PI Innovations Privacy Policy
Legal

Cordelia Privacy Policy

Cordelia records people's life stories. That makes this the most sensitive data we will ever hold, and this policy is written to be read rather than skimmed. Cordelia is operated by PI Innovations, LLC (“PI Innovations,” “we,” “us”).

Effective date: July 30, 2026 Last updated: July 30, 2026
Contents 1 · The short version2 · What Cordelia collects3 · Text messages4 · Email5 · Your recordings6 · Voice and biometrics7 · Service providers8 · Who can see a Legacy9 · Security10 · How long we keep things11 · Your choices and rights12 · Children's privacy13 · Changes14 · Contact

Cordelia (“the service”) is a biographical capture service. An AI biographer holds a spoken conversation with someone — often an older family member — and what they say is transcribed, organized, and preserved as a living record of their life. This policy explains what the service collects, who else touches it, and what we will never do with it.

Cordelia is currently in a limited beta. Some features described in our public materials are not yet available; this policy describes the service as it actually operates today, and we will update it before new data practices take effect.

1 · The short version

  • Cordelia records audio of people telling their life stories, and keeps it. That is the entire point of the service — the recording is the thing being preserved.
  • We do not sell your data, and we do not use your recordings or transcripts to train AI models. We require the same of every provider that processes them — see sections 5 and 7.
  • The only text message we send is a one-time sign-in code. Your mobile number is never shared with anyone for marketing. See section 3.
  • Recordings are encrypted, and each Legacy's material is encrypted under its own key.
  • A Legacy is private by default. Nothing is shared outside it unless someone with authority over it chooses to share.
  • Voice recordings can be used to recognize who is speaking only if you have separately and explicitly consented. See section 6.

2 · What Cordelia collects

Account information

To create an account we collect a mobile phone number or an email address — whichever you use to sign in — and your name. We use a one-time code rather than a password, so we never store a password for you.

Session recordings and transcripts

When a session runs, we record the audio of the conversation and produce a transcript. From the transcript we derive structured material: the events, people, places, and themes that appear in the stories, and summaries built from them. All of this is stored as part of the Legacy.

What people say

People telling their life stories mention other people, health, relationships, money, religion, and events they may never have told anyone. We do not attempt to filter this — it is the material. We do classify it by sensitivity so the service can handle the most personal parts more conservatively.

Information about other people

Because life stories are about other people, a Legacy will contain information about individuals who are not Cordelia users and did not consent. We treat that material as part of the private Legacy and do not surface it outside it.

Invitations

If you invite someone to contribute, you give us their name and contact details so we can deliver the invitation. We use those details for that invitation and nothing else.

Device and technical information

We collect a push notification token if you enable reminders, plus routine technical information (IP address, app version, device and OS type) that any hosted service receives in order to function. We do not use it to profile or track you, and there is no advertising or third-party analytics in Cordelia.

3 · Text messages

Cordelia sends one kind of text message: a one-time numeric code so you can sign in. That is the entire messaging program.

  • How you opt in. You enter your own mobile number on the sign-in screen and tap “Send code.” The screen displays a disclosure directly above that button, before any message is requested. We never add a number to this program on someone else's behalf, and we never buy, rent, or import phone numbers from any list.
  • What you receive. A single message containing a verification code, sent only in response to your own sign-in request. The code expires after five minutes.
  • Frequency. One message per sign-in request. There are no recurring messages, no marketing, and no promotional content of any kind.
  • Cost. Message and data rates may apply, depending on your mobile plan.
  • Opting out. Reply STOP to any message to stop receiving them; reply HELP for help. You can also simply sign in by email instead. Opting out of these messages means you can no longer use a phone number to sign in.

We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. No mobile information, opt-in data, or consent record is sold, rented, leased, or otherwise disclosed for marketing. The only party that receives your number in connection with messaging is our messaging carrier, Twilio, acting solely to deliver the message on our behalf and prohibited from using it for its own marketing. Text messaging originator opt-in data and consent are not shared with any third party for any other purpose.

4 · Email

If you sign in by email, we send a one-time code to that address. We also send email that is necessary to operate the service, such as an invitation you asked us to deliver. Email is sent through Resend, which processes it on our behalf. We do not send marketing email.

5 · Your recordings

Session audio and transcripts are used to operate the service: to transcribe what was said, to organize it into a coherent record, to let the biographer remember earlier conversations, and to produce the outputs you have chosen to enable.

Producing that record requires sending text derived from the conversation — and, for transcription, the audio itself — to the AI providers listed in section 7.

Not training on this material is a requirement we place on those providers, not a preference. We do not knowingly use a provider that trains its generally available models on customer content, and we are confirming that commitment in writing with each provider named in section 7. Where a provider will not commit to it, we replace them. We will not describe that confirmation as complete until it is.

We do not sell your recordings, transcripts, or anything derived from them. We do not use them for advertising. We do not use them to train our own models for other customers.

6 · Voice and biometrics

Cordelia can learn to recognize who is speaking when more than one person is in the room, so contributions are attributed to the right person. Doing that creates a voiceprint, which is biometric information under laws including the Illinois Biometric Information Privacy Act (BIPA) and the Texas Capture or Use of Biometric Identifier Act (CUBI).

Because of that, a voiceprint is created only after you have given separate, explicit, written consent in the app, presented on its own and naming what is being collected and why. Recording a session does not by itself create a voiceprint.

You can withdraw that consent at any time in the app. Withdrawing it deletes the voiceprints it covered. Withdrawal does not delete the underlying recordings, which remain part of the Legacy — it removes the biometric identifier derived from them.

We do not sell, lease, or trade biometric information, and we do not disclose it except as required to operate the service or by law.

7 · Service providers

Cordelia relies on the following providers, each acting on our behalf and bound to use the material only to provide their service to us. This list is part of the policy: if it changes materially, the policy changes.

  • Anthropic — the AI that conducts the conversation and organizes what was said. Receives conversation text.
  • Speechmatics — speech-to-text. Receives session audio.
  • Inworld — text-to-speech for the biographer's voice. Receives the text the biographer speaks.
  • LiveKit — carries the live audio during a session.
  • Voyage AI (MongoDB) — converts text into the numeric representations that make a Legacy searchable.
  • Twilio — text messages. Receives your mobile number and the message body (see section 3).
  • Resend — email. Receives your email address and the message body.
  • Expo — push notifications. Receives your device's push token.
  • DigitalOcean — hosting and encrypted storage.

8 · Who can see a Legacy

A Legacy is private by default. It is visible to the person whose story it is, to the sponsor who manages it, and to contributors who have been explicitly invited. Nothing leaves that circle unless someone with authority over the Legacy chooses to share it.

Where the service offers broader sharing, it is opt-in per item — the choice is made for a specific memory, not switched on for everything — and it is retractable.

9 · Security

Session material is encrypted in storage. Each Legacy's material is encrypted under its own key, so access to one Legacy does not imply access to another, and those keys are held in a dedicated key-management system rather than alongside the data. Access to the service is authenticated by one-time code, and access to sensitive records is written to a tamper-evident audit log.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your information, we will notify you as required by law.

10 · How long we keep things

Cordelia is an archive, not a subscription app. The premise is that a great-grandchild can one day hear a voice that is otherwise gone. Session audio and the record built from it are retained indefinitely while the Legacy exists — deleting them would defeat the purpose of the service.

Working data that exists only to produce that record — intermediate processing output, historical snapshots — is kept for a period and then archived or discarded. Audit records are retained for compliance and cannot be rewritten.

You can ask us to delete a Legacy. See section 11.

11 · Your choices and rights

  • Withdraw biometric consent at any time in the app; the voiceprints it covered are deleted.
  • Stop text messages by replying STOP, or turn off push reminders in the app.
  • Request a copy of your information, or ask us to correct or delete it, by contacting us below.
  • Delete a Legacy. Because a Legacy holds material contributed by several people about a shared history, we will explain what deletion affects before doing it.

Depending on where you live, you may have rights under laws such as the GDPR or the CCPA, including access, correction, deletion, and the right not to have your personal information sold — which, in our case, is a right we exercise on your behalf by not selling it. We do not discriminate against anyone for exercising these rights. Contact us and we will respond.

12 · Children's privacy

Cordelia is not directed to children and we do not knowingly collect personal information from children under 13. Life stories often mention children, including as they were decades ago; that material is part of the private Legacy and is not used to build profiles of anyone. If you believe a child has provided us information directly, contact us and we will address it.

13 · Changes to this policy

If we change this policy we will update the effective date above and publish the new version at this URL. Material changes will be reflected before they take effect. Because this policy names the specific providers who process your recordings, a change to that list is a change to this policy.

14 · Contact

Questions about this policy, or a request about your data? Reach us at:

PI Innovations, LLC

522 W Riverside Ave, Ste N
Spokane, WA 99201, USA
Email: paul@piinnovationsllc.com
Phone: (206) 238-7939

See also: Terms of Use

© 2026 PI Innovations, LLC. All rights reserved. a product by PI Innovations