Privacy Policy

Effective date: September 15, 2026

This policy explains what Sayforth collects, why, where it's stored, how long it's kept, and how to have it deleted. Sayforth is operated from North Carolina, United States ("Sayforth," "we," "us"). If you have questions this page doesn't answer, write to support@sayforth.app.

In short: your voice recordings stay on your iPhone and are never uploaded to us. The text of what you said, and metrics we measure from it, are sent to our backend and then to OpenAI so our AI coach can write your feedback. We don't run advertising, we don't sell data, and we don't track you across other apps or websites.

1. What we collect, and why

DataWhat it isWhy we collect it
Audio recordings The voice recording of each practice session, made when you tap record. So you can play back and compare your own sessions. Recordings are transcribed and stored on your device only; we do not receive them.
Transcripts and speech metrics The text of what you said (produced on-device), plus timing measurements: speaking rate, pause count and placement, hesitation pauses, run length, hedge-word count, answer length. To generate your feedback (what changed, what to work on next) and to show your trend against your own baseline.
AI-generated feedback The feedback paragraph, focus observation, and drill produced for each coached session. To show you what to change and to track your progress across the program.
Season and streak state Which day and phase you're on, streak count, milestones reached. To run the 30-day program and show your progress.
Account and entitlement identifiers A random device-generated identifier (App Attest key), your Sign in with Apple identifier if you choose to sign in, and your subscription status. To verify you're a legitimate app install (not to serve ads), to sync your account if you sign in, and to unlock Daily coaching features you've paid for.
Usage analytics Anonymized product-interaction events (for example, "session completed"), crash reports, and performance data. No advertising identifier is collected. To find and fix problems and understand which parts of the program are used, in aggregate, not tied to your identity.
Purchase information Subscription status and receipt validation, handled entirely by Apple. To unlock the features you've paid for. We never see your payment card details; Apple processes all payments.

2. Where your data lives, and for how long

DataWhereRetention
Audio recordings Locally on your iPhone only. Never uploaded. Deletable per session at any time. Auto-deleted after the period you choose in Settings (30, 90, or 365 days, or never); your Day 1 baseline and Day 30 retest recordings are kept until you delete them yourself.
Transcripts, metrics, feedback, Season/streak state Locally on your iPhone. Kept for as long as you use the app. Removed immediately when you delete your data or delete the app.
Transcript and metrics sent for feedback Passed through our backend (Cloudflare Workers) to OpenAI's API (model: gpt-5-nano) and back. Not written to a database on our servers. Held only for the duration of the request. We request zero data retention from OpenAI where it's available for our account; where it isn't yet in place, OpenAI's standard API retention window applies to that one request, as disclosed in section 3.
Backend operational logs Cloudflare Analytics Engine: timestamp, hashed device key, subscription tier, AI model used, token counts, latency, response status. Aggregated for 30 days, then discarded. These logs never contain your transcript, your prompt, or your feedback text.
Account/entitlement records (device key, linked Sign in with Apple identifier) Cloudflare KV (key-value store). Kept until you delete your data or delete your account, whichever you do. Rate-limit counters expire automatically after 48 hours.
Usage analytics TelemetryDeck, an analytics processor that does not use advertising identifiers or cross-app tracking. Held per TelemetryDeck's standard retention. You can turn analytics off in Settings → Privacy at any time; turning it off stops new events without deleting the app.

3. Who we share data with

We don't sell your data, and we don't share it for advertising. We use a small number of service providers ("processors") to run Sayforth, each limited to what they need to do their job:

  • OpenAI (maker of the GPT models; we use the gpt-5-nano model). We send the transcript text and speech metrics from a coached session, never the audio, to OpenAI's API, which returns the structured feedback (observation, one change, one drill) that the model writes. This is the one place your words are processed by a third-party AI system, and it happens on every coached session. OpenAI processes this data under its own API terms and is contractually restricted from using API inputs to train its models. We request zero-data-retention handling from OpenAI for our account where it's available; you can ask us for the current status at support@sayforth.app. We may also use Anthropic's Claude models as an alternate feedback processor (for example, during a provider outage); when that happens, the same transcript-only, no-training-use terms apply to Anthropic as they do to OpenAI.
  • Cloudflare. Runs the backend that relays your transcript to our AI feedback provider and back, and stores the operational logs and account/entitlement records described in section 2. Cloudflare does not use your data for its own purposes.
  • Apple. Handles Sign in with Apple (if you choose to sign in), app distribution, and all subscription payments through the App Store. Apple's own privacy policy governs data Apple collects directly, such as your payment method.
  • TelemetryDeck. Provides anonymized product analytics and crash reporting, without an advertising identifier and without cross-app tracking. You can opt out in Settings → Privacy.

We do not currently use a separate cloud speech-recognition service; transcription happens on your device using Apple's on-device speech framework. If we later offer an optional, opt-in cloud transcription upgrade for improved accuracy, it will require your explicit consent before any audio leaves your device, and this policy will be updated to name the provider and its retention terms before that feature ships.

If you're located in the European Economic Area, the United Kingdom, or another jurisdiction with similar requirements, we rely on the following legal bases:

  • Contract. Processing your transcript and metrics to generate feedback is the core service you're using the app for.
  • Consent. Usage analytics beyond what's strictly necessary to run the app, and any future opt-in cloud processing of audio, rely on your consent, which you can withdraw at any time in Settings without affecting your ability to use the app.
  • Legitimate interest. Operational logs (30-day aggregated, no content) that let us keep the service running and detect abuse.

5. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your data, to object to or restrict certain processing, and to withdraw consent at any time. Because most of your data lives on your device by design, you can exercise most of these rights directly in the app:

  • Access and export. Your transcripts, metrics, and feedback are visible in the app itself under Progress and session history at any time.
  • Deletion. Go to Settings → "Delete my data." This works whether or not you've created an account, and does not require contacting us. See section 6 for exactly what it does.
  • Opt out of analytics. Settings → Privacy → turn off usage analytics.
  • Any other request, including a formal GDPR or CCPA data subject request, a correction, or a question about what we hold: email support@sayforth.app. We aim to respond within 30 days.

California residents (CCPA/CPRA): we do not sell or share personal information as those terms are defined by California law, and we do not use advertising technology that would require a "Do Not Sell or Share My Personal Information" link. You have the same access, deletion, and correction rights described above.

6. Deleting your data

You can delete your data two ways:

  1. In the app. Settings → "Delete my data." This removes your recordings, transcripts, metrics, and Season state from your device; deletes your account and entitlement records from our backend; and, if you signed in with Apple, revokes that sign-in link. No account or email is required to do this.
  2. By email. Write to support@sayforth.app from the email address associated with your account, if any, and we'll confirm deletion within 30 days.

Deleting your data does not cancel an active subscription; subscriptions are managed and canceled through your Apple ID, described in our Terms of Use and on the Support page. Purchase history is retained by Apple independently of our deletion process, since it's Apple's record, not ours.

7. Age requirements

Sayforth carries a 4+ content rating on the App Store, meaning the app itself contains no objectionable content, violence, or mature themes. That content rating is separate from who the service is designed for: Sayforth is built for adults and older teens preparing for interviews, meetings, and presentations, and is not directed at children. The app is not intended for use by anyone under 16, and we do not knowingly collect data from children under 13. If you believe a child has used Sayforth and data was collected, email support@sayforth.app and we will delete it.

8. Security

Recordings on your device use iOS file protection and are excluded from iCloud backup, so they don't leave your device even in a backup. Data in transit between the app and our backend, and between our backend and OpenAI, is encrypted (TLS). Account and entitlement identifiers on your device are stored in the iOS Keychain. No method of storage or transmission is perfectly secure, but we don't hold a central database of your recordings or transcripts for an attacker to reach in the first place, by design.

9. Changes to this policy

If we make a material change to what we collect or how we use it, we'll update the effective date at the top of this page and, where the change is significant, notify you in the app before it takes effect.

10. Contact

Sayforth
North Carolina, United States
Email: support@sayforth.app