Alpha Disclosure

How ConvergenceIQ actually works right now

You're using an early alpha. This page says plainly what happens with your data today, what's temporary, and what's the permanent destination — not marketing language, and not a legal document. If anything here changes, this page changes with it.

The short version

Right now, ConvergenceIQ routes your questions through frontier AI models (like Gemini or Claude) because they give the best answers available today. On-device models aren't yet good enough to match that quality. We think that will change — on-device AI is improving fast — and when it does, more of what ConvergenceIQ does will move fully onto your device. Until then, we're honest about the bridge we're using to get you the best answer today while we build toward that destination.

The bridge, stated plainly

Your personal context graph — the facts, people, and history ConvergenceIQ has learned about you — lives in a database tied to your account. During alpha, that database is hosted on a server we run (a small Hetzner VPS in Germany), not entirely on your phone. When you ask a question, the server:

This is a real, current-state architectural fact, not a hypothetical risk — we're telling you because "the graph lives on your device" is a destination we're building toward, not a claim about today's alpha build. Every install has its own separate database and its own credential; nothing about one person's graph is ever visible to another's, including ours as the operator, outside of the operational access required to run the service.

Why Germany

That was a deliberate choice, not where we happened to land. Hosting in the EU puts your data under the GDPR, which is the strictest privacy regime available to us, and under the EU Data Act, which mandates the same portability and freedom from vendor lock-in that this whole product is built around. Given the choice between operating under the loosest rules we could find and the strictest, we'd rather be governed by people who already take this as seriously as we do. It also means that if we ever drifted from what this page says, someone other than us would have standing to care.

What that is and isn't: jurisdiction is a floor, not a substitute for architecture. The things that actually protect you are the separate database per person, the boundary below, and ultimately moving your graph onto your own device. Choosing the EU just means the rules we operate under point in the same direction we're already walking.

The one boundary that already holds today, regardless of the bridge above: Your most sensitive records are excluded from everything we send to a frontier model.

"Tier-3" is our label for your most sensitive material — full journal entries, raw conversation history, anything you wouldn't want quoted verbatim to a third party. When ConvergenceIQ assembles the slice of context for a question, tier-3 records are filtered out by default, before that slice is ever built. That raw text is never sent to Gemini, Claude, or any other frontier model, and this isn't a policy we're asking you to take on faith — there's an automated check that runs the real production path and fails our build if a tier-3 record ever shows up in an answer, in the prompt we sent, or in the context chips we show you.

Where that boundary stops, stated just as plainly. On the phone app — the way you'll use this — nothing reads your tier-3 material on the way to an answer. It's filtered out before the slice of context is even assembled, and no summary of it is made.

On other paths, a small model can read your material, including tier-3, and write a short working summary — for example "he's been thinking through a career decision involving X and Y" rather than the journal entry itself. That summary, not your raw text, is what can reach a frontier model. Be clear about where that model runs: on whichever machine is running ConvergenceIQ's backend. That's your own Mac if you're running it there, and it's our server during the hosted alpha.

Either way the tier-3 material itself lives in your database, which during alpha is on our server, exactly as described in the bridge above. So: tier-3 is fenced off from the frontier models. It is not, today, fenced off from us.

From the one person who has that access:

To be plain about who can see this: it runs on a server I control, your database sits on that server during the alpha, it's backed up nightly to my own encrypted laptop and to a Dropbox account — and that means I can technically read anything you put in it. I don't, and nobody else has access, but I'd rather you hear that from me than work it out later.

What it stores

Whatever you tell it — that's the point of it. Your setup answers, the people and work and preferences you describe, your questions and the answers you get, anything you write in the journal, and the facts and relationships the system works out from all of it so it can answer you later. Plus ordinary server logs recording that requests happened.

It doesn't ask for payment details, government identifiers, or health records, and you shouldn't give it any.

Backups

Losing your graph would be worse than most things that could go wrong here, so it's backed up nightly. Those copies go further than the server, and you should know where:

They hold the same database described above, they exist so a failure or an accidental deletion is recoverable, and they're used for nothing else. Both copies are checked after they're written rather than only when the transfer finishes: the job re-opens each database it just wrote and verifies it, because a copy nobody has read is not yet a backup.

One distinction worth being exact about, since "encrypted" gets used loosely: the copy on our own machine sits on a full-disk-encrypted volume. The Dropbox copy is encrypted in transit and at rest by Dropbox, but it is not end-to-end encrypted — Dropbox holds keys we don't control. If that matters to you, say so; it's the kind of thing that moves up the list when someone asks.

Deleting it, and what you can ask for

All of it goes to the same place: jw@convergenceiq.ai.

There's no self-serve export yet. A person handles each request.

Who operates this

ConvergenceIQ is built and run by one person, Jake Wiley. There is no team. That's relevant to everything above: the commitments on this page are one person's conduct, and the access described in the boundary section is one person's access.

Not for children

ConvergenceIQ isn't intended for anyone under 18, and information about children isn't knowingly collected. If you believe a child has provided information, email the address at the bottom and it will be removed.

What's already protected today

Every install has its own separate database and its own per-device credential — one person's data cannot be reached with another person's credential.

The mobile app's credential lives in your device's Keychain (hardware-backed secure storage), never in a plain app-data file, and never gets included in a cloud backup to a different device.

Your saved conversations on your phone are encrypted at rest, with the encryption key held only in the Keychain — not sitting next to the data it protects.

We never place ads, never let anyone pay for placement in an answer, and never sell or use your graph to train any model — ours or anyone else's.

What's still on the way

End-to-end on-device storage with encrypted sync (no server-hosted graph at all) — the permanent architecture we are building toward. This alpha is the bridge to that, not that.

Local, on-device models good enough to fully replace frontier calls for everyday answers, without giving up answer quality.

A light mode. The app is dark only for now — if that makes it hard to read in bright light, say so and it moves up.

Why we're building it this way

We could have waited to launch until the on-device version was ready. We didn't, because we think the honest tradeoff — best answers now, built openly toward full device-local ownership — is better for you than waiting, as long as we're upfront about which one you're getting at any given moment. That's what this page is for. If we ever think the frontier labs we depend on are making choices that put your interests second to theirs, that's exactly the moment this product needs to exist as the alternative — which is the whole reason we're building it this way rather than just wrapping a chatbot.

Last updated 8 August 2026. If anything here changes materially, everyone testing gets an email and this date changes. Questions about anything on this page — email jw@convergenceiq.ai directly. This page is the authoritative description of how ConvergenceIQ handles your data today. If anything anywhere else — the home page, an email, a conversation with us — ever seems to conflict with it, this page wins, and tell us so we can fix the other one.