Privacy Policy
Last updated: April 3, 2026
Spoke ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use the Spoke mobile application ("App"). By using the App, you agree to the practices described in this policy.
1. Information We Collect
1.1 Voice & Audio Data
- On-device speech recognition is performed using Apple's Speech Recognition framework. Audio is processed locally on your device and is not transmitted to our servers during normal use.
- Temporary audio recordings are created during voice input sessions. These recordings are stored temporarily on your device and are automatically deleted immediately after transcription. We do not retain audio files.
- In rare fallback scenarios (e.g., when on-device recognition is unavailable), audio data may be sent to our secure Cloud Function, which processes it via the OpenAI Whisper API for transcription. The audio is not stored after processing.
1.2 Text Content
- Input text (transcribed from voice or pasted manually) is sent to our secure Cloud Function for AI-powered rewriting via Anthropic's Claude API.
- Generated text (the AI-rewritten output) is returned to your device.
- Both input and output text are stored in Firebase Firestore under your user account for history purposes. This data is accessible only to you.
- We also store metadata associated with each rewrite: the preset used, input method, tone modifier, AI model used, processing latency, and timestamp.
1.3 Account Information
- We use Firebase Anonymous Authentication by default. A unique user ID (UID) is generated automatically. No personal information (name, email, phone number) is required to use the App.
- If you choose to Sign in with Apple, we receive only the information Apple shares based on your preferences (which may include a private relay email address). This is used solely for account management, data preservation, and linking your anonymous account to a persistent identity.
1.4 Identifiers
- Firebase User ID (UID): A pseudonymous identifier generated at first launch. Used for authentication, data isolation, rate limiting, and analytics.
- We do not collect the Apple Advertising Identifier (IDFA), device IDs, MAC addresses, or any hardware identifiers.
1.5 Usage & Analytics Data
- We collect product interaction events through Mixpanel and Google Analytics (via Firebase). These include: app opens, onboarding completion, feature usage (preset selection, voice recording, text pasting, rewrite requests), result interactions (copy, share), paywall views, subscription events, referral actions, and error occurrences.
- Analytics events include metadata such as: preset type, input method, word counts, processing latency, error types, and subscription plan. Full text content is never sent to analytics services.
- Analytics data is linked to your Firebase UID (a pseudonymous identifier).
- We track daily request counts for the purpose of enforcing free-tier usage limits (3 requests per day).
1.6 Diagnostic Data
- We collect performance and diagnostic data including: API response latency, HTTP error codes, error types from failed rewrite requests, and Cloud Function response statuses.
- This data is used to monitor service health, debug issues, and improve reliability.
1.7 Purchase & Subscription Data
- Subscription purchases are processed through Apple's StoreKit. We do not collect or store your payment information (credit card, billing address, etc.).
- We store your subscription plan status (Free or Pro) in Firebase Firestore to determine feature access.
- Subscription events (plan type, trial status) are sent to Mixpanel and Google Analytics for product analytics.
- Superwall manages paywall presentation and receives subscription status information.
1.8 Clipboard Access
- The App may read your device clipboard when you use the "Paste text" feature or when entering a referral code. Clipboard data is used only for the intended action and is not stored or transmitted for any other purpose.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Core functionality: Convert voice input to text and rewrite it using AI (Anthropic Claude)
- Authentication: Identify your account and isolate your data
- Rate limiting: Enforce free-tier daily usage limits
- History: Store your rewrite history for later access
- Product analytics: Understand feature usage and improve the App experience
- Marketing analytics: Measure acquisition channels and campaign performance
- Diagnostics: Monitor errors, performance, and service reliability
- Subscription management: Determine feature access based on your plan
- Referral program: Track and reward referral invitations
- Customer support: Assist with issues and requests
3. Third-Party Services
We use the following third-party services that may process your data:
3.1 Firebase (Google)
- Services: Authentication, Firestore Database, Cloud Functions, Analytics
- Data processed: User ID, account metadata, rewrite history, request counts, analytics events
- Privacy policy: policies.google.com/privacy
3.2 Anthropic (Claude AI)
- Services: Text rewriting and generation (Claude Sonnet)
- Data processed: Your input text and selected preset/tone (sent via our Cloud Function; your user ID is not shared with Anthropic)
- Privacy policy: anthropic.com/privacy
3.3 OpenAI (Whisper)
- Services: Speech-to-text transcription (fallback only, when on-device recognition is unavailable)
- Data processed: Audio recording (temporarily, for transcription only)
- Privacy policy: openai.com/privacy
3.4 Mixpanel
- Services: Product analytics
- Data processed: Firebase UID (pseudonymous), interaction events, user properties (plan, total rewrites, anonymous status)
- Privacy policy: mixpanel.com/legal/privacy-policy
3.5 Google Analytics
- Services: Marketing and acquisition analytics (via Firebase)
- Data processed: Firebase UID, interaction events, app version, OS version, device model
- Privacy policy: policies.google.com/privacy
3.6 Superwall
- Services: Paywall configuration and subscription management
- Data processed: Subscription status, paywall presentation events
- Privacy policy: superwall.com/privacy
3.7 Apple
- Services: On-device Speech Recognition, Sign in with Apple, StoreKit (In-App Purchases)
- Data processed: Voice (on-device only), Apple ID credentials (if opted in), purchase transactions
- Privacy policy: apple.com/privacy
4. Data Storage & Security
- All server-side data is stored on Google Cloud infrastructure (Firebase) with encryption at rest and in transit (TLS 1.2+).
- API keys and sensitive credentials are stored securely on our Cloud Functions and are never included in the App binary.
- We implement Firebase Security Rules to ensure users can only read and write their own data (
request.auth.uid == userId). - Audio recordings are stored temporarily on your device in a sandboxed directory and deleted immediately after transcription.
- All communication between the App and our servers uses HTTPS encryption.
5. Data Retention
- Audio recordings: Deleted immediately after transcription (not retained).
- Rewrite history: Retained in Firestore until you delete it or request account deletion.
- User account data: Retained until you delete your account.
- Daily request counters: Reset automatically at UTC midnight each day.
- Analytics data (Mixpanel): Retained per Mixpanel's data retention policy (default up to 5 years).
- Analytics data (Google Analytics): Retained per Google's data retention settings.
- Device preferences: Stored locally in UserDefaults; cleared upon app uninstallation.
6. Data Sharing
- We do not sell your personal data to any third party.
- We do not share your data with advertising networks.
- We share data with third-party service providers (listed in Section 3) only as necessary to provide the App's functionality and as described in this policy.
- We may disclose your information if required by law, legal process, or government request.
7. Tracking & Advertising
- Spoke does not display any advertisements.
- We do not collect the Apple Advertising Identifier (IDFA). Advertising support is explicitly disabled in the App.
- We use Mixpanel and Google Analytics for product and marketing analytics. These services use your pseudonymous Firebase UID (not personal information) to track usage patterns.
- We do not engage in cross-app tracking or share data with data brokers.
8. Your Rights
Depending on your jurisdiction (including under GDPR, CCPA, and similar regulations), you have the right to:
- Access your personal data stored by us
- Delete your account and all associated data (history, user profile, request counts)
- Rectify inaccurate personal data
- Port your data — export your rewrite history upon request
- Opt out of analytics tracking by contacting us
- Restrict processing of your personal data in certain circumstances
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at support@hiaira.ai. We will respond to your request within 30 days.
9. Children's Privacy
The App is not directed at children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly.
10. International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate (Google, Anthropic, Mixpanel, OpenAI). By using the App, you consent to the transfer of your data to these jurisdictions. We ensure that appropriate safeguards are in place to protect your data in accordance with applicable laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy within the App and updating the "Last updated" date. Your continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: support@hiaira.ai