Privacy Policy
Effective date: 14 September 2026
Unsaid is designed to let adults rehearse difficult conversations while keeping their microphone audio on their iPhone. This Privacy Policy explains what Unsaid processes, why it is needed, where it is kept, and the choices available to you.
In this policy, “Unsaid,” “we,” “us,” and “our” mean John Chimaobi. Contact us at thechillguy600@gmail.com.
The short version
• Your microphone audio is transcribed on your iPhone and is not uploaded to Unsaid, OpenAI, ElevenLabs, or our backend.
• Transcript text and custom-scenario text may be processed online to provide AI role-play and feedback.
• Practice history is saved on your device first. Private iCloud backup is optional and controlled in Settings.
• We do not sell personal data, show third-party advertising, or use your data for cross-app tracking.
• You can delete individual practices, all practice history, or your Unsaid account from the app.
Information processed by Unsaid
Sign in with Apple
Unsaid uses Sign in with Apple. The app requests no name or email scopes. Apple gives Unsaid a stable account identifier and signed authentication information so we can verify your session, protect access, support account deletion, and connect your subscription entitlement. We transform account identifiers into pseudonymous service identifiers. We do not use Apple sign-in information for advertising.
Spoken practice and transcripts
When you hold to speak, Apple’s on-device speech recognition turns your microphone audio into text. Microphone audio remains in memory on your device for recognition and is not uploaded or saved by Unsaid.
The resulting transcript text, the current scenario, conversation history, and the goals needed for the practice are sent over encrypted HTTPS to our backend and to OpenAI to generate an in-character reply, moderate content, and produce feedback. These requests are configured not to create a durable OpenAI conversation or enable model training through Unsaid. Under OpenAI’s default API controls, abuse-monitoring logs may include request content and may be retained for up to 30 days unless a different approved retention setting applies or law requires longer retention.
AI-generated voice
The AI partner’s reply text is sent to ElevenLabs to create the voice you hear. ElevenLabs does not receive your microphone audio. Generated reply text and generated audio may be processed or temporarily retained by ElevenLabs according to the retention settings and API terms that apply to our account. Unsaid streams the generated audio for playback and does not save it in your practice history, iCloud history, or backend database.
Read more on the How Your Voice Is Handled page.
Custom scenarios and feedback
If you create a custom scenario, the details you enter are sent to our backend and OpenAI for safety moderation and to generate a title, goals, response style, and practice instructions. Ordinary custom-scenario text and generated feedback are not stored in the Unsaid backend database. They are returned to the app and stored locally, and may be included in your private iCloud backup when you enable it.
Please leave out names and private details that the practice partner does not need.
Practice history and iCloud
Practice summaries, transcripts, feedback, and custom scenarios are stored locally on your device. If you enable iCloud backup, Unsaid synchronizes supported history to your private iCloud database. Apple operates iCloud under your Apple Account and Apple’s terms. Unsaid remains usable with iCloud backup turned off.
Signing out does not delete local practice history. Deleting a practice or all practice history removes the selected local data and queues deletion of its private iCloud copy when applicable. Deleting your account revokes the Unsaid sign-in connection, removes saved practices and custom scenarios from the device, and queues deletion from private iCloud when sync is enabled. Your App Store subscription is managed separately through Apple.
Purchases
Apple and RevenueCat process subscription purchases and status. Unsaid receives a pseudonymous account identifier, product and transaction information, entitlement status, renewal or expiry information, and related technical events so we can unlock Unsaid+ and restore purchases. We do not receive your full payment-card details.
Notifications
If you choose to enable practice reminders, Apple Push Notification service and OneSignal process a push token, delivery information, notification preferences, and a pseudonymous Unsaid identifier needed to deliver and measure service messages. Notification content is designed to avoid sensitive conversation details by default. You can disable reminders in Unsaid or in iOS Settings.
Reports and support
If you report a practice response, Unsaid sends the selected reason and minimal technical context. Any practice text is attached only when the report screen clearly offers it and you choose to include it. Sending a report does not delete your local history.
If you email support, we receive your email address and anything you include in your message. Do not send passwords, authentication codes, payment-card details, or sensitive conversation transcripts unless support specifically asks for limited information needed to resolve a problem.
Operational and security data
We process limited technical data needed to authenticate sessions, enforce voice-minute limits, prevent replay and abuse, reconcile purchases, deliver notifications, investigate failures, and control provider costs. This can include pseudonymous account and installation hashes, session and request identifiers, scenario identifiers, subscription state, quota counters, timestamps, latency, error codes, provider usage totals, and security events. Production logs are designed not to contain microphone audio or ordinary transcript content.
Our hosting and network providers may automatically process information such as IP address and device or connection metadata to deliver and secure requests. We do not use this information for advertising or cross-app tracking.
Why we process information
We process information to:
• authenticate your Apple sign-in and protect your account;
• provide scenarios, AI role-play, generated speech, transcripts, and feedback;
• save and optionally synchronize your practice history;
• manage Unsaid+ purchases, entitlements, trials, restores, and voice-minute limits;
• deliver reminders you choose to receive;
• moderate unsafe content, prevent abuse, and protect the service;
• respond to reports and support requests;
• meet legal, accounting, security, and App Store obligations.
Where applicable law requires a legal basis, these purposes rely on performance of the service you request, your consent for optional permissions and notifications, our legitimate interests in security and service operation, and legal obligations.
Service providers
We use the following providers only for the functions described:
• Apple for Sign in with Apple, on-device speech recognition, iCloud, App Store purchases, and push notification delivery;
• Convex for backend hosting, authentication state, quota and entitlement metadata, and transient request orchestration;
• OpenAI for moderation, role-play reasoning, custom-scenario enrichment, and structured feedback using text rather than microphone audio;
• ElevenLabs to generate the AI partner’s voice from AI reply text;
• RevenueCat to manage subscription entitlement and purchase lifecycle information;
• OneSignal to deliver reminders and lifecycle notifications when you opt in.
These providers process information under their own service terms and privacy commitments. We require service providers to protect information consistently with their role and applicable law. Providers may process data in countries other than yours.
Retention
• Microphone audio: memory only on your iPhone; not uploaded or saved by Unsaid.
• Generated AI audio: streamed for playback; not stored by Unsaid. Provider-side processing or temporary retention may apply under ElevenLabs settings and terms.
• Local history and custom scenarios: kept until you delete them, delete your account, or remove the app and its local data.
• Private iCloud copies: kept in your private iCloud until deleted through supported app controls or your Apple Account tools.
• Ordinary transcript, custom-scenario, and feedback text on our backend: processed transiently and not kept as ordinary database records.
• Authentication sessions: normally expire within 30 days unless refreshed, signed out, revoked, or deleted sooner.
• Practice accounting records: generally retained for up to 35 days for session settlement, while monthly quota, entitlement, and aggregated provider-usage records may be retained for up to 13 months.
• Webhook and security events: generally retained for up to 90 days.
• Report text you choose to attach: retained for up to 30 days; limited report metadata may be retained for up to 13 months.
• Support email: retained as long as reasonably needed to resolve the request, maintain a support record, and meet legal obligations.
We may retain limited records longer when required for fraud prevention, dispute resolution, tax, accounting, legal compliance, or to establish and defend legal claims. When deletion is not immediately possible, we restrict the record to the purpose that requires it.
Your choices and rights
You can:
• deny or revoke microphone, speech-recognition, or notification permission in iOS Settings;
• turn private iCloud backup on or off in Unsaid Settings;
• delete individual practices or all practice history;
• sign out without deleting local history;
• delete your Unsaid account from Settings;
• manage or cancel your subscription through your Apple Account;
• contact us to request access, correction, deletion, restriction, or a copy of information we control, subject to applicable law.
Because much of your history is stored only on your device or in your private iCloud, we may not be able to access or export it for you. Use the app’s controls to manage that information.
To make a privacy request, email thechillguy600@gmail.com. We may need to verify that the request relates to your account without asking for more information than necessary.
Children
Unsaid is intended only for adults aged 18 or older. It is not directed to children, and we do not knowingly allow anyone under 18 to use the service. Contact us if you believe a minor has provided information through Unsaid.
Security
We use encrypted network connections, server-verified Apple identity, short-lived access credentials, rotating refresh credentials, Keychain storage, request validation, rate limits, and data-minimizing logs. No system can guarantee absolute security, but we design Unsaid to reduce the amount of sensitive information stored in the first place.
Changes to this policy
We may update this policy as Unsaid changes or legal requirements develop. We will change the effective date and provide additional notice when required. Material changes apply prospectively unless the law permits otherwise.
Contact
Email: thechillguy600@gmail.com
X: @thechillguy600