Fifi Privacy Policy
Last updated: August 30, 2026
Fifi is an alarm clock. There is no login, no email address and no profile — nothing you sign up for, and nothing that carries your name. Most of what you put into it never leaves your phone.
This policy describes exactly what does leave, when, and to whom.
The short version
- There is no sign-up and no login. Our server knows your install only by two random identifiers the app generates for itself, both described below. Neither is your name, your email address, or an advertising identifier.
- Your alarms, to-do items, caller photos and voice recordings never leave your device. They are stored only in Fifi's own storage on your iPhone.
- The morning briefing is the one feature that talks to a server. If you turn it on, a small amount of context is sent so a forecast and a spoken line can be produced. That is listed in full below.
- We do not sell your data, and we do not use it for advertising.
- The website's waitlist is the one place we hold an email address. One launch email, then nothing; see "Website and waitlist" below.
What stays on your device
The following never leaves your iPhone. It is not backed up to us, and we cannot read it:
| Data | Where it lives |
|---|---|
| Alarm times, labels and repeat schedules | On-device storage |
| To-do items you add to a briefing | On-device storage |
| Photos you choose for a caller | Copied into Fifi's private app folder |
| Voice recordings you make for a wake-up line | Fifi's private app folder |
| Caller and character customization | On-device storage |
| Your wake-up streak history | On-device storage |
If you delete Fifi, all of this is deleted with it.
What is sent when you use the morning briefing
The briefing is optional. When it is enabled, Fifi contacts our own server to assemble your briefing, and sends only this:
| Field | What it is | Sent when |
|---|---|---|
| Device identifier | Apple's "identifier for vendor" — a random value scoped to your device that resets when you uninstall the app. It is not your Apple ID, your name, or an advertising identifier. | Always |
| Anonymous install ID | A random ID the app signs in with automatically on first launch, so our server can check the request is really from Fifi and count it against your subscription. You never see it and never create it — there is no password and nothing to log in to. It is not your Apple ID or your name, and it is stored by iOS in a way that can outlive an uninstall. | Always |
| Approximate location | Latitude and longitude, requested at your phone's lowest accuracy setting — enough for a city-level forecast, not a street address | Only if you grant location access |
| First name | Only the name you typed into Fifi, so the briefing can greet you | Only if you entered one |
| Wake-up streak | A number, e.g. "7 days running" | Always |
| Language, country, time zone offset | So the briefing is in your language and the right time | Always |
| News category | The topic you picked for headlines | Always |
Your to-do items are not sent to build the briefing. They are read from your phone and assembled there.
If you use a premium voice, the words your caller speaks — which can include your first name, a to-do, or a note you wrote — are sent to our server and passed to the voice provider to be turned into audio. We do not keep them: they are held only for the length of the request and never written to our storage. See "How long we keep it" below.
The voice provider is a different matter, and we would rather say so than imply otherwise. ElevenLabs, one of the two providers, keeps a history of what it was asked to speak, on the plan Fifi uses. That history is held by ElevenLabs under their own privacy policy, not by us. It contains the words spoken and nothing that identifies you — no account, no install ID, no location — but if the line included your first name or a note, that text is in it. Cartesia, the other provider, is used for the remaining characters. If you would rather this never happen, do not enter a name and do not put notes or to-dos in a briefing read by a premium voice; the built-in voice is generated on your device and sends nothing at all.
Who we pass it to
Our server calls a small number of third-party services to build the briefing. Each receives only the fragment it needs:
- Apple WeatherKit — receives your approximate coordinates, to return a forecast. See Apple's privacy policy.
- Currents API — receives your country and chosen news category, to return headlines. It receives no identifier and no location.
- Google (Gemini) — receives your first name, the day of the week, the weather condition and your streak count, in order to write the sentence you hear. It receives no identifier, no coordinates and no to-do items.
- Cartesia and ElevenLabs — if you subscribe to the premium voice, one of these receives the words your caller speaks, to convert them to audio. Which one depends on the character you chose. Either receives no identifier and no coordinates, and receives a to-do or note only as part of the words being spoken, as described above.
We share only the fragments listed above, we do not sell them to anyone, and we do not use any of this to advertise to you or to build a profile of you. Each provider handles what it receives under its own privacy policy, linked from its name above.
How long we keep it
We keep a request count per device identifier — two dates and two numbers, one pair for the day and one for the month — so that no single device can run up unlimited cost. It is not linked to any other data.
That record is deleted automatically 30 days after your last briefing. It is not archived first, and we do not keep a copy. If you use Fifi again before then, the 30 days start over from that day.
Your briefing is not stored on our server. It is assembled, returned to your phone, and discarded.
Audio of shared lines may be kept and re-used. Some of what your caller says is identical for everyone who hears it — the news headlines for your country, the weather sentence for your city's conditions, and the scripted lines the character itself says. Rather than pay to generate the same audio for every person every morning, we may store those recordings and give the same file to other people who would hear the same words.
The personal parts are never stored. Your greeting with your name in it, your to-do list and your notes are generated fresh each time, sent to your phone, and discarded. They are never written to our storage and never re-used for anyone else.
Analytics and crash reporting
PostHog (product analytics). Fifi records a fixed, small set of events so we can tell whether the app works: onboarding started and completed, the promise you make at the end of setup, alarm permission granted or denied, first alarm set, alarm fired, answered or snoozed, briefing completed or repeated, to-do added, caller customized, paywall viewed, purchase completed, preview played, and — if you open the "Did your alarm not ring?" screen — that you opened it, which of its checks failed, and whether you used it to reschedule your alarms.
Three of your setup answers are attached to the "onboarding completed" event, because they are what tells us whether the questions are worth asking: how many alarms you said you set, what you said happens when one rings, and where you said you heard about Fifi. That last one is also attached to your later events so we can tell which of those places sends people who stay. Your name, your wake-up time and the days you chose are not sent.
Otherwise these record that an action happened, never its content. We do not send your alarm labels, to-do text, name or location to PostHog. Because Fifi has no accounts, these events are tied only to a random anonymous identifier — we never call PostHog's identify function, so there is no person profile to build.
Sentry (crash reporting). If Fifi crashes or hits an error, Sentry receives a technical report: the error, a stack trace, and your app and OS version. Personally identifying information is explicitly disabled in our configuration, and performance tracing is turned off entirely.
RevenueCat (purchases). If you subscribe, RevenueCat handles the purchase and tells us whether your subscription is active. Payment itself is processed by Apple — we never see your card details.
Website and waitlist
If you leave your email address on the Fifi website before the app is out, we store two things: the address, and the time you left it. That is used for one purpose — a single email telling you the app is on the App Store. It is not a newsletter, we do not share or sell the list, and we do not add you to anything else. The list is held in Google Cloud Firestore in the United States, and the website sends nothing else about you to us: no analytics, no cookies of ours, no tracking of what you read.
To be removed before launch, or after it, email the address under Contact below from the address you signed up with and we will delete it.
Permissions Fifi asks for, and why
- Alarms — to ring on time, even when your phone is silenced. This is the core of the app.
- Location (while using the app) — for a city-level forecast in your briefing. Requested at the lowest accuracy iOS offers. Decline it and the briefing simply skips the weather.
- Photo library — to let you pick a photo for a caller. The photo is copied into Fifi's private storage and never uploaded.
- Microphone — to record a wake-up line in your own voice. Recordings stay on your device and are never uploaded.
Every one of these is optional except alarms, and Fifi degrades gracefully without them.
Children
Fifi is not directed at children under 13, and we do not knowingly collect data from them.
Your rights
Because Fifi has no sign-up, we hold no name, email address or profile, and there is nothing for us to look up under your name. The only thing we store on a server is the briefing request count described above, keyed to the random identifiers in that table.
If you are in the EU/EEA or UK (GDPR) or California (CCPA/CPRA), you have rights to access, correct, delete and port your personal data, and to object to its processing. In practice:
- To delete everything on your device, delete the app.
- To reset the device identifier our server sees, delete and reinstall the app — the "identifier for vendor" is regenerated. The anonymous install ID is kept by iOS outside the app and may survive a reinstall; email us and we will clear what is stored against it.
- To stop all data leaving your phone, turn off the morning briefing.
- To ask us to delete the request count held against your install, or to ask what it contains, email us — see Contact below.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
To exercise any right, or to ask what we hold, contact us at the address below.
Changes
If we change this policy we will update the date at the top and note the change in the app's release notes.
Contact
Fifi support@callfifi.app
Fifi is published by an individual established in the Republic of the Philippines, who is the data controller for the purposes of this policy. Email the address above for the publisher's registered name and postal address, or to exercise any right described under "Your rights".