the same line it draws for profile pictures. The bytes live in process memory only as long as it takes to extract the text, and never reach disk.
How the text was obtained is stored with it — read, heard or seen. This is not a technical detail: the assistant must never say “they wrote” about something that was spoken aloud or read off a picture, and this marker is how it tells them apart.
Transcripts and descriptions go to the model provider on the same terms as message text — see section “5. Who else receives your data”.
How long this lives. A file you attached to a question is remembered the way your correspondence is: the text understood from it becomes part of memory and stays there while you use the product. Deleting the CONVERSATION does not remove it — you sent that file about your life, not about that chat; “Erase all data” and deleting your account remove it, as they remove everything else.
A file you picked but never asked about disappears within a day. Until then the text understood from it waits for your question in a service record next to your in-app conversations — the only place where it lives separately, and it lives there no longer than a day.
What is known about the people you correspond with. To recognise the same person across different messengers and to answer “who is this”, the product stores what the messenger states about your correspondent and what they published about themselves: their name and the name they call themselves by, their username, phone number, email address, the birthday from their profile, their “about” text, a link to their profile picture, and — from Google Contacts — their organisation and job title if you recorded those there.
A phone number is the only signal on which the product links the same person across messengers silently; a matching name never links people, it only proposes. We store a link to a profile picture, never the picture itself. No additional requests are made to obtain any of this: all of it arrives in the responses the messenger already sends while the product reads your correspondence. An “about” text is written by that person, and the product treats it as somebody else's words — never as a fact, and never as an instruction.
Your conversation with the assistant. The questions you ask and the answers you get.
To connect a source. For Telegram and MAX, the phone number, the login code, and — if your account has two-factor authentication — the cloud password of that messenger. These are passed straight through to the messenger to complete the login. They are never written to our database and never written to a log.
When you pay. The amount, the date, and the payment reference. Card details never reach us — they are entered on the payment provider's side and do not pass through our servers at any point.
Technical logs. Identifiers, chat names, counts and timings — the records that let us find a fault. They do not contain message text.
4. What we use it for — all of it
We use the data above only for these purposes:
- to answer your questions about your own correspondence;
- to build and maintain the searchable memory that makes answering possible;
- to sign you in and keep you signed in across your devices;
- to keep your account secure and to investigate abuse of the service;
- to send you service messages — a sign-in code, a warning before anything is deleted, a notice that a connection has broken;
- to take payment and manage your subscription;
- to find and fix faults, and to see whether the product works at all;
- to comply with the law where we are legally required to.
There is no other purpose. We do not use your data for advertising, we do not build advertising or behavioural profiles, we do not sell it or share it with data brokers, and we do not combine it with data from other services to track you.
5. Who else receives your data
We name every recipient, because a recipient we did not name is a recipient you could not have agreed to.
OpenAI — the AI models. Two distinct flows, and the second is larger than people expect:
- when you ask a question, your question and the fragments of correspondence relevant to it are sent to OpenAI to compose the answer;
- to make your correspondence searchable at all, the text of everything Uxen indexes is sent to OpenAI to be turned into numerical vectors. This happens in the background, not only when you ask.
So: the content of your correspondence leaves our server and is processed by OpenAI. We use their API under terms that exclude using this traffic to train their models.
Google — only if you connect Gmail, Calendar or Contacts. We call Google's APIs on your behalf, under the permission you granted. By default the permission is read-only in all three cases — the product changes nothing of yours and sends nothing anywhere.
Write permissions exist, and each one is switched on by you SEPARATELY — its own button and its own Google consent screen. Until you allow it, the product does not do it at all. You can withdraw a permission where you granted it: in your Google account settings (myaccount.google.com/permissions) or by disconnecting the source here.
- Writing events to your Calendar. An agreement you confirm appears in your calendar: the event title, the place and a link back to the original message — the conversation itself is not copied. Cancel the agreement and the calendar entry is cancelled too. Events Uxen did not create, it does not touch.
- Sending mail on your behalf. A letter leaves only after your tap on a finished text you have read in full. The permission asked for is the narrowest one that exists: it can do exactly one thing — send. It does not allow reading, changing or deleting mail.
- Sorting your mail into folders. Mark read, move to archive, apply and create a label. Uxen cannot delete email and does not ask for that permission.
Contacts stay read-only always: the product cannot change a contact of yours — we never asked for the ability to.
Google API Services User Data Policy — Limited Use. Uxen's use of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Concretely: data from Gmail, Calendar and Contacts is used only to provide and improve the user-facing features you asked for; it is never sold, never used for advertising, and never transferred to anyone except as needed to provide those features (see the model provider above), to comply with the law, or as part of a merger or acquisition. Humans do not read it, except with your explicit permission, to fix a fault you reported, for security reasons, or where the law requires it. Google user data is not used to develop, improve or train generalised AI models: the model provider processes it under API terms that exclude training on this traffic.
Resend — our email provider. Every email we send you passes through it: your address, the subject and the body, including the one-time sign-in code.
Apple. Two roles. If you use Sign in with Apple, Apple confirms your identity to us and gives us an account identifier and an email. If you turn on notifications, Apple's push service receives your device token and a notification key with short parameters — never the text of your correspondence.
Telegram. Three roles, and they are separate. If you connect Telegram as a source, our server acts as a linked device on your own account, using Telegram's official interface — you can see it and close it in Telegram's own device list. If you use the Uxen bot, everything you type there passes through Telegram, as with any bot. If you pay with Telegram Stars, Telegram processes the payment.
YooKassa — only when you pay by card or SBP. It receives the amount, the currency, a payment description and a reference to your account. Card details are entered on YooKassa's side and never reach us. Nothing from your correspondence is ever sent with a payment: payment and memory are separate systems that know nothing about each other.
No one else. No advertising networks, no data brokers, no analytics services. There are no tracking scripts and no advertising SDKs in the product.
What we require of them. We only send data to providers whose terms commit them to protect it at least as strongly as this policy does, to use it solely to deliver their service to us, and never to sell it or use it to train their own models. We do not send your data to a provider that will not commit to this.
6. What Uxen does not do
- it writes to no one on your behalf until you switch that on — off by default, and a draft never leaves without your tap;
- it never deletes your email — we do not ask for that permission at all, and the software has no path by which a letter can be lost;
- it does not track you across other apps and websites;
- it shows no advertising and builds no advertising profiles;
- it does not read sources you have not connected;
- it does not ask for your mail password. Mail is connected through Google's official permission.
One honest correction to a claim that is often made and is not quite true: connecting Telegram or MAX may require the two-factor cloud password of that messenger, because those messengers require it to add a device. It is passed straight through to complete the login and is never stored or logged. If you would rather not do that, do not connect those sources — everything else works without them.
7. How long we keep things
Your memory has no time limit, and that is deliberate. Uxen exists to answer questions about correspondence from years ago. Deleting old material on a calendar would not mean “we keep fewer details” — it would mean “we cannot answer questions about that period”. So your memory lives for as long as you keep the service, and disappears when you delete it (section 8).
Everything else has a limit:
- technical logs — identifiers and chat names, no message text — are deleted after 14 days;
- system logs on the server are deleted after 14 days;
- sign-in tokens expire after 90 days, and expire immediately if you sign out;
- one-time sign-in codes live for minutes, are stored only as a keyed hash, and are used once;
- backups are taken daily. We keep the last 7 daily archives and the last 2 weekly ones, on the server and as a copy held by the operator. Deleted data disappears from backups as those archives rotate out — within about two weeks.
Dormant accounts. We do not delete accounts on a timer today. If we introduce automatic deletion of long-dormant accounts, we will warn you at least 30 days in advance — in the app, by email, and in the Telegram bot if that is how you reached us — and a single question will reset the clock. We will not do it silently.
8. Deleting your data
There are three different actions, and they do different things. We name them separately because they are easy to confuse and their consequences differ.
Disconnect a source. New messages from it stop arriving. Everything already stored stays and keeps being used in answers — disconnecting stops collection, it does not erase memory. You can reconnect at any time.
Erase all data. Every source is disconnected, everything Uxen remembered is erased, and your conversations with the assistant are deleted. Your account and sign-in methods remain — you can reconnect sources and start from scratch. Irreversible, and it requires you to re-prove it is you.
Delete the account. All of the above, plus the account itself: sign-in methods, verified email addresses, devices, push tokens, and the account action log. Also with re-authentication.
What survives deletion, and why. Two records do not go away:
- your plan and its paid-through date. If you delete your account with paid time remaining and come back later, you get those days back. You paid for them, and deleting your account is not our excuse to keep them;
- the payment ledger — the reference, amount, status and date of each payment. It is what a payment is reconciled against, and what a refund or a tax question is answered from.
Neither record contains the content of your correspondence.
You can also close the Uxen session inside the messenger itself, in its linked-devices list — and we suggest you do, so you see it with your own eyes rather than take our word for it.
9. Your choices, and how to withdraw consent
Everything Uxen does with a source rests on a permission you gave, and every permission can be taken back:
- disconnect any single source in the app, in one step;
- revoke Google's permission in your own Google account, at myaccount.google.com/permissions — it takes effect regardless of us;
- close the Uxen device in Telegram, WhatsApp or MAX, in their own linked-devices list;
- turn off notifications in your device settings;
- erase all data or delete your account, as described in section 8. Deleting your account is the complete withdrawal of consent: nothing is left for us to process.
If you want a copy of what we hold about you, or you think something is wrong, write to privacy@rrrfirstchat.com.
10. Security
Data travels over encrypted connections only. Access tokens are held in the device's secure storage (Keychain), not in ordinary app settings. On the server, key files and databases are readable only by the service account. Sign-in codes are stored as keyed hashes, never as codes. Sign-in tokens are stored as hashes, and reuse of a token revokes its whole family. Backups are taken daily, verified for integrity, and a copy is kept away from the main server.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your data, we will tell you.
11. Children
Uxen is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, write to privacy@rrrfirstchat.com and we will delete it.
12. Changes to this policy
We will keep this document accurate. When it changes, we will publish the new version with a new date, and tell you in the app before the change takes effect.
A separate and stronger commitment applies to new purposes. Writing on your behalf is no longer a future example — it exists, section 2 describes it, and it is off until you switch it on. If we ever want to use your data for something else not listed in section 4, then before that processing begins we will:
- tell you plainly what would change and what Uxen would be able to do;
- ask for your separate, explicit consent to that specific purpose;
- keep working exactly as this policy describes until you give it.
We will not treat your continued use of the app as agreement to a new purpose, and we will not enable such a capability by default. Consent to a new purpose is a decision you make once you can see what it is — not something you can be assumed into.
13. Languages
This policy is written in English, and the English text is the authoritative one. A Russian version is published at rrrfirstchat.com/privacy/ru and carries the same meaning.
If the two versions differ, the English text prevails — except where the law of your country requires otherwise. For consumers in the Russian Federation the Russian text prevails, as required by Article 8(2) of the Russian Law on Protection of Consumer Rights.
Last updated: 21 August 2026