Skip to main content

Legal

Privacy Policy

Draft pending legal review

This is a working draft. It is being reviewed and finalized with counsel, and it will be updated before public launch. The highlighted items in brackets are still being completed, including the effective date. Please do not rely on this draft as a final or binding document.

Draft for attorney review. Not final. Not legal advice. Prepared by Automate AI LLC for counsel to review, correct, and finalize. Bracketed items are placeholders requiring founder or counsel input. Scope: United States (all states) and Canada excluding Quebec. Quebec (Law 25) and the EU and UK (GDPR) are out of scope and flagged where they would apply.

Effective date: [TO BE SET ON FINALIZATION]
Version: [TO BE SET, must match POLICY_VERSION in the app]
Last updated: [DATE]

Automate AI LLC (“Automate AI LLC,” “we,” “us”) operates the Replay mobile application and the website at replaycouples.com. This policy explains what we collect, why, who we share it with, and the rights you have. It covers both the app and the website, which collect different things.

Contact: [privacy contact name/title], [privacy@ email], Automate AI LLC, [full mailing address].

1. Summary

Replay is built so that we cannot read what you record. Your reflections are encrypted on your device with keys only you hold. We do not sell your personal information, we do not share it for cross-context behavioral advertising, we do not show ads, and we do not use third-party tracking technologies. This summary is for convenience only; the full policy governs.

2. What Replay is, and is not

Replay helps you capture and understand patterns in your relationship. It is not therapy, counseling, medical care, a medical device, a diagnostic tool, or an emergency service, and it does not provide professional advice. If you are in crisis, call 911 or your local emergency number.

3. How the encryption works and what it means

Your recordings, transcripts, and reflections are end-to-end encrypted on your device before transmission. Plaintext and raw audio never leave your device. We and our hosting provider store only ciphertext we cannot decrypt. Your recovery code is the only means of restoring access on a new device; if you lose it, no one, including Automate AI LLC, can recover your content. This is a deliberate design protection we cannot override.

When the app uses AI to generate reflections, it first removes identifying detail and reduces text to a sanitized, blame-neutral form on your device. Only that sanitized text is transmitted to our AI service providers, under contractual terms prohibiting retention and model training.

Important limitation: end-to-end encryption protects the content of your entries. It does not conceal account metadata (that an account exists, its email, when it was active, that two accounts are paired). Section 4 describes what we do hold.

4. Personal information we collect

4.1 From the app

Category (CCPA/CPRA statutory category)Specific informationSourcePurposeRetention
IdentifiersEmail address, account/user IDYouAccount creation, authentication, securityUntil account deletion
Customer recordsEncrypted entry content (we cannot read it)YouTo provide the serviceUntil you delete the entry or account
Commercial informationSubscription status, purchase historyApp stores / RevenueCatBilling, entitlementUntil account deletion, plus any period required for tax and accounting [CONFIRM]
Internet/network activityContent-free diagnostic and operational logsAutomaticSecurity, reliability, incident scoping[CONFIRM window; target at least 30 days]
InferencesSanitized, de-identified text derived from your entries for AI processingDerived on deviceTo generate the reflections you requestTransient; not retained by providers
Consent and compliance recordsConsent choices with version and timestamp, age attestation, content-free automated-processing recordsYou / automaticLegal compliance, proof of consent[CONFIRM post-deletion retention: see §11]

We do not collect precise geolocation, biometric identifiers, voiceprints, government identifiers, or advertising identifiers. We do not create a voiceprint or any voice-based biometric identifier at any point.

4.2 From the website (replaycouples.com)

CategorySpecific informationPurposeRetention
IdentifiersEmail address if you submit a form or join a listTo respond, to send the requested material, to notify you at launchUntil you unsubscribe or request deletion, then [CONFIRM]
Internet/network activityPrivacy-friendly, first-party, cookieless analytics (page views, referrer, approximate region)To understand site usage[CONFIRM]

The website uses first-party analytics only. We do not use Google Analytics, advertising pixels, or third-party tracking cookies. Website email collection is separate from the app and is notprotected by the app’s end-to-end encryption; an email address you give us on the website is ordinary business data we can read.

How website email sign-up works. We use double opt-in: when you submit your email we send a confirmation link, and we only add you to the list after you click it. Once confirmed, we deliver the resource you requested and a short welcome sequence of a few messages over about two weeks. Every marketing message includes a working one-tap unsubscribe and our postal mailing address, and unsubscribes are honored immediately. We do not set any cookies for this. ATTORNEY: confirm CAN-SPAM and consent-record wording.

Global Privacy Control. When your browser sends the Global Privacy Control signal (the Sec-GPC header or navigator.globalPrivacyControl), we treat it as an opt-out: we do none of the sale or sharing it targets, and we additionally suppress our non-essential first-party analytics for that visit.

4.3 Information about other people

Entries you create may describe your partner or others. That information is encrypted and unreadable to us. We disclose this in the app. See §9.4 for how requests about such information are handled. ATTORNEY: confirm the disclosure and deletion posture, ATTORNEY-DECISION 2.

5. How we use personal information

To provide, secure, and maintain the service; to authenticate you; to process subscriptions; to generate the reflections and features you request; to operate the app’s safety features; to respond to you; to comply with legal obligations; and to detect and prevent fraud, abuse, and security incidents.

We do not use your information for advertising, profiling for advertising, or any purpose incompatible with those above. We do not use your content to train AI models, and our providers are contractually prohibited from doing so.

6. Legal bases (Canada, excluding Quebec)

Where PIPEDA applies, we process on the basis of your knowledge and consent, obtained expressly and per purpose in the app, and withdrawable at any time. [Quebec residents: Law 25 is out of scope in this version.]

7. Service providers (subprocessors)

ProviderRoleWhat it receivesTerms
Anthropic, PBCAI reasoningSanitized, de-identified text onlyZero-retention configuration; no training [CONFIRM DPA executed]
Voyage AIEmbeddingsSanitized, de-identified text onlyNo-training setting [CONFIRM DPA]
ElevenLabsVoice synthesisBlame-neutral output lines only; never crisis or safety-held contentPer-request logging disabled; zero-retention workspace setting [CONFIRM DPA]
RevenueCatSubscription entitlementsSubscription metadata; no content[CONFIRM DPA]
SupabaseEncrypted-content hosting and authentication (United States, us-east-1)Ciphertext and account metadata[CONFIRM DPA]
SendGrid (Twilio)Website email deliveryEmail addresses submitted on the website[CONFIRM DPA]
Apple, GoogleApp distribution, payment processing, push deliveryPer platform policiesPlatform terms

These are service providers/processors acting on our instructions, not independent recipients. We do not authorize them to use your information for their own purposes.

8. Disclosure of personal information

We disclose personal information only: to the service providers above; to comply with law, legal process, or a valid governmental request; to establish, exercise, or defend legal claims; to protect the rights, safety, or property of any person; and in connection with a merger, acquisition, or asset sale, in which case this policy continues to apply to the transferred information until amended with notice.

We have not sold personal information or shared it for cross-context behavioral advertising in the preceding twelve months, and we do not do so. We do not sell or share the personal information of anyone under 16. The app is limited to adults 18 and over.

9. Your rights and how to exercise them

9.1 Rights

Depending on your residence, you may have the right to: know what we collect and why; access and receive a portable copy; correct inaccuracies; delete; opt out of sale, sharing, or targeted advertising (we do none); limit use of sensitive personal information; withdraw consent; and not be discriminated or retaliated against for exercising a right.

9.2 How to exercise

Use the in-app controls (Settings) for export, correction, and account deletion, or contact [privacy@ email]. Deletion is also available at replaycouples.com/delete-account.

9.3 Verification and timing

We verify requests by confirming control of the account email, and for sensitive requests may require additional confirmation. We do not require an account to make a request but may be unable to verify a request from someone we cannot associate with data we hold. We respond within 45 days, extendable once by an additional 45 days with notice, or sooner where a shorter period applies. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you why before proceeding.

9.4 Limitations under encryption

Because entry content is end-to-end encrypted, we cannot read, locate, correct, or selectively delete information within your entries, including information about another person. We can delete entries and accounts in full. ATTORNEY: confirm this satisfies deletion and correction obligations, including as to third-party information, ATTORNEY-DECISION 2.

9.5 Authorized agents

You may use an authorized agent, who must provide written, signed permission; we may also contact you directly to confirm and to verify your identity.

9.6 Appeals

If we deny a request, you may appeal by writing to [appeals contact] within [60] days. We will respond in writing within 45 days with our decision and reasoning. If we deny the appeal, you may contact your state attorney general. [Required in CO, CT, VA, and others; confirm state list.]

9.7 State-specific

California:the rights above, plus the right to know categories of sources and recipients (§§4, 7, 8) and the right to limit use of sensitive personal information. We do not use or disclose sensitive personal information for purposes requiring an opt-out. Under Cal. Civ. Code §1798.83, California residents may request information about disclosures to third parties for direct-marketing purposes; we make none.

Washington, Nevada, Connecticut: see our separate Consumer Health Data Privacy Policy.

Other states:residents of states with comprehensive privacy laws in effect have access, correction, deletion, portability, and opt-out rights on the terms of their state’s law, and we honor the Global Privacy Control universal opt-out signal on our website where required.

Canada (excluding Quebec): access and correction rights under PIPEDA; contact [privacy contact]. You may complain to the Office of the Privacy Commissioner of Canada.

10. Cross-border transfers

We are located in the United States and process and store information in the United States. If you are in Canada, your information is transferred to and processed in the United States by us and the providers in §7, and is subject to United States law and lawful access by United States authorities. By using the service you acknowledge this transfer. ATTORNEY: confirm PIPEDA transparency wording.

11. Retention and deletion

We retain personal information for the periods in §4 and for as long as needed for the purposes described, then delete or de-identify it. On account deletion we delete server-side content and account records, remove local data on the device, and instruct providers to delete any copy they hold. We may retain: records required by law (tax, accounting); records of consent and age attestation as proof of your affirmative acts; and content-free security logs, each for the minimum necessary period. ATTORNEY: confirm post-deletion retention of consent proof, which is in tension with a complete-deletion representation. Also: if Canada is in scope, PIPEDA requires breach records be kept 24 months.

12. Security

We use end-to-end encryption, hardware-backed key storage, encryption in transit and at rest, row-level access controls, and least-privilege access. No system is perfectly secure. We maintain a written incident-response runbook and will notify you and regulators of a security breach as required by applicable law.

13. Minors

The service is for adults 18 and over. We do not knowingly collect personal information from anyone under 18. A user who indicates they are under 18 has local data wiped and is denied access. If you believe a minor has provided information, contact [privacy@ email] and we will delete it.

14. Automated processing and AI

We use automated processing, including AI models, to generate reflections, patterns, and optional spoken responses, operating only on sanitized, de-identified text. These are reflective tools. They do not produce legal or similarly significant decisions about you, do not diagnose, and are not a substitute for professional judgment. We keep content-free records of this processing. You may withdraw consent to cloud AI processing in the app, in which case the app degrades conservatively to on-device processing. ATTORNEY: confirm against the Colorado AI Act, effective June 30, 2026, and any successor state AI laws.

15. Third-party links

Our website and app may link to third-party sites and to the app stores. We are not responsible for their privacy practices.

16. Changes

We will update this policy as needed. Material changes will be notified in the app and, where required, will require renewed consent. The app increments its policy version and re-obtains consent automatically when legal wording changes.

17. Accessibility

If you need this policy in an alternative accessible format, contact [privacy@ email].

18. Contact

Automate AI LLC, [address]. Privacy: [privacy@ email]. Support: support@construktr.ai.

Attorney checklist for this document

  • Confirm the CCPA/CPRA category mapping and retention entries in §4.
  • Confirm §9.4 (deletion/correction limits under E2EE) satisfies obligations, including third-party data in user entries.
  • Confirm §11 post-deletion retention of consent proof against the deletion representation.
  • Confirm the appeal states and timelines in §9.6.
  • Confirm §10 cross-border wording for PIPEDA.
  • Confirm §14 against the Colorado AI Act and successors.
  • Confirm the “have not sold in the preceding twelve months” statement in §8 is accurate and appropriately phrased.
  • Confirm whether a separate website privacy notice is preferable to the combined approach used here.