Skip to content
DeepSpace

Privacy, in plain language.

Raw sensor data never leaves your phone. Every read is logged. Here is what that means in practice, based on how the app actually works today.

What never leaves your device

Your phone, Watch, and Mac do the sensing. They turn raw readings into a handful of compact facts, and only the facts you've enabled are sent.

Raw sensor streams
Motion, barometer, and other sensor readings are turned into small facts on your phone. The streams themselves are never uploaded.
Audio
If you turn on ambient sound, Deep takes a three-second sample about every five minutes while it's open on your phone and turns it into one word: quiet, conversational, or loud. The temporary clip is deleted on your phone and never uploaded.
Raw health samples
Health data is read on your device and summarized there. Raw samples and history stay put.
Calendar details
Only busy or free leaves your phone. Event titles, attendees, and notes do not.
Nearby sightings
Bluetooth sightings use rotating identifiers. Signal strength and unmatched sightings stay on your phone.
App names
Screen time is shared as a bucket at most. App identifiers and window titles never leave the device.

What Deep stores

Your current status
The latest value of each signal you've turned on, like your place label, whether you're driving, or busy/free, with when it was observed and when it expires. Expired values are deleted automatically.
Precise location
Only if you turn it on. Sharing exact coordinates with anyone is a separate permission that expires after 24 hours by default.
Your account
Your sign-in email, handle, and display name; your connections and permissions; agents you've connected; automations; and push tokens.
The access log
A record of every read of your status by a person or agent: who, which categories, and when. It exists for you.

For weather, the server rounds your location to a shared cell about 10 km wide before asking a weather provider. No account details go with it.

Who can see what

Only what you approve. An invite carries the sharing its sender offered, and the person accepting sees exactly what that is before saying yes. What they share back is their own choice. Every grant names specific categories at a precision you pick: presence only, approximate, or exact. Grants can run on a schedule or expire.

Checked on every read. Permissions are enforced on the server each time someone asks, and values are reduced to the precision you granted. Revoke a grant and the next request no longer sees it.

Health is opt-in, one category at a time. Presets never include health, coordinates, or exact precision.

Go Dark pauses everything your devices sense. They stop sending updates, what's already shared is marked stale, and people and agents see that you're paused, never why or until when. You're never shown as reachable while paused. Things you set by hand, like “open to coffee,” stay visible until you clear them.

Analytics and crash reports

The app can send product analytics (PostHog) and crash reports (Sentry). Analytics use an opaque ID and categorical events only, with autocapture and session replay off. Both are scrubbed of signal values, coordinates, health values, email addresses, and credentials before they leave the app.

Deep doesn't use your context for advertising.

Export and delete

Export or delete your account any time in the app under Account → Your data, or in the web app. Deletion is confirmed with a six-digit code sent to your email.

This website

This site sets no cookies, runs no analytics, and loads no third-party scripts or fonts. If you join the waitlist we store one thing, your email address, normalized to lowercase. It isn't linked to an account and is only used to tell you when you can get in.

This page is a plain-language summary of how Deep works today, not a legal policy.