Privacy Policy

Effective: 21 August 2026 · Last updated: 21 August 2026 · Applies to the Dryrun iOS/Android app (bundle ID com.dryrun.app), including TestFlight, and this website.

Dryrun is a voice roleplay app that helps you practice difficult conversations. This policy describes what personal information we collect, how we collect it, every way we use it, who we share it with, how we require those parties to protect it, and how you can ask us to delete it.

Dryrun is operated by a business located in California, United States (“Dryrun,” “we,” “us”). We are the controller of personal information described here, except where Apple or a network provider collects information under its own policy (for example TestFlight crash logs collected by Apple).

This is not legal advice. It reflects how the product actually works as of the date above, including vendor terms we have on file. If we change a vendor setting (for example enabling crash reporting or a vendor’s zero-data-retention add-on), we will update this page.

1. Information we collect

We collect the categories below when you create an account and use Dryrun. We do not collect payment card data, advertising IDs, contacts, photos, precise location, or analytics from Mixpanel, Amplitude, Firebase Analytics, or similar products. We do not clone your voice.

Account and profile

What: Email address, password (stored hashed by our auth provider; we do not see the plaintext), display name, account ID, and session tokens.

How collected: You type them at sign-up, sign-in, or password reset. Session tokens are stored on your device after you sign in.

Uses: Create and secure your account; keep you signed in; send password-reset (and, if enabled, confirmation) email; associate saved personas and roleplays with you.

Shared with: Supabase (auth and database). Password-reset email is sent through Supabase and its email delivery subprocessor.

Microphone audio — persona and scene interviews

What: Live microphone audio (PCM) while you describe a person or a situation. The app does not save an audio file on the phone.

How collected: After you grant microphone permission, audio is streamed from the device to Deepgram’s speech-to-text API. Our server only issues a short-lived token; interview audio does not pass through our servers.

Uses: Turn speech into text so we can build a persona or scene.

Shared with: Deepgram (direct). We set Deepgram’s per-request model-improvement opt-out on these requests.

Interview transcripts and extracted personas / scenes

What: The transcript of what you said in setup, plus structured fields we derive (for example how someone communicates, conflict style, “who” you are talking to, and a scene briefing). Persona records include a copy of the raw transcript. Scene/roleplay records store the briefing text, not the live roleplay audio.

How collected: Transcript text is sent from the app to our API, then to Anthropic, then saved in our database. A copy of personas may also be cached on your device.

Uses: Create and store the people and situations you practice with; generate the next interview question; run later roleplays.

Shared with: Anthropic (to extract and prompt); Supabase (to store); Railway (our API host, which receives the JSON in transit and may log request metadata).

Microphone audio and conversation — live roleplay

What: Your live voice and the AI character’s spoken replies during a practice round; the system prompt for that round (who you are talking to, scene briefing, adjustments); call metadata such as roleplay ID, round number, and your user ID; and, on Vapi’s side, recordings, transcripts, messages, summaries, and call logs under Vapi’s default product settings.

How collected: After you grant microphone permission, audio is sent through Vapi’s voice pipeline (WebRTC via Daily). Vapi sends your speech to Deepgram for live transcription, conversation text to OpenAI to generate the character’s replies, and assistant reply text to ElevenLabs to synthesize the character’s voice. User microphone audio is not sent to ElevenLabs. A parallel transcript stream comes back to our app for coaching and interruptions.

Uses: Run the live practice conversation; decide in-character interruptions; generate coaching tips; produce written feedback after the round; measure usage/cost.

Shared with: Vapi; Daily (transport); Deepgram, OpenAI, and ElevenLabs as Vapi’s providers; Anthropic (coaching, interruptions, written feedback); our API on Railway; Supabase if we store a usage record or, when our Vapi webhook is configured, a copy of the call transcript.

Coaching tips and short quotes of what you said

What: Recent live transcript lines, scene context, and the tip shown in the app, including a “you said” excerpt. These log rows are stored without your account ID.

How collected: Created during a live round by our API (Anthropic) and written to our database.

Uses: Show you a tip in the moment; review and improve coaching quality during beta.

Shared with: Anthropic (to generate the tip); Supabase (storage). Because these rows are not tied to your user ID, we may not be able to find every excerpt on a deletion request unless you give us the approximate time of the session.

Written feedback after a round

What: Strengths, improvements, and a focus for the next round. We do not store the full live transcript in the feedback table.

How collected: After a round, the in-memory transcript is sent to Anthropic; only the three feedback fields are saved.

Uses: Show you the debrief screen; keep history on that roleplay.

Shared with: Anthropic; Supabase.

Usage and cost records

What: Duration and cost of speech and voice calls (for example Deepgram audio milliseconds). If our Vapi webhook is enabled, the record can also include call duration, end reason, summary, cost breakdown, and the full call transcript.

How collected: The app and/or Vapi report to our API after a call or transcription session.

Uses: Operate the service, understand cost, debug failures, and (if the webhook is on) retain a transcript copy we control.

Shared with: Supabase; Railway (API). Source data also exists at Vapi.

On-device storage

What: Session tokens, a local cache of personas (including transcript text), and whether you have seen product tours. Tokens are stored in ordinary app storage, not the iOS Keychain.

How collected: Written by the app on your phone.

Uses: Keep you signed in and the app usable offline for saved personas.

Shared with: Not uploaded as a vendor dataset. Deleted if you sign out, delete the persona, or uninstall the app (OS permitting).

Server logs

What: Technical logs from our API (for example user ID, route, roleplay ID, timing, truncated error/operation text). Interview audio files are not stored on this host. Request bodies that include transcripts may appear in logs if logged.

How collected: Automatically when the app calls our API.

Uses: Security, debugging, reliability.

Shared with: Railway (hosting and log storage).

TestFlight crash logs, usage, and tester identity (beta only)

What: Crash logs, session counts, device type, OS, app version; if Apple invited you by email, your name and email as shown in App Store Connect. Screenshot feedback can include whatever is on screen (persona names, scene text, coaching). Testers who join via a public link do not have name/email shown to us.

How collected: Automatically by Apple when you install a TestFlight build. You cannot opt out of crash and usage collection in TestFlight.

Uses: We use this only to improve Dryrun. Apple may use crash and usage data to improve TestFlight and to detect fraud. We are not permitted to share TestFlight data with another company.

Shared with: Collected by Apple and provided to us. See Apple’s TestFlight & Privacy notice.

Technical data from content-delivery networks

What: IP address, user-agent, and URL when the app loads the Vapi web SDK from a CDN (esm.sh, jsDelivr, or esm.run).

How collected: Ordinary HTTPS download. No microphone audio is sent to these CDNs.

Uses: Load the live-call software.

Shared with: The CDN operator, under that operator’s policy.

What we do not currently send

Sentry crash reporting is compiled into the app but is turned off unless we set a Sentry project key. If we turn it on, we will update this policy; it would receive stack traces, device/OS, and release version, without a default user email attachment.

2. How we use personal information

We use the information above only for these purposes:

We do not use your information for advertising, sell it, or share it for cross-context behavioral advertising. We do not use your voice to identify you uniquely or to clone your voice.

3. Who we share it with

We share personal information with the companies that actually process the data described above. We do not sell personal information.

Company Role What they receive
Supabase Pte. Ltd. Processor (auth + database) Account, personas, scenes, feedback, usage rows, coaching-tip logs
Railway Corporation Processor (API hosting) API traffic and server logs
Deepgram, Inc. Processor for interview STT; Vapi provider for live STT Interview audio (direct). Live roleplay audio via Vapi
Anthropic PBC Processor (language model API) Transcripts and prompts for personas, scenes, coaching, interruptions, feedback
Vapi Processor / voice platform Live roleplay audio, transcripts, assistant config, call metadata; may store recordings and logs by default
Daily.co Vapi’s WebRTC transport Live media in transit; Daily states it does not store call audio unless recording APIs are used
OpenAI Vapi’s language-model provider (gpt-4o-mini) Live conversation text via Vapi. We do not have a direct OpenAI API contract for roleplay
ElevenLabs Vapi’s text-to-speech provider Assistant reply text (not your microphone). We do not have an ElevenLabs account
Apple TestFlight / App Store platform Crash logs, usage, tester name/email when invited by email
Expo (EAS) Build and distribution Not runtime speech. May receive push tokens or update tokens only if we enable those Expo features
CDN operators (esm.sh, jsDelivr, esm.run) Script delivery IP and request metadata when loading the Vapi SDK

We may also disclose information if required by law, to protect rights and safety, or in a merger or sale of the business, subject to this policy.

4. Equal protection (third parties)

Apple requires that if we share user data with a third party, that party provide the same or equal protection of the data as described in this policy. Here is what that means in practice for Dryrun:

We will not describe Dryrun as “HIPAA compliant,” as “zero retention,” or as a service that “never stores your voice.” Live roleplay audio and transcripts may be stored by Vapi under its default settings.

5. AI training and how long vendors keep API content

6. How long we keep information

7. How to request deletion and other choices

You can delete individual personas and roleplays in the app. That removes the corresponding rows we store (persona data, scene, feedback for that roleplay).

To delete your account and remaining personal information we hold, email privacy@itsdryrun.com from the address on the account (or use Contact on itsdryrun.com and identify the account). We will:

  1. Verify the request is yours.
  2. Delete or de-identify your account, profile, personas, roleplays, feedback, and usage rows we can tie to your user ID, generally within 30 days (sooner when feasible).
  3. Ask our processors (including Supabase, Railway, Anthropic, Deepgram, and Vapi) to delete personal information they hold for us that we can reasonably identify, subject to their residual backups, security logs, and legal holds.

What we may not be able to fully erase on request:

You can also revoke microphone permission in iOS/Android settings (the app cannot run voice features without it), sign out (clears session tokens on device), and uninstall the app.

There is no in-app advertising preference center because we do not run ads or sell/share personal information for advertising.

8. California privacy rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA applies. In the prior 12 months we have collected the categories of personal information listed in section 1. Sources are you (the app), our processors acting on our instructions, and Apple (TestFlight). Business purposes are those in section 2. Categories of third parties are those in section 3.

Sensitive personal information we process can include account log-in (email and password), and the contents of your speech (transcripts may describe other people). We use sensitive personal information only to provide Dryrun, not to infer characteristics for advertising, and not to sell or share.

We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not offer a financial incentive for data. If that changes, we will update this policy and provide a “Do Not Sell or Share” method. We honor Global Privacy Control signals as a request to opt out of sale/sharing; because we do not sell or share, there is no additional sale to turn off.

You have the right to:

To exercise these rights, email privacy@itsdryrun.com. We will verify your identity (typically by confirming control of the account email). You may use an authorized agent; we may require proof of authorization and still verify you. We will respond within the time CPRA requires. You may appeal a denial by replying to our decision; we will explain in writing.

California “Shine the Light”: we do not disclose personal information to third parties for their direct marketing.

9. EEA and United Kingdom (GDPR)

If you use Dryrun from the EEA or UK, we process personal data as controller on these bases:

You may request access, correction, deletion, restriction, objection, and portability, and you may withdraw consent without affecting processing before withdrawal. You may complain to your local supervisory authority. UK users may contact the ICO.

We and our processors store and process data in the United States. Where GDPR requires a transfer mechanism, we rely on the Standard Contractual Clauses (and UK addendum where applicable) in our processors’ DPAs (including Supabase, Railway, Anthropic, and Deepgram). Vapi and its providers also process live voice in accordance with their terms, which include US processing.

10. Children

Dryrun is not directed at children. We do not knowingly collect personal information from anyone under 13 (or under 16 where GDPR requires that age for consent). If you believe a child has created an account, contact us and we will delete it.

11. Security

Vendor API keys for Anthropic, Deepgram, and Vapi live on our server, not in the mobile app. Database access is limited by account-based rules for your personas and roleplays. Session tokens on the device are stored in ordinary app storage. No method of transmission or storage is 100% secure.

12. Changes

We will post updates on this page and change the “Last updated” date. If we start collecting a new category, turn on Sentry, enable payments, or change a material vendor practice (for example Vapi zero-data-retention), we will revise this policy before or when that change takes effect.

13. Contact

Privacy requests, including access and deletion:

privacy@itsdryrun.com
Dryrun, California, United States
Website: https://itsdryrun.com/

This page is public and does not require an account. Canonical URL: https://itsdryrun.com/privacy.