Legal
Privacy Policy
Draft pending legal review
This is a working draft. It is being reviewed and finalized with counsel, and it will be updated before public launch. The highlighted items in brackets are still being completed, including the effective date. Please do not rely on this draft as a final or binding document.
Draft for attorney review. Not final. Not legal advice. Prepared by Automate AI LLC for counsel to review, correct, and finalize. Bracketed items are placeholders requiring founder or counsel input. Scope: United States (all states) and Canada excluding Quebec. Quebec (Law 25) and the EU and UK (GDPR) are out of scope and flagged where they would apply.
Effective date: [TO BE SET ON FINALIZATION]
Version: [TO BE SET, must match POLICY_VERSION in the app]
Last updated: [DATE]
Automate AI LLC (“Automate AI LLC,” “we,” “us”) operates the Replay mobile application and the website at replaycouples.com. This policy explains what we collect, why, who we share it with, and the rights you have. It covers both the app and the website, which collect different things.
Contact: [privacy contact name/title], [privacy@ email], Automate AI LLC, [full mailing address].
1. Summary
Replay is built so that we cannot read what you record. Your reflections are encrypted on your device with keys only you hold. We do not sell your personal information, we do not share it for cross-context behavioral advertising, we do not show ads, and we do not use third-party tracking technologies. This summary is for convenience only; the full policy governs.
2. What Replay is, and is not
Replay helps you capture and understand patterns in your relationship. It is not therapy, counseling, medical care, a medical device, a diagnostic tool, or an emergency service, and it does not provide professional advice. If you are in crisis, call 911 or your local emergency number.
3. How the encryption works and what it means
Your recordings, transcripts, and reflections are end-to-end encrypted on your device before transmission. Plaintext and raw audio never leave your device. We and our hosting provider store only ciphertext we cannot decrypt. Your recovery code is the only means of restoring access on a new device; if you lose it, no one, including Automate AI LLC, can recover your content. This is a deliberate design protection we cannot override.
When the app uses AI to generate reflections, it first removes identifying detail and reduces text to a sanitized, blame-neutral form on your device. Only that sanitized text is transmitted to our AI service providers, under contractual terms prohibiting retention and model training.
Important limitation: end-to-end encryption protects the content of your entries. It does not conceal account metadata (that an account exists, its email, when it was active, that two accounts are paired). Section 4 describes what we do hold.
4. Personal information we collect
4.1 From the app
| Category (CCPA/CPRA statutory category) | Specific information | Source | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Email address, account/user ID | You | Account creation, authentication, security | Until account deletion |
| Customer records | Encrypted entry content (we cannot read it) | You | To provide the service | Until you delete the entry or account |
| Commercial information | Subscription status, purchase history | App stores / RevenueCat | Billing, entitlement | Until account deletion, plus any period required for tax and accounting [CONFIRM] |
| Internet/network activity | Content-free diagnostic and operational logs | Automatic | Security, reliability, incident scoping | [CONFIRM window; target at least 30 days] |
| Inferences | Sanitized, de-identified text derived from your entries for AI processing | Derived on device | To generate the reflections you request | Transient; not retained by providers |
| Consent and compliance records | Consent choices with version and timestamp, age attestation, content-free automated-processing records | You / automatic | Legal compliance, proof of consent | [CONFIRM post-deletion retention: see §11] |
We do not collect precise geolocation, biometric identifiers, voiceprints, government identifiers, or advertising identifiers. We do not create a voiceprint or any voice-based biometric identifier at any point.
4.2 From the website (replaycouples.com)
| Category | Specific information | Purpose | Retention |
|---|---|---|---|
| Identifiers | Email address if you submit a form or join a list | To respond, to send the requested material, to notify you at launch | Until you unsubscribe or request deletion, then [CONFIRM] |
| Internet/network activity | Privacy-friendly, first-party, cookieless analytics (page views, referrer, approximate region) | To understand site usage | [CONFIRM] |
The website uses first-party analytics only. We do not use Google Analytics, advertising pixels, or third-party tracking cookies. Website email collection is separate from the app and is notprotected by the app’s end-to-end encryption; an email address you give us on the website is ordinary business data we can read.
How website email sign-up works. We use double opt-in: when you submit your email we send a confirmation link, and we only add you to the list after you click it. Once confirmed, we deliver the resource you requested and a short welcome sequence of a few messages over about two weeks. Every marketing message includes a working one-tap unsubscribe and our postal mailing address, and unsubscribes are honored immediately. We do not set any cookies for this. ATTORNEY: confirm CAN-SPAM and consent-record wording.
Global Privacy Control. When your browser sends the Global Privacy Control signal (the Sec-GPC header or navigator.globalPrivacyControl), we treat it as an opt-out: we do none of the sale or sharing it targets, and we additionally suppress our non-essential first-party analytics for that visit.
4.3 Information about other people
Entries you create may describe your partner or others. That information is encrypted and unreadable to us. We disclose this in the app. See §9.4 for how requests about such information are handled. ATTORNEY: confirm the disclosure and deletion posture, ATTORNEY-DECISION 2.
5. How we use personal information
To provide, secure, and maintain the service; to authenticate you; to process subscriptions; to generate the reflections and features you request; to operate the app’s safety features; to respond to you; to comply with legal obligations; and to detect and prevent fraud, abuse, and security incidents.
We do not use your information for advertising, profiling for advertising, or any purpose incompatible with those above. We do not use your content to train AI models, and our providers are contractually prohibited from doing so.
6. Legal bases (Canada, excluding Quebec)
Where PIPEDA applies, we process on the basis of your knowledge and consent, obtained expressly and per purpose in the app, and withdrawable at any time. [Quebec residents: Law 25 is out of scope in this version.]
7. Service providers (subprocessors)
| Provider | Role | What it receives | Terms |
|---|---|---|---|
| Anthropic, PBC | AI reasoning | Sanitized, de-identified text only | Zero-retention configuration; no training [CONFIRM DPA executed] |
| Voyage AI | Embeddings | Sanitized, de-identified text only | No-training setting [CONFIRM DPA] |
| ElevenLabs | Voice synthesis | Blame-neutral output lines only; never crisis or safety-held content | Per-request logging disabled; zero-retention workspace setting [CONFIRM DPA] |
| RevenueCat | Subscription entitlements | Subscription metadata; no content | [CONFIRM DPA] |
| Supabase | Encrypted-content hosting and authentication (United States, us-east-1) | Ciphertext and account metadata | [CONFIRM DPA] |
| SendGrid (Twilio) | Website email delivery | Email addresses submitted on the website | [CONFIRM DPA] |
| Apple, Google | App distribution, payment processing, push delivery | Per platform policies | Platform terms |
These are service providers/processors acting on our instructions, not independent recipients. We do not authorize them to use your information for their own purposes.
8. Disclosure of personal information
We disclose personal information only: to the service providers above; to comply with law, legal process, or a valid governmental request; to establish, exercise, or defend legal claims; to protect the rights, safety, or property of any person; and in connection with a merger, acquisition, or asset sale, in which case this policy continues to apply to the transferred information until amended with notice.
We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months, and we do not do so. We do not sell or share the personal information of anyone under 16. The app is limited to adults 18 and over.
9. Your rights and how to exercise them
9.1 Rights
Depending on your residence, you may have the right to: know what we collect and why; access and receive a portable copy; correct inaccuracies; delete; opt out of sale, sharing, or targeted advertising (we do none); limit use of sensitive personal information; withdraw consent; and not be discriminated or retaliated against for exercising a right.
9.2 How to exercise
Use the in-app controls (Settings) for export, correction, and account deletion, or contact [privacy@ email]. Deletion is also available at replaycouples.com/delete-account.
9.3 Verification and timing
We verify requests by confirming control of the account email, and for sensitive requests may require additional confirmation. We do not require an account to make a request but may be unable to verify a request from someone we cannot associate with data we hold. We respond within 45 days, extendable once by an additional 45 days with notice, or sooner where a shorter period applies. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you why before proceeding.
9.4 Limitations under encryption
Because entry content is end-to-end encrypted, we cannot read, locate, correct, or selectively delete information within your entries, including information about another person. We can delete entries and accounts in full. ATTORNEY: confirm this satisfies deletion and correction obligations, including as to third-party information, ATTORNEY-DECISION 2.
9.5 Authorized agents
You may use an authorized agent, who must provide written, signed permission; we may also contact you directly to confirm and to verify your identity.
9.6 Appeals
If we deny a request, you may appeal by writing to [appeals contact] within [60] days. We will respond in writing within 45 days with our decision and reasoning. If we deny the appeal, you may contact your state attorney general. [Required in CO, CT, VA, and others; confirm state list.]
9.7 State-specific
California:the rights above, plus the right to know categories of sources and recipients (§§4, 7, 8) and the right to limit use of sensitive personal information. We do not use or disclose sensitive personal information for purposes requiring an opt-out. Under Cal. Civ. Code §1798.83, California residents may request information about disclosures to third parties for direct-marketing purposes; we make none.
Washington, Nevada, Connecticut: see our separate Consumer Health Data Privacy Policy.
Other states:residents of states with comprehensive privacy laws in effect have access, correction, deletion, portability, and opt-out rights on the terms of their state’s law, and we honor the Global Privacy Control universal opt-out signal on our website where required.
Canada (excluding Quebec): access and correction rights under PIPEDA; contact [privacy contact]. You may complain to the Office of the Privacy Commissioner of Canada.
10. Cross-border transfers
We are located in the United States and process and store information in the United States. If you are in Canada, your information is transferred to and processed in the United States by us and the providers in §7, and is subject to United States law and lawful access by United States authorities. By using the service you acknowledge this transfer. ATTORNEY: confirm PIPEDA transparency wording.
11. Retention and deletion
We retain personal information for the periods in §4 and for as long as needed for the purposes described, then delete or de-identify it. On account deletion we delete server-side content and account records, remove local data on the device, and instruct providers to delete any copy they hold. We may retain: records required by law (tax, accounting); records of consent and age attestation as proof of your affirmative acts; and content-free security logs, each for the minimum necessary period. ATTORNEY: confirm post-deletion retention of consent proof, which is in tension with a complete-deletion representation. Also: if Canada is in scope, PIPEDA requires breach records be kept 24 months.
12. Security
We use end-to-end encryption, hardware-backed key storage, encryption in transit and at rest, row-level access controls, and least-privilege access. No system is perfectly secure. We maintain a written incident-response runbook and will notify you and regulators of a security breach as required by applicable law.
13. Minors
The service is for adults 18 and over. We do not knowingly collect personal information from anyone under 18. A user who indicates they are under 18 has local data wiped and is denied access. If you believe a minor has provided information, contact [privacy@ email] and we will delete it.
14. Automated processing and AI
We use automated processing, including AI models, to generate reflections, patterns, and optional spoken responses, operating only on sanitized, de-identified text. These are reflective tools. They do not produce legal or similarly significant decisions about you, do not diagnose, and are not a substitute for professional judgment. We keep content-free records of this processing. You may withdraw consent to cloud AI processing in the app, in which case the app degrades conservatively to on-device processing. ATTORNEY: confirm against the Colorado AI Act, effective June 30, 2026, and any successor state AI laws.
15. Third-party links
Our website and app may link to third-party sites and to the app stores. We are not responsible for their privacy practices.
16. Changes
We will update this policy as needed. Material changes will be notified in the app and, where required, will require renewed consent. The app increments its policy version and re-obtains consent automatically when legal wording changes.
17. Accessibility
If you need this policy in an alternative accessible format, contact [privacy@ email].
18. Contact
Automate AI LLC, [address]. Privacy: [privacy@ email]. Support: support@construktr.ai.
Attorney checklist for this document
- Confirm the CCPA/CPRA category mapping and retention entries in §4.
- Confirm §9.4 (deletion/correction limits under E2EE) satisfies obligations, including third-party data in user entries.
- Confirm §11 post-deletion retention of consent proof against the deletion representation.
- Confirm the appeal states and timelines in §9.6.
- Confirm §10 cross-border wording for PIPEDA.
- Confirm §14 against the Colorado AI Act and successors.
- Confirm the “have not sold in the preceding twelve months” statement in §8 is accurate and appropriately phrased.
- Confirm whether a separate website privacy notice is preferable to the combined approach used here.