Privacy Policy
Last updated 2026-07-05
Sayable is a speech-practice application operated by TEAHOUSEAI LLC, a Texas limited liability company ("Sayable," "we," "us," or "our"). This Privacy Policy explains what personal information we collect from and about users of the Sayable web application (sayable.work) and the Sayable iOS application (collectively, the "Service"), how we use it, who we share it with, and the rights you have over it.
If you have questions about this policy, contact us at support@sayable.work.
1. Scope
This policy applies to information we collect when you:
- Create or use a Sayable account
- Record speech practice sessions ("reps") through the Service
- Interact with our marketing pages at sayable.work
- Contact us for support
It does not apply to third-party sites or services we link to, or to information you provide directly to a third party outside the Service.
2. Information We Collect
2.1 Information you provide directly
- Account information. Email address and either (a) a hashed password or (b) an Apple Sign-In identity token, depending on how you sign up.
- Payment information. For web subscriptions, payment card and billing details are collected and stored by Stripe, our payment processor. We receive only a subscription status and a limited billing record; we do not store your full card number. For iOS subscriptions, Apple handles payment directly and shares only a subscription state with us.
- User content. Voice recordings you create during practice reps, transcripts of those recordings, and any notes or metadata you attach to a rep.
- Support communications. Emails and messages you send to support@sayable.work.
2.2 Information collected automatically
- Session data. Log-in state, session identifiers, and technical metadata associated with your account (user ID, device type, app or browser version).
- Product analytics. With your consent where required, we use PostHog to record product events (which screens you viewed, which features you used) to understand how the Service is used and to improve it.
- Error monitoring. With your consent where required, we use Sentry to record technical errors and crashes so we can fix them. Error reports may include limited technical context such as stack traces and device metadata.
2.3 Voice recordings and transcripts (specifics)
Voice recordings are transient on our servers and never leave our infrastructure. When you complete a rep on the web, the audio is processed by a self-hosted transcription service (based on the open-source `whisper.cpp` project) running inside our production environment for the sole purpose of producing a text transcript. On the Sayable iOS app, transcription runs entirely on your device using an on-device model — the audio never leaves your device at all. In neither case is the audio sent to any third party, and it is not persisted in our production databases after transcription completes.
The resulting transcript is persisted in your account so you can review it, score it, and compare reps over time. Transcripts are transmitted to Google's Gemini API (paid tier) for scoring; under Google's paid Gemini API terms, Google does not use API inputs or outputs to train or improve its models, and we do not authorize any such use. Scores and derived metrics are stored with the transcript.
3. How We Use Information
We use the information described above to:
- Create and maintain your account and process authentication.
- Provide the core Service: recording reps, transcribing audio, generating scores, and displaying your history.
- Process subscription payments and manage subscription state.
- Send transactional email (password resets, receipts, account notices) via Resend.
- Detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service.
- Debug errors and improve reliability (Sentry).
- Understand how the Service is used and improve it (PostHog).
- Comply with legal obligations and enforce our agreements.
We do not sell your personal information. We do not use your voice recordings, transcripts, or scores to train third-party AI models beyond the transient processing required to produce a transcript and a score for you.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data under the following bases in Article 6 of the GDPR (and the equivalent provisions of the UK GDPR):
| Purpose | Legal basis |
|---|---|
| Creating your account, delivering the Service, processing payments | Performance of a contract (Art. 6(1)(b)) |
| Preventing fraud and abuse; securing the Service | Legitimate interests (Art. 6(1)(f)) |
| Product analytics (PostHog), non-essential error monitoring, marketing | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Complying with tax, accounting, and other legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have carried out an assessment weighing those interests against your rights. You may object to processing under this basis; see Section 8.
5. Third-Party Processors (Sub-processors)
We share personal data with the following processors, each of whom acts on our instructions under a written agreement:
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. | Payment processing (web subscriptions) | Email, billing details, subscription state |
| Apple Inc. | Payment processing and Sign in with Apple (iOS) | Apple identity token, subscription state |
| Resend | Transactional email delivery | Email address, message content |
| Sentry | Error monitoring and crash reporting | Technical error data, limited user identifiers |
| PostHog | Product analytics | Event data, user ID, device metadata |
| Google LLC (Gemini API, paid tier) | LLM-based scoring of transcripts | Transcript text (Google's paid API terms prohibit training use) |
Voice-to-text transcription is performed by a self-hosted `whisper.cpp` service running inside our own infrastructure; no third-party sub-processor receives voice recordings. Session and authentication management is handled by the open-source `better-auth` library running in our own infrastructure; it is not a separate service or sub-processor.
We may update this list from time to time. Material changes will be reflected in an updated version of this policy (see Section 12).
6. Data Retention
- Account and profile data: retained for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations.
- Reps (transcripts, scores, metadata): retained for the life of your account so you can review your progress over time, and deleted when the account is deleted (Section 8). You can also delete individual reps at any time from within the Service.
- Voice recordings: not persisted in our production databases after transcription. Transient processing logs may exist for a short period for debugging and are automatically expired.
- Payment records: retained by Stripe and Apple according to their own retention practices and applicable financial-recordkeeping law. On our side, we retain minimal billing records for the period required by tax law.
- Support communications: retained for as long as reasonably necessary to resolve your matter and to reference prior interactions.
7. International Data Transfers
Sayable is operated from the United States. If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction outside the United States, your personal data will be transferred to and processed in the United States and other countries where our processors operate.
Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) to provide an appropriate safeguard for such transfers, using the SCCs our processors make available in their data-processing terms. If you would like a copy of the safeguards applicable to a specific transfer, contact us at support@sayable.work.
8. Your Rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Right to access. You can ask us for a copy of the personal data we hold about you.
- Right to correction. You can ask us to correct inaccurate or incomplete data.
- Right to deletion. You can ask us to delete your account and associated personal data. Some records may be retained where we have a legal obligation to keep them.
- Right to portability. You can ask us to provide your data in a machine-readable format so you can move it elsewhere.
- Right to object. You can object to processing based on legitimate interests.
- Right to withdraw consent. Where we rely on your consent (e.g., for analytics), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint. You can lodge a complaint with a supervisory authority in your country of residence or place of work.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you the right to know what personal information we collect, use, and disclose about you; the right to delete it; the right to correct inaccurate information; the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights.
12-month lookback disclosure. In the preceding 12 months we have collected the following categories of personal information from California residents: Identifiers (email, user ID, IP address); Commercial Information (subscription and billing records); Internet/Network Activity (log-in state, session identifiers, device and app metadata); Audio Data (voice recordings, processed transiently and not persisted); and User Content (transcripts, scores, and rep metadata). We collect this information from you directly and, in the case of network activity, from your device. We disclose this information to the sub-processors listed in Section 5 for the purposes described there. We have not sold or shared personal information as those terms are defined under CCPA/CPRA in the preceding 12 months, and we do not knowingly sell or share the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes that would trigger the CCPA "Limit the Use of My Sensitive Personal Information" right, so no such link is presented.
How to exercise your rights. Email support@sayable.work with the request and the email address associated with your account. We will respond within 30 days (or the shorter period required by applicable law). We may ask you to verify your identity before acting on the request, using signals available through your account.
You may also delete individual reps and initiate account deletion directly from within the Service.
9. Cookies, Tracking, and Consent
The Service uses a small number of cookies and equivalent technologies:
- Strictly necessary cookies, used for authentication and session management. These are always active because the Service cannot function without them.
- Analytics cookies (PostHog), used to understand product usage.
- Error monitoring identifiers (Sentry), used to attribute errors to sessions for debugging.
Where required by EU or UK law, we present a consent notice on your first visit that allows you to accept or decline non-essential cookies and analytics. Your choices are respected until you change them; you can change them at any time through the in-app privacy settings.
10. Children's Data
The Service is not directed at children under 13 (or under 16 in jurisdictions that treat 16 as the applicable age of digital consent for online services), and we do not knowingly collect personal information from them. Account creation requires that you confirm you are at least 13 years old (or the applicable minimum age in your jurisdiction).
If we become aware that we have collected personal information from a child in violation of this section, we will delete that information and terminate the associated account. If you believe a child has provided us with personal information, contact support@sayable.work.
11. Security
We take reasonable technical and organizational measures to protect personal information, including transport encryption for data in transit, encryption at rest for account data in our production database, hashed passwords for local accounts, and restricted access to production systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) and by posting a notice within the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
For privacy questions, requests, or complaints:
- Email: support@sayable.work
- Legal notices: legal@sayable.work
- Mailing address: TEAHOUSEAI LLC, 2227 Eriksson Ln, Dallas, TX 75204, United States
EU / UK Representative (GDPR Article 27 / UK GDPR Article 27)
For data subjects and supervisory authorities in the European Union or the United Kingdom, TEAHOUSEAI LLC has appointed the following representative to act as its point of contact under GDPR Article 27 and UK GDPR Article 27:
- EU representative: [TO BE APPOINTED BEFORE EU LAUNCH — see the Go-Live tracker for status]
- UK representative: [TO BE APPOINTED BEFORE UK LAUNCH — see the Go-Live tracker for status]
You may contact the representative directly for any matter relating to the processing of your personal data or the exercise of your rights under the GDPR / UK GDPR.