PhraseReplayTrust Center

PhraseReplay Trust Center · privacy

Privacy Policy

A plain-language account of what enters PhraseReplay capture, what stays on device, what may be processed in the cloud, and which controls are available to you.

Version: 2.2 Last reviewed: 12 August 2026 Effective date: 13 August 2026

About this policy

This policy explains the PhraseReplay data flows and controls that apply when you use the app, website, and support channel.

01 · orientation

At a glance

This summary highlights the main data flows. The sections below provide the details and controls.

You start capture

ReplayKit Live Capture or a manual screenshot flow begins only after you initiate it in the app.

On-device steps

Sample preparation and Vision OCR may happen on the device before selected session data is uploaded.

AI is feature-specific

Google Gemini receives only the relevant input needed for a selected cloud-assisted language feature.

Retention follows the data type

Transient capture inputs, saved learning outputs, optional excerpts, and account records are handled differently.

Data lifecycle

From capture to deletion control

This sequence separates transient inputs used to produce a result from learning outputs that may remain in your account. “Text only” describes the retained learning output; it does not guarantee that transient audio or sampled frames are unnecessary for processing.

  1. 01CaptureYou deliberately start/stop ReplayKit or a manual capture. App audio and sampled screen/text may enter; microphone is optional.
  2. 02Selective uploadWhen cloud-assisted capture is enabled and consented, selected session inputs are uploaded to PhraseReplay systems.
  3. 03PhraseReplay processingBackend/API/workers process the selected session to create transcripts, Moments, phrases, and learning data.
  4. 04Conditional GeminiRelevant text/audio, and image only where vision fallback is required, may be sent for evidenced language functions.
  5. 05Learning outputTranscripts and Moments may be retained. Plus may retain a short source-audio excerpt tied to a learning Moment when that feature is enabled.
  6. 06Deletion controlsDelete content or the account in-app. Account-owned server records/storage are deleted, subject to legal/security backup limits that are not fixed here.

02 · scope

Scope and roles

This policy covers the PhraseReplay iOS app, its Broadcast Upload Extension, PhraseReplay APIs and processing workers, account and entitlement features, notification features, the support page, and this static website.

Product and privacy contact: PhraseReplay is a Vibe MKR product environment. For privacy questions or requests, contact support@vibemkr.com.

03 · inventory

Data inventory

The categories below describe the data used to provide PhraseReplay capture, learning, account, notification, subscription, support, and website features.

CategoryExamples and sourcePurposeFact status
Account and identityGuest account ID; Sign in with Apple/Google subject identifiers and tokens when linkedAccount access, sync, entitlement associationVerify deployed fields and token deletion
Capture contentSampled screen frames, app audio, optional microphone audio, manual screenshots, OCR textTranscripts, phrases, translations, Moments, Replay/Path learningUsed to provide capture and learning features
Derived learning dataTranscripts, titles, translations, glosses, excerpts, Memory/Library/Path progressProvide and sync learning featuresDelete saved content or account using available controls
Device and operationsApp/device metadata, push token, source-app label, request/job diagnosticsReliability, notifications, security, supportUsed for reliability, notifications, security, and support
PurchasesStoreKit product and transaction/entitlement metadataUnlock Plus and restore statusApple handles payment details; confirm server records
SupportOptional name, category, subject, and message prepared in your email appSend a one-way support request to support@vibemkr.comNo form body is stored by this site.
Website technical dataStandard request data needed to deliver a static pageServe pages and maintain securityNo analytics, trackers, remote fonts, or embeds in this Trust Center

Data by feature: required, optional, and retained

The matrix below shows common inputs and outputs for each PhraseReplay feature.

FeatureRequired inputOptional inputOutput that may be retainedUser control / dependency
Live CaptureUser-started Broadcast session and selected capture settingsApp audio; sampled screen frames/text; microphone only when enabledSession state, transcript, Moments, phrases, and learning dataStart/stop in iOS controls; review the cloud-processing choice shown by the app
Manual screenshot / text captureUser-triggered screenshot or text inputRelevant image/text context needed by the selected featureOCR/transcript and saved learning items when you keep themUser triggers each capture; no promise of complete on-device substitute
Replay / practiceSaved phrase, Moment, or transcript selected for practicePractice voice or short source-audio excerpt where the feature offers itPractice progress; Plus may retain a short source-audio excerpt tied to a MomentDelete saved content or account using the controls available in the app
Account and syncGuest account or selected Apple/Google identity flowNotifications and linked sign-in providerAccount, preferences, entitlement, push-token and learning stateLinking, notification permission, and in-app deletion controls

04 · capture

Capture and device processing

PhraseReplay is designed around user-initiated capture. Live Capture uses Apple ReplayKit Broadcast flow and a system confirmation. Manual screenshot or Action Button flows require an action by you. PhraseReplay does not intentionally record the screen in the background outside an active session you started.

Based on the selected capture mode, the capture path may include sampled frames, app audio, optional microphone audio, manual screenshots, and on-device OCR text. Microphone capture is intended to be off unless you enable it. iOS system indicators and permissions remain part of the capture experience.

Capture carefully

Anything visible or audible in an active capture can enter the capture path, including passwords, one-time codes, messages, work documents, photos, and other people’s voices or faces. Stop capture before opening sensitive screens. Only capture content you are allowed to process.

05 · AI processing

Cloud and third-party AI

Google Gemini is a separate server-side language-processing flow from Google Sign-In. When a selected PhraseReplay language feature uses Gemini, it can receive relevant text, audio, or image content only where that feature needs it, plus necessary request information. Purposes include speech recognition, visual-text extraction, translation and glosses, explanations, coaching-related text, and related language-learning generation.

This is not a general upload of your entire device, an unrelated screen, or every capture category for every request. The relevant input depends on the server function that is invoked and the capture/settings path that produced it.

Cloud-processing choice

Cloud-assisted capture may use Google Gemini for relevant language functions. Review the cloud-processing choice shown by the app before starting a cloud-assisted capture. If you decline a cloud-assisted option, that feature may not start or complete; PhraseReplay does not promise a full on-device substitute.

Google Gemini is separate from Google Sign-In. It receives only the relevant text, audio, or image input needed for the selected language function, plus necessary request information. It does not receive your entire device or unrelated content.

06 · disclosures

Service providers used to deliver PhraseReplay

PhraseReplay transmits data to a service or to PhraseReplay backend systems when that transmission is needed to perform a PhraseReplay function you request or enable. That functional transmission is different from a disclosure or sale for advertising, behavioral profiling, or a recipient’s unrelated independent purpose.

Plain-language boundary

PhraseReplay does not send your entire device or unrelated content to these services. A service receives only the categories needed for the relevant feature, subject to the controls and limitations described below.

DataRecipient/serviceTriggerPurposeControl / retention status
Authentication data, tokens, and provider identifiersApple Sign in with AppleOnly when you select Sign in with Apple or link that identityAuthenticate or link a PhraseReplay accountProvider selection is user-initiated.
Product, transaction, and entitlement metadataApple StoreKit / App Store; PhraseReplay entitlement pathWhen you purchase, restore, or the app verifies Plus accessProcess the purchase through Apple and determine in-app entitlementApple handles payment details.
APNs device token and notification payloadApple Push Notification service; PhraseReplay notification pathWhen notifications are enabled and a notification is registered or sentDeliver an enabled notification, such as a session-ready updateYou control notification permission in iOS.
Relevant authentication data, token, and identifierGoogle Sign-InOnly when you select Google Sign-In or account linkingAuthenticate or link a PhraseReplay accountThis is separate from Gemini language processing.
Relevant feature input: text, audio, and image only where vision fallback is required; necessary request metadataGoogle Gemini APIWhen a selected server-side language function invokes GeminiSpeech recognition, translation/glosses, explanations, coaching-related text, and related language-learning generationUse the cloud-processing choice shown by the app for the relevant feature.
Selected capture payloads and derived learning dataPhraseReplay backend/API/database/workers/object storageWhen you start/stop a session and the app uploads selected payloads, or when a learning item is created/syncedReceive, process, store, and return Sessions, Moments, transcripts, excerpts, Memory/Library/Path data, and related service stateDelete saved content or account using the controls available in the app.
Optional name, category, subject, and messageYour configured email app addressed to support@vibemkr.comWhen you submit the support form and choose Send in your email appOne-way support intakeThis website does not store or forward the form body.
Page request and security-related delivery metadataVibe MKR-controlled static Trust Center deploymentWhen you request a Trust Center pageDeliver the static page and apply security headersThese pages contain no advertising SDK, cross-app tracking integration, analytics pixel, session replay, remote font, or third-party embed.

iOS capture controls are not a content recipient

ReplayKit and iOS system-permission UI control capture locally on the device. Their presence is not evidence that captured frames or audio are sent to Apple, so this table does not list ReplayKit or device permissions as recipients of capture content.

Advertising: PhraseReplay does not send capture content to ad networks. These Trust Center pages have no advertising SDK, cross-app tracking integration, analytics pixel, or session-replay code.

07 · lifecycle

Retention and deletion

Data is kept for the feature and account purposes described here. Some records may remain for legal, accounting, security, backup, dispute, or service-provider purposes.

Data pathHow it is usedYour controls
Raw chunks and framesUsed as capture inputs for processing and handled separately from saved learning outputs.Capture and account controls apply.
Retained transcripts, Moments, and learning libraryKept as account learning output when you save/use the feature.Delete saved content or account using the controls available in the app.
Optional short source-audio excerptsPlus may retain a short excerpt tied to a learning Moment when that feature is enabled.Feature settings and content/account deletion controls apply.
Account-owned records and storageThe app provides in-app account deletion that removes account-owned server records and storage.Limited legal, security, and backup handling may apply.
Operational logs and backupsMay be created for service reliability, security, legal, or recovery purposes.Access is limited to those operational purposes.
Support requestsPrepared in the user’s email app and sent to support@vibemkr.com only when the user chooses Send.This website does not store or forward the form body.

Deleting the app or account does not automatically cancel an Apple subscription. Manage or cancel billing in Apple subscription settings.

08 · safeguards

Security safeguards

The Trust Center is served without remote fonts, analytics, pixels, session replay, or embedded feeds and uses restrictive browser security headers. PhraseReplay’s app/backend uses authenticated service flows and server-side validation. We do not claim a certification or guarantee that any system is risk-free.

09 · choices

Your controls

  • Start and stop capture yourself, choose capture intent, and keep microphone access off unless needed.
  • Use the cloud-processing choice shown by the app before a cloud-assisted feature begins.
  • Delete individual Sessions/Moments where the app provides that control, or request account deletion.
  • Manage notification permissions in iOS Settings and manage, restore, or cancel Apple subscriptions in Apple’s subscription settings.
  • Contact Support for access, correction, deletion, objection, or other privacy requests. Send only the minimum information needed to locate your request.

10 · regional information

Regional rights, children, and transfers

Local law may provide rights to access, correct, delete, restrict, object, port, appeal, or complain to a regulator. Contact Support to ask about a privacy request.

11 · contact

Security, changes, and contact

Report a security concern or privacy request through PhraseReplay Support or email support@vibemkr.com. Do not include passwords, one-time codes, payment-card data, government IDs, or private captured media unless we specifically request a safe redacted artifact.

We may update this policy when the Service, providers, or legal requirements change. We will update the version and dates and provide additional notice for material changes where required.

Version history

2.2 · 13 August 2026: added the data lifecycle sequence, required/optional feature matrix, transient-versus-retained wording, optional Plus audio-excerpt disclosure, account deletion scope, security safeguards, and one-way support email intake.
2.1 · 12 August 2026: clarified AI and service-provider data flows; separated Apple authentication, StoreKit, and APNs flows from local ReplayKit/system permission controls; added the five-column data-flow table and support/advertising limits.
2.0 · 12 August 2026: added capture data, AI processing, provider roles, retention, deletion, support, subscriptions, and regional information.
1.0 · 30 July 2026: prior repository policy; superseded.

Questions or corrections?

Send a privacy question or fact correction through Privacy & data request.