Shoulder can watch you pay bills, log into portals, and handle personal information — so its privacy posture isn’t a footnote, it’s the reason it’s safe to use for that in the first place.

The short version

Project storage and search are on-device — your recordings, extractions, and chat history live on your phone, not a Shoulder server. Two things leave your device to make Shoulder work: extracting a recording, and generating a chat reply. Neither is retained afterward.

What touches the cloud

When you stop a recording, it’s sent to the Shoulder relay so a cloud model (Gemini Flash) can extract information from it against your project’s goal. When you ask a question in a project thread, Shoulder finds the relevant extractions on your device, then sends your question and those extracted notes to whichever model you’ve selected in Settings — Claude by default, or Gemini if you’ve switched it — to write the reply. In both cases, the relay doesn’t keep a copy of what it forwards — recordings, goals, and extracted text exist only for the moment it takes to process the request.

Along with those requests, Shoulder sends an anonymous device identifier — a random ID generated on your phone, not tied to your name or an account (there are no accounts in Shoulder). It’s used to apply a free usage allowance per device and to understand what the service costs to run. It travels with usage counts (how many requests, how much processing, when) but never with the content of a recording or a chat.

Retention on the provider side: Google (Gemini) retains prompts for up to 55 days solely to detect abuse of its API, then deletes them. Anthropic (Claude) keeps API prompts for about 30 days by default, then deletes them. Neither of these is what’s formally called “Zero Data Retention” — Shoulder doesn’t claim that term, because it isn’t in place with either provider today. Both are used under paid commercial terms, and under those terms neither company trains its models on what you send.

What stays on your device

  • Your project list, goals, and extractions are stored locally, not synced to a Shoulder server.
  • Search across your projects runs on-device — Shoulder finds what’s relevant to a question locally, before anything is sent to a cloud model to generate the reply.
  • Chat history is stored on-device.

How your data is protected on your phone

Everything Shoulder stores on your device is encrypted using your phone’s own security — the same protection that covers your photos and messages. While your phone is locked, that data can’t be read, even with physical access to the device. There’s no separate Shoulder password to set up; it rides on your existing passcode or Face ID.

Viewing a raw recording (not just what Shoulder extracted from it) asks for an extra check — Face ID or your passcode again, even if your phone is already unlocked. That confirmation covers the rest of your session; leave the app and come back, and it asks again. There isn’t yet a setting to lock the whole app behind Face ID the moment you open it — that’s planned, not shipped.

Erasing everything

Because extractions and chat history live on your device rather than a server, deleting a project — or using the app-wide “erase everything” option in Settings — actually removes it.

That includes the anonymous usage record described above (the device ID and request counts): erasing everything reaches the relay too, not just your phone.

What Shoulder will never do

Shoulder thinks like an agent — it actively watches, analyzes, and reasons about what matters toward your goal — but it doesn’t act like one. It never takes actions on your behalf: no logging into a site for you, no submitting forms, no moving money. That’s the precise distinction that makes it safe to point at things that matter — it can’t break anything, because it never acts for you. It’s doing real work the whole time; it just never clicks, types, or submits anything on your behalf. You stay the one driving; Shoulder rides along, analyzes, and remembers.