The promise
Your conversations are heard on the pendant, understood on your phone and stored on your phone. narad.si — the company — never receives your audio, your transcripts, your summaries or your voice profiles.
That isn’t a policy that a future version of our terms could quietly change. It is how the product is built: there is no narad.si server that accepts conversation data, so there is nothing to switch on. Speech recognition, speaker separation (diarisation), the language model that writes your summaries and the search index that answers your questions all run on hardware you own.
A few things do leave your phone — when you decide they should. Sending a WhatsApp message, adding an event to your calendar, reordering from a shop, or backing up to your own cloud. Each of those is an explicit tap, and each is described below.
Where every byte lives
The complete inventory of what narad.si handles, and where:
| Data | Where it lives | Who can read it | Leaves your devices? |
|---|---|---|---|
| Raw audio | Pendant buffer (seconds to minutes), then phone until transcribed | You | Never |
| Transcripts & summaries | Phone, encrypted | You | Only inside your E2EE backup, if enabled |
| Voice profiles (who is who) | Phone, encrypted | You | Only inside your E2EE backup, if enabled |
| To-dos, reminders, people | Phone, encrypted | You | Only when you tap an action (e.g. add to calendar) |
| Search index & embeddings | Phone, encrypted | You | Never |
| Account & order details | narad.si servers (India) | You and narad.si | Yes — needed to ship and support |
| Crash reports (opt-in) | narad.si servers | narad.si | Only if you opt in; scrubbed of content |
The journey of a sentence
- On the pendant. Three microphones form a beam toward the nearest voices. A small neural processor detects speech, isolates it from background noise and discards silence — most of a day is never transmitted at all.
- Across Bluetooth. Speech segments travel to your phone over an encrypted BLE 5.4 link, with an additional layer of encryption on the audio itself.
- On your phone. An Indic-first speech model transcribes it, including mid-sentence switches between Hindi and English. A diarisation model works out who said what, using voice profiles stored only on the phone.
- Understanding. An on-device language model extracts to-dos, dates, promises and people, and writes your summaries. Heavier work waits until you’re charging.
- Memory. Results go into an encrypted local database and search index. Raw audio is deleted once it has been transcribed, unless you choose to keep clips.
What we can and cannot see
We can see
- Your name, email, phone number and delivery address — to ship and support your pendant
- Your Membership status and payment confirmation (from our payment provider; we never see card numbers)
- Pendant serial number and firmware version, when you check for updates
- Crash reports, only if you opt in — stack traces, never conversation content
We cannot see
- Any audio the pendant hears
- Transcripts, summaries or answers
- Who you talked to, or what about
- Your to-dos, reminders, people or promises
- Your voice profile or anyone else’s
- The contents of your encrypted backup
Encryption & keys
- At rest on your phone: AES-256-GCM. Keys are generated on the phone and protected by its secure hardware — the Secure Enclave on iPhone, Android Keystore (StrongBox where available) on Android — and released only after you unlock the device.
- Pendant to phone: BLE LE Secure Connections pairing, plus application-layer encryption of every audio packet with keys exchanged during setup.
- Backups (optional): encrypted on your phone before upload to your iCloud Drive or Google Drive, with a key derived from a recovery phrase that only you hold. Neither we nor your cloud provider can read it.
- Deletion: deleting a memory removes it and its index entries from the local database; your backup reflects the deletion at the next sync.
Design note: cryptographic choices will be documented in a public whitepaper and reviewed in the independent audit before launch.
Things that leave, by design
Some things are useful precisely because they go somewhere. These only ever happen after you tap:
- WhatsApp. narad.si drafts a message and hands it to WhatsApp through your phone’s share sheet. You read it and press send in WhatsApp. We don’t use the WhatsApp Business API, we don’t run a bot, and we never read your chats.
- Calendar. Events are written through your phone’s own calendar (which may sync to Google, Apple or Outlook as you’ve set it up). There’s no narad.si calendar account in the middle.
- Shopping. Reorders, tracking and add-to-cart open the shopping app you choose with the item ready. The merchant receives what any order requires; narad.si receives nothing.
- Backup. Encrypted on your phone, stored in your own cloud. See above.
Threat model
No system is perfectly secure. Here is what we defend against, how, and what risk remains:
Your phone is lost or stolen
MitigationMemories are encrypted at rest with keys held in the phone’s secure hardware and released only after device unlock.
Residual riskIf your passcode is weak or known, an attacker who unlocks the phone can read the app. Use a strong passcode.
The pendant is lost
MitigationIt stores only a short encrypted buffer, bonded to one phone. Removing it from the app revokes the pairing.
Residual riskA determined lab attack on the hardware could recover the most recent unsynced seconds.
narad.si’s servers are breached
MitigationThere is no conversation data on them to steal — only account and order records.
Residual riskYour name, email, phone and address could be exposed, as with any retailer.
narad.si is acquired or shuts down
MitigationYour memories are on your devices, not ours. The app keeps working offline; export is always available.
Residual riskA new owner could change future app updates. Our commitment: any change to this architecture is opt-in, never silent.
A legal demand reaches narad.si
MitigationWe can only hand over what we hold: account and order records. We cannot decrypt your memory or backups.
Residual riskAuthorities may seek data directly from you or your device, under the law that applies to you.
A malicious or careless app update
MitigationNo third-party analytics or advertising SDKs. Published dependency list, and a network log you can inspect in the app.
Residual riskYou are trusting our release process; that is why we are committing to independent audits and reproducible builds.
Someone nearby sniffs Bluetooth
MitigationBLE 5.4 LE Secure Connections pairing with an additional application-layer encryption of the audio stream.
Residual riskMetadata such as “a device is transmitting” remains observable, as with any Bluetooth accessory.
Your backup provider is breached
MitigationBackups are end-to-end encrypted on your phone before upload, with a key derived from your recovery phrase.
Residual riskIf you lose the recovery phrase, we cannot help you restore — by design.
Honest trade-offs
Keeping everything on your devices has costs. We’d rather you hear them from us:
- No backup, no recovery. If you don’t enable encrypted backup and your phone is lost, your memories are gone. We can’t restore what we never had.
- Smaller models. On-device models are smaller than the biggest cloud models. We focus them on what matters — to-dos, dates, names, promises — and improve them through updates.
- Phone battery. Your phone does the thinking. We filter silence on the pendant and schedule heavy work for charging time, and we’ll publish measured battery impact before launch.
- iPhone background limits. iOS restricts background processing, so some summaries are prepared when the phone is charging or the app is open.
Commitments
Commitments — not yet completed narad.si is pre-launch. These are promises we are making publicly; we will report progress against each one on this page.
- Independent security audit. A recognised third-party firm audits the app, pendant firmware and our servers before launch. The summary report is published, findings included.
- Network transparency. A screen in the app that lists every connection it has made, to whom and why — readable by anyone, not just engineers.
- No third-party trackers. No analytics, advertising or attribution SDKs in the app. The full dependency list is published with every release.
- Reproducible builds. We will work towards Android builds that researchers can reproduce from published source for the privacy-critical components.
- Bug bounty. A public programme with real rewards for anyone who can make conversation data leave the device without the user’s action.
- Annual transparency report. How many legal requests we received, what we were asked for, and what we were able to provide (expected: account data only).
- No silent cloud. If we ever offer any cloud-assisted feature, it will be off by default, labelled clearly every time it is used, and never required.
India’s DPDP Act
The Digital Personal Data Protection Act, 2023 and the DPDP Rules notified on 13 November 2025 are coming into force in phases, with most core obligations — notice, security safeguards, breach reporting, retention — applying from 13 May 2027.
Our reading, which is not legal advice: because conversation audio, transcripts and derived data never reach narad.si’s systems, narad.si does not process that data and so does not act as a data fiduciary for it. We do process account, order, payment and (opt-in) diagnostic data, and we will handle that in line with the Act, with a clear notice and consent flow.
The Act also exempts processing by an individual for purely personal or domestic purposes. Using narad.si to remember your own day is likely to fall there; using it to record clients or employees in a professional setting may not, and you may then have obligations of your own. If you use narad.si at work, check your organisation’s policy and take advice.
This section is general information, not legal advice. Last reviewed October 2026.