Privacy
What Exono holds, and who can read it.
Exono asks you to write down the people who matter to your work. This is what happens to that, in the order you would want to know it.
Last updated
What Exono holds
- Your account
- Your name, your email address, a hashed password, the devices you have signed in from, and your timezone. Sign-in is two steps, so we also hold short-lived codes and the tokens that keep you signed in.
- What you capture
- The people you save and whatever you record about them — names, roles, companies, contact details, the notes you write, what you have promised and when it is due, and the photographs of business cards you take. This is the bulk of it, and it is yours.
- How you use it
- The questions you ask Exono and the answers it gave, so a conversation can carry on where it left off. Changes to records are written to an audit log against your account.
- If you asked for an invite
- Your name, your address, and what you said you would use Exono for. Nothing else, and it is kept only until the beta is open.
Exono holds information about people who are not its users — the people you meet. You are the one who decided to write them down, and you remain responsible for that. Exono's job is to keep it to you.
Who can read it
Every table holding relationship data has row-level security switched on and forced in the database itself. The policy compares each row against the account bound to the current transaction, and forcing it is what makes the rule apply to the table's owner too — so the application cannot read across accounts even if it is asked to.
The assistant that answers your questions runs inside your own signed-in session and its tools are read-only. It has no credential of its own, it can reach nothing you could not reach yourself, and it cannot change or delete anything.
What that does not mean: nobody at Exono can ever see it. Someone holding direct database credentials can bypass any policy in any database, ours included. Today the protection there is that very few people hold those credentials and they are not used to read customer records. A customer-visible audit trail and support access you have to consent to are both being built, and until they exist this paragraph is the honest version.
Where it lives
Everything is stored in Singapore. The database and the card photographs are hosted by Supabase in ap-southeast-1; the service and its background worker run on Render in the same region; this website is served by Vercel.
Exono is in private beta and nothing is backed up yet. Point-in-time recovery is part of the work to open the doors, and it is not done. Do not use the beta as the only copy of something you cannot lose.
Who else processes it
Exono is a small product built on other people's infrastructure, and being vague about which is a way of avoiding the question. These are all of them.
- Gemini, through Vertex AI. It reads the business cards you photograph and returns fields for you to confirm; it answers the questions you ask, from your notes; and it turns your notes into the vectors that make search work by meaning as well as by word. It is the only AI provider Exono has a client for.
- Supabase
- The database and the file storage the photographs sit in.
- Render
- Runs the service and its background worker.
- Vercel
- Serves this website and the web app.
- Brevo
- The mail relay. It delivers your sign-in codes, your invitation and the reminders you asked for, which means it handles your email address and the subject line of anything we send you.
- Google Apps Script and Sheets
- The invite waitlist on this page, and nothing else. It is a stop-gap while the beta is closed; when the waitlist moves into Exono's own database this line goes away.
What Exono does not do with it
- Your relationship graph is not sold, and it is not a saleable asset. Exono is a subscription business and is intended to stay one.
- It is not syndicated, shared with other customers, or offered to anybody as data.
- It is not used to train a shared model. What you write trains nothing that anyone else benefits from.
- There is no advertising here, and no advertising or analytics cookie is set on this site.
That is a commercial commitment as much as a privacy one: a product asking to hold your private network cannot also be a party with an interest in that network.
Keeping it, and getting rid of it
Inside the app you can delete any record you have made — a person, a note, a contact detail, a reminder, a conversation with the assistant.
There is no button yet for deleting your whole account, and none for exporting everything you have written. Both are being built. Until they exist, write to the address below and we will do it by hand; you are entitled to that, and the absence of a button is not a reason for us to be slow about it.
Waitlist entries are deleted once the beta opens or once you ask, whichever comes first.
Changes to this policy
The date at the top is the date this last changed. Exono is in beta and the product is moving, so this page will move with it — particularly the paragraphs above that describe things as not yet built. Anything that materially changes what happens to what you have already written will be sent to you by email rather than quietly edited in.
Questions about any of this, a request to delete or export what you have written, or a message from someone who is not a user and believes Exono holds something about them: contact@exono.ai