Privacy Policy
Dryrun is a voice roleplay app that helps you practice difficult conversations. This policy describes what personal information we collect, how we collect it, every way we use it, who we share it with, how we require those parties to protect it, and how you can ask us to delete it.
Dryrun is operated by a business located in California, United States (“Dryrun,” “we,” “us”). We are the controller of personal information described here, except where Apple or a network provider collects information under its own policy (for example TestFlight crash logs collected by Apple).
This is not legal advice. It reflects how the product actually works as of the date above, including vendor terms we have on file. If we change a vendor setting (for example enabling crash reporting or a vendor’s zero-data-retention add-on), we will update this page.
1. Information we collect
We collect the categories below when you create an account and use Dryrun. We do not collect payment card data, advertising IDs, contacts, photos, precise location, or analytics from Mixpanel, Amplitude, Firebase Analytics, or similar products. We do not clone your voice.
Account and profile
What: Email address, password (stored hashed by our auth provider; we do not see the plaintext), display name, account ID, and session tokens.
How collected: You type them at sign-up, sign-in, or password reset. Session tokens are stored on your device after you sign in.
Uses: Create and secure your account; keep you signed in; send password-reset (and, if enabled, confirmation) email; associate saved personas and roleplays with you.
Shared with: Supabase (auth and database). Password-reset email is sent through Supabase and its email delivery subprocessor.
Microphone audio — persona and scene interviews
What: Live microphone audio (PCM) while you describe a person or a situation. The app does not save an audio file on the phone.
How collected: After you grant microphone permission, audio is streamed from the device to Deepgram’s speech-to-text API. Our server only issues a short-lived token; interview audio does not pass through our servers.
Uses: Turn speech into text so we can build a persona or scene.
Shared with: Deepgram (direct). We set Deepgram’s per-request model-improvement opt-out on these requests.
Interview transcripts and extracted personas / scenes
What: The transcript of what you said in setup, plus structured fields we derive (for example how someone communicates, conflict style, “who” you are talking to, and a scene briefing). Persona records include a copy of the raw transcript. Scene/roleplay records store the briefing text, not the live roleplay audio.
How collected: Transcript text is sent from the app to our API, then to Anthropic, then saved in our database. A copy of personas may also be cached on your device.
Uses: Create and store the people and situations you practice with; generate the next interview question; run later roleplays.
Shared with: Anthropic (to extract and prompt); Supabase (to store); Railway (our API host, which receives the JSON in transit and may log request metadata).
Microphone audio and conversation — live roleplay
What: Your live voice and the AI character’s spoken replies during a practice round; the system prompt for that round (who you are talking to, scene briefing, adjustments); call metadata such as roleplay ID, round number, and your user ID; and, on Vapi’s side, recordings, transcripts, messages, summaries, and call logs under Vapi’s default product settings.
How collected: After you grant microphone permission, audio is sent through Vapi’s voice pipeline (WebRTC via Daily). Vapi sends your speech to Deepgram for live transcription, conversation text to OpenAI to generate the character’s replies, and assistant reply text to ElevenLabs to synthesize the character’s voice. User microphone audio is not sent to ElevenLabs. A parallel transcript stream comes back to our app for coaching and interruptions.
Uses: Run the live practice conversation; decide in-character interruptions; generate coaching tips; produce written feedback after the round; measure usage/cost.
Shared with: Vapi; Daily (transport); Deepgram, OpenAI, and ElevenLabs as Vapi’s providers; Anthropic (coaching, interruptions, written feedback); our API on Railway; Supabase if we store a usage record or, when our Vapi webhook is configured, a copy of the call transcript.
Coaching tips and short quotes of what you said
What: Recent live transcript lines, scene context, and the tip shown in the app, including a “you said” excerpt. These log rows are stored without your account ID.
How collected: Created during a live round by our API (Anthropic) and written to our database.
Uses: Show you a tip in the moment; review and improve coaching quality during beta.
Shared with: Anthropic (to generate the tip); Supabase (storage). Because these rows are not tied to your user ID, we may not be able to find every excerpt on a deletion request unless you give us the approximate time of the session.
Written feedback after a round
What: Strengths, improvements, and a focus for the next round. We do not store the full live transcript in the feedback table.
How collected: After a round, the in-memory transcript is sent to Anthropic; only the three feedback fields are saved.
Uses: Show you the debrief screen; keep history on that roleplay.
Shared with: Anthropic; Supabase.
Usage and cost records
What: Duration and cost of speech and voice calls (for example Deepgram audio milliseconds). If our Vapi webhook is enabled, the record can also include call duration, end reason, summary, cost breakdown, and the full call transcript.
How collected: The app and/or Vapi report to our API after a call or transcription session.
Uses: Operate the service, understand cost, debug failures, and (if the webhook is on) retain a transcript copy we control.
Shared with: Supabase; Railway (API). Source data also exists at Vapi.
On-device storage
What: Session tokens, a local cache of personas (including transcript text), and whether you have seen product tours. Tokens are stored in ordinary app storage, not the iOS Keychain.
How collected: Written by the app on your phone.
Uses: Keep you signed in and the app usable offline for saved personas.
Shared with: Not uploaded as a vendor dataset. Deleted if you sign out, delete the persona, or uninstall the app (OS permitting).
Server logs
What: Technical logs from our API (for example user ID, route, roleplay ID, timing, truncated error/operation text). Interview audio files are not stored on this host. Request bodies that include transcripts may appear in logs if logged.
How collected: Automatically when the app calls our API.
Uses: Security, debugging, reliability.
Shared with: Railway (hosting and log storage).
TestFlight crash logs, usage, and tester identity (beta only)
What: Crash logs, session counts, device type, OS, app version; if Apple invited you by email, your name and email as shown in App Store Connect. Screenshot feedback can include whatever is on screen (persona names, scene text, coaching). Testers who join via a public link do not have name/email shown to us.
How collected: Automatically by Apple when you install a TestFlight build. You cannot opt out of crash and usage collection in TestFlight.
Uses: We use this only to improve Dryrun. Apple may use crash and usage data to improve TestFlight and to detect fraud. We are not permitted to share TestFlight data with another company.
Shared with: Collected by Apple and provided to us. See Apple’s TestFlight & Privacy notice.
Technical data from content-delivery networks
What: IP address, user-agent, and URL when the app loads the Vapi web SDK from a CDN (esm.sh, jsDelivr, or esm.run).
How collected: Ordinary HTTPS download. No microphone audio is sent to these CDNs.
Uses: Load the live-call software.
Shared with: The CDN operator, under that operator’s policy.
What we do not currently send
Sentry crash reporting is compiled into the app but is turned off unless we set a Sentry project key. If we turn it on, we will update this policy; it would receive stack traces, device/OS, and release version, without a default user email attachment.
2. How we use personal information
We use the information above only for these purposes:
- Provide the Dryrun service you request: accounts, personas, scenes, live roleplay, coaching, interruptions, and written feedback.
- Operate, secure, and debug the app and API (logs, usage/cost records, TestFlight crashes).
- Send account emails (password reset; confirmation email if we enable it).
- Improve coaching and the product during beta, using tip logs and (if stored) transcripts we hold.
- Comply with law and enforce our terms, including investigating abuse.
We do not use your information for advertising, sell it, or share it for cross-context behavioral advertising. We do not use your voice to identify you uniquely or to clone your voice.
3. Who we share it with
We share personal information with the companies that actually process the data described above. We do not sell personal information.
| Company | Role | What they receive |
|---|---|---|
| Supabase Pte. Ltd. | Processor (auth + database) | Account, personas, scenes, feedback, usage rows, coaching-tip logs |
| Railway Corporation | Processor (API hosting) | API traffic and server logs |
| Deepgram, Inc. | Processor for interview STT; Vapi provider for live STT | Interview audio (direct). Live roleplay audio via Vapi |
| Anthropic PBC | Processor (language model API) | Transcripts and prompts for personas, scenes, coaching, interruptions, feedback |
| Vapi | Processor / voice platform | Live roleplay audio, transcripts, assistant config, call metadata; may store recordings and logs by default |
| Daily.co | Vapi’s WebRTC transport | Live media in transit; Daily states it does not store call audio unless recording APIs are used |
| OpenAI | Vapi’s language-model provider (gpt-4o-mini) | Live conversation text via Vapi. We do not have a direct OpenAI API contract for roleplay |
| ElevenLabs | Vapi’s text-to-speech provider | Assistant reply text (not your microphone). We do not have an ElevenLabs account |
| Apple | TestFlight / App Store platform | Crash logs, usage, tester name/email when invited by email |
| Expo (EAS) | Build and distribution | Not runtime speech. May receive push tokens or update tokens only if we enable those Expo features |
| CDN operators (esm.sh, jsDelivr, esm.run) | Script delivery | IP and request metadata when loading the Vapi SDK |
We may also disclose information if required by law, to protect rights and safety, or in a merger or sale of the business, subject to this policy.
4. Equal protection (third parties)
Apple requires that if we share user data with a third party, that party provide the same or equal protection of the data as described in this policy. Here is what that means in practice for Dryrun:
- Companies we contract with as processors — Supabase, Railway, Anthropic, and Deepgram (for interview speech-to-text) — publish data-processing terms that prohibit selling customer data and limit use to providing their service (and, for Anthropic’s commercial API, prohibit training on customer content unless we join a separate partner program, which we have not). We rely on those contracts so that personal information they process is protected at least as described in this policy.
- Vapi processes live roleplay under its terms. Vapi may store call recordings and transcripts by default and may use that content to improve its own voice features (for example turn-taking and interruption detection), in a form that Vapi states does not identify the business or the caller. Vapi states it does not share your content with OpenAI, Deepgram, ElevenLabs, or Daily for those companies’ independent model training.
- Vapi’s providers. Vapi’s terms say each provider’s own terms apply, and that Vapi does not warrant those providers’ compliance. We have reviewed the published API/privacy terms for OpenAI, Deepgram, ElevenLabs, and Daily. We do not claim any stronger protection than those published terms. In particular, we have not enabled Vapi zero-data-retention or HIPAA mode, OpenAI or Anthropic zero-data-retention, or ElevenLabs zero-retention on an account we control.
- Apple TestFlight is collected under Apple’s policy. We do not share that data onward.
We will not describe Dryrun as “HIPAA compliant,” as “zero retention,” or as a service that “never stores your voice.” Live roleplay audio and transcripts may be stored by Vapi under its default settings.
5. AI training and how long vendors keep API content
- Anthropic: Does not train on our API inputs or outputs. Retains them on its backend for up to 30 days for safety and abuse monitoring (longer if flagged for a usage-policy violation or required by law). We have not enabled Anthropic zero data retention.
- OpenAI (via Vapi): Published API default is no training on inputs or outputs unless the API customer opts in. Abuse-monitoring logs are retained up to 30 days. We do not operate an OpenAI zero-data-retention organization.
- Deepgram (interviews): We opt each interview request out of Deepgram’s Model Improvement Program. Deepgram states opted-out requests are retained only as long as needed to process them.
- Deepgram (live roleplay via Vapi): Audio is sent by Vapi. Vapi states it does not share content for providers’ independent training. We have not confirmed Deepgram project-level opt-out on Vapi’s Deepgram account.
- Vapi: May use call content to improve its own service features, as described above. We have not purchased Vapi’s zero-data-retention add-on.
- ElevenLabs (via Vapi): Receives assistant text, not your microphone. Training and retention on ElevenLabs’ side are controlled by Vapi’s ElevenLabs account, which we do not operate. We do not claim ElevenLabs zero retention.
6. How long we keep information
- Account, personas, scenes, feedback, usage rows: Until you delete them or we delete your account, plus backups kept by our processors for a limited period after that (Supabase’s DPA provides a 30-day window after contract end to export, then deletion of copies they process).
- Coaching-tip logs: No automatic expiry today. Not stored with your user ID.
- On-device data: Until sign-out, item deletion, or uninstall.
- Railway logs: According to our Railway plan (exact window not published in this policy; ask us if you need the current setting).
- Vapi call recordings/transcripts: According to Vapi’s default product retention. We have not confirmed a public day-count and do not quote one.
- Anthropic / OpenAI API copies: Up to 30 days for abuse/safety, as those vendors describe, unless a longer legal or safety hold applies.
- Apple TestFlight: Apple retains beta feedback for one year and may retain crash and usage data until bugs are resolved.
7. How to request deletion and other choices
You can delete individual personas and roleplays in the app. That removes the corresponding rows we store (persona data, scene, feedback for that roleplay).
To delete your account and remaining personal information we hold, email privacy@itsdryrun.com from the address on the account (or use Contact on itsdryrun.com and identify the account). We will:
- Verify the request is yours.
- Delete or de-identify your account, profile, personas, roleplays, feedback, and usage rows we can tie to your user ID, generally within 30 days (sooner when feasible).
- Ask our processors (including Supabase, Railway, Anthropic, Deepgram, and Vapi) to delete personal information they hold for us that we can reasonably identify, subject to their residual backups, security logs, and legal holds.
What we may not be able to fully erase on request:
- Coaching-tip excerpts that are not stored with your user ID, unless you give us enough detail (date/time of the session) to find them.
- Copies already in Anthropic or OpenAI’s 30-day abuse-monitoring stores, or Vapi’s stored call artifacts, until those vendors’ own retention ends.
- Apple TestFlight records that Apple controls.
- Information we must keep for law, dispute, or security.
You can also revoke microphone permission in iOS/Android settings (the app cannot run voice features without it), sign out (clears session tokens on device), and uninstall the app.
There is no in-app advertising preference center because we do not run ads or sell/share personal information for advertising.
8. California privacy rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA applies. In the prior 12 months we have collected the categories of personal information listed in section 1. Sources are you (the app), our processors acting on our instructions, and Apple (TestFlight). Business purposes are those in section 2. Categories of third parties are those in section 3.
Sensitive personal information we process can include account log-in (email and password), and the contents of your speech (transcripts may describe other people). We use sensitive personal information only to provide Dryrun, not to infer characteristics for advertising, and not to sell or share.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not offer a financial incentive for data. If that changes, we will update this policy and provide a “Do Not Sell or Share” method. We honor Global Privacy Control signals as a request to opt out of sale/sharing; because we do not sell or share, there is no additional sale to turn off.
You have the right to:
- Know / access the personal information we hold about you
- Delete personal information, subject to exceptions
- Correct inaccurate personal information
- Opt out of sale or sharing (not applicable to our current practices)
- Limit use of sensitive personal information to the uses allowed by law for providing the service (our current use is already limited to providing Dryrun)
- Not be discriminated against for exercising these rights
To exercise these rights, email privacy@itsdryrun.com. We will verify your identity (typically by confirming control of the account email). You may use an authorized agent; we may require proof of authorization and still verify you. We will respond within the time CPRA requires. You may appeal a denial by replying to our decision; we will explain in writing.
California “Shine the Light”: we do not disclose personal information to third parties for their direct marketing.
9. EEA and United Kingdom (GDPR)
If you use Dryrun from the EEA or UK, we process personal data as controller on these bases:
- Contract (Art. 6(1)(b)): account, personas, scenes, live roleplay, coaching, feedback, and the vendor processing needed to deliver them.
- Consent (Art. 6(1)(a)): microphone access, which you can withdraw in system settings (the voice product will not work without it).
- Legitimate interests (Art. 6(1)(f)): security, debugging, usage/cost records, and improving coaching during beta, balanced against your interests in a private practice space.
- Legal obligation (Art. 6(1)(c)): where the law requires us to keep or disclose information.
You may request access, correction, deletion, restriction, objection, and portability, and you may withdraw consent without affecting processing before withdrawal. You may complain to your local supervisory authority. UK users may contact the ICO.
We and our processors store and process data in the United States. Where GDPR requires a transfer mechanism, we rely on the Standard Contractual Clauses (and UK addendum where applicable) in our processors’ DPAs (including Supabase, Railway, Anthropic, and Deepgram). Vapi and its providers also process live voice in accordance with their terms, which include US processing.
10. Children
Dryrun is not directed at children. We do not knowingly collect personal information from anyone under 13 (or under 16 where GDPR requires that age for consent). If you believe a child has created an account, contact us and we will delete it.
11. Security
Vendor API keys for Anthropic, Deepgram, and Vapi live on our server, not in the mobile app. Database access is limited by account-based rules for your personas and roleplays. Session tokens on the device are stored in ordinary app storage. No method of transmission or storage is 100% secure.
12. Changes
We will post updates on this page and change the “Last updated” date. If we start collecting a new category, turn on Sentry, enable payments, or change a material vendor practice (for example Vapi zero-data-retention), we will revise this policy before or when that change takes effect.
13. Contact
Privacy requests, including access and deletion:
privacy@itsdryrun.com
Dryrun, California, United States
Website: https://itsdryrun.com/
This page is public and does not require an account. Canonical URL: https://itsdryrun.com/privacy.