About this policy
This policy explains the PhraseReplay data flows and controls that apply when you use the app, website, and support channel.
01 · orientation
At a glance
This summary highlights the main data flows. The sections below provide the details and controls.
You start capture
ReplayKit Live Capture or a manual screenshot flow begins only after you initiate it in the app.
On-device steps
Sample preparation and Vision OCR may happen on the device before selected session data is uploaded.
AI is feature-specific
Google Gemini receives only the relevant input needed for a selected cloud-assisted language feature.
Retention follows the data type
Transient capture inputs, saved learning outputs, optional excerpts, and account records are handled differently.
Data lifecycle
From capture to deletion control
This sequence separates transient inputs used to produce a result from learning outputs that may remain in your account. “Text only” describes the retained learning output; it does not guarantee that transient audio or sampled frames are unnecessary for processing.
- 01CaptureYou deliberately start/stop ReplayKit or a manual capture. App audio and sampled screen/text may enter; microphone is optional.
- 02Selective uploadWhen cloud-assisted capture is enabled and consented, selected session inputs are uploaded to PhraseReplay systems.
- 03PhraseReplay processingBackend/API/workers process the selected session to create transcripts, Moments, phrases, and learning data.
- 04Conditional GeminiRelevant text/audio, and image only where vision fallback is required, may be sent for evidenced language functions.
- 05Learning outputTranscripts and Moments may be retained. Plus may retain a short source-audio excerpt tied to a learning Moment when that feature is enabled.
- 06Deletion controlsDelete content or the account in-app. Account-owned server records/storage are deleted, subject to legal/security backup limits that are not fixed here.
02 · scope
Scope and roles
This policy covers the PhraseReplay iOS app, its Broadcast Upload Extension, PhraseReplay APIs and processing workers, account and entitlement features, notification features, the support page, and this static website.
Product and privacy contact: PhraseReplay is a Vibe MKR product environment. For privacy questions or requests, contact support@vibemkr.com.
03 · inventory
Data inventory
The categories below describe the data used to provide PhraseReplay capture, learning, account, notification, subscription, support, and website features.
| Category | Examples and source | Purpose | Fact status |
|---|---|---|---|
| Account and identity | Guest account ID; Sign in with Apple/Google subject identifiers and tokens when linked | Account access, sync, entitlement association | Verify deployed fields and token deletion |
| Capture content | Sampled screen frames, app audio, optional microphone audio, manual screenshots, OCR text | Transcripts, phrases, translations, Moments, Replay/Path learning | Used to provide capture and learning features |
| Derived learning data | Transcripts, titles, translations, glosses, excerpts, Memory/Library/Path progress | Provide and sync learning features | Delete saved content or account using available controls |
| Device and operations | App/device metadata, push token, source-app label, request/job diagnostics | Reliability, notifications, security, support | Used for reliability, notifications, security, and support |
| Purchases | StoreKit product and transaction/entitlement metadata | Unlock Plus and restore status | Apple handles payment details; confirm server records |
| Support | Optional name, category, subject, and message prepared in your email app | Send a one-way support request to support@vibemkr.com | No form body is stored by this site. |
| Website technical data | Standard request data needed to deliver a static page | Serve pages and maintain security | No analytics, trackers, remote fonts, or embeds in this Trust Center |
Data by feature: required, optional, and retained
The matrix below shows common inputs and outputs for each PhraseReplay feature.
| Feature | Required input | Optional input | Output that may be retained | User control / dependency |
|---|---|---|---|---|
| Live Capture | User-started Broadcast session and selected capture settings | App audio; sampled screen frames/text; microphone only when enabled | Session state, transcript, Moments, phrases, and learning data | Start/stop in iOS controls; review the cloud-processing choice shown by the app |
| Manual screenshot / text capture | User-triggered screenshot or text input | Relevant image/text context needed by the selected feature | OCR/transcript and saved learning items when you keep them | User triggers each capture; no promise of complete on-device substitute |
| Replay / practice | Saved phrase, Moment, or transcript selected for practice | Practice voice or short source-audio excerpt where the feature offers it | Practice progress; Plus may retain a short source-audio excerpt tied to a Moment | Delete saved content or account using the controls available in the app |
| Account and sync | Guest account or selected Apple/Google identity flow | Notifications and linked sign-in provider | Account, preferences, entitlement, push-token and learning state | Linking, notification permission, and in-app deletion controls |
04 · capture
Capture and device processing
PhraseReplay is designed around user-initiated capture. Live Capture uses Apple ReplayKit Broadcast flow and a system confirmation. Manual screenshot or Action Button flows require an action by you. PhraseReplay does not intentionally record the screen in the background outside an active session you started.
Based on the selected capture mode, the capture path may include sampled frames, app audio, optional microphone audio, manual screenshots, and on-device OCR text. Microphone capture is intended to be off unless you enable it. iOS system indicators and permissions remain part of the capture experience.
Capture carefully
Anything visible or audible in an active capture can enter the capture path, including passwords, one-time codes, messages, work documents, photos, and other people’s voices or faces. Stop capture before opening sensitive screens. Only capture content you are allowed to process.
05 · AI processing
Cloud and third-party AI
Google Gemini is a separate server-side language-processing flow from Google Sign-In. When a selected PhraseReplay language feature uses Gemini, it can receive relevant text, audio, or image content only where that feature needs it, plus necessary request information. Purposes include speech recognition, visual-text extraction, translation and glosses, explanations, coaching-related text, and related language-learning generation.
This is not a general upload of your entire device, an unrelated screen, or every capture category for every request. The relevant input depends on the server function that is invoked and the capture/settings path that produced it.
Cloud-processing choice
Cloud-assisted capture may use Google Gemini for relevant language functions. Review the cloud-processing choice shown by the app before starting a cloud-assisted capture. If you decline a cloud-assisted option, that feature may not start or complete; PhraseReplay does not promise a full on-device substitute.
Google Gemini is separate from Google Sign-In. It receives only the relevant text, audio, or image input needed for the selected language function, plus necessary request information. It does not receive your entire device or unrelated content.
06 · disclosures
Service providers used to deliver PhraseReplay
PhraseReplay transmits data to a service or to PhraseReplay backend systems when that transmission is needed to perform a PhraseReplay function you request or enable. That functional transmission is different from a disclosure or sale for advertising, behavioral profiling, or a recipient’s unrelated independent purpose.
Plain-language boundary
PhraseReplay does not send your entire device or unrelated content to these services. A service receives only the categories needed for the relevant feature, subject to the controls and limitations described below.
| Data | Recipient/service | Trigger | Purpose | Control / retention status |
|---|---|---|---|---|
| Authentication data, tokens, and provider identifiers | Apple Sign in with Apple | Only when you select Sign in with Apple or link that identity | Authenticate or link a PhraseReplay account | Provider selection is user-initiated. |
| Product, transaction, and entitlement metadata | Apple StoreKit / App Store; PhraseReplay entitlement path | When you purchase, restore, or the app verifies Plus access | Process the purchase through Apple and determine in-app entitlement | Apple handles payment details. |
| APNs device token and notification payload | Apple Push Notification service; PhraseReplay notification path | When notifications are enabled and a notification is registered or sent | Deliver an enabled notification, such as a session-ready update | You control notification permission in iOS. |
| Relevant authentication data, token, and identifier | Google Sign-In | Only when you select Google Sign-In or account linking | Authenticate or link a PhraseReplay account | This is separate from Gemini language processing. |
| Relevant feature input: text, audio, and image only where vision fallback is required; necessary request metadata | Google Gemini API | When a selected server-side language function invokes Gemini | Speech recognition, translation/glosses, explanations, coaching-related text, and related language-learning generation | Use the cloud-processing choice shown by the app for the relevant feature. |
| Selected capture payloads and derived learning data | PhraseReplay backend/API/database/workers/object storage | When you start/stop a session and the app uploads selected payloads, or when a learning item is created/synced | Receive, process, store, and return Sessions, Moments, transcripts, excerpts, Memory/Library/Path data, and related service state | Delete saved content or account using the controls available in the app. |
| Optional name, category, subject, and message | Your configured email app addressed to support@vibemkr.com | When you submit the support form and choose Send in your email app | One-way support intake | This website does not store or forward the form body. |
| Page request and security-related delivery metadata | Vibe MKR-controlled static Trust Center deployment | When you request a Trust Center page | Deliver the static page and apply security headers | These pages contain no advertising SDK, cross-app tracking integration, analytics pixel, session replay, remote font, or third-party embed. |
iOS capture controls are not a content recipient
ReplayKit and iOS system-permission UI control capture locally on the device. Their presence is not evidence that captured frames or audio are sent to Apple, so this table does not list ReplayKit or device permissions as recipients of capture content.
Advertising: PhraseReplay does not send capture content to ad networks. These Trust Center pages have no advertising SDK, cross-app tracking integration, analytics pixel, or session-replay code.
07 · lifecycle
Retention and deletion
Data is kept for the feature and account purposes described here. Some records may remain for legal, accounting, security, backup, dispute, or service-provider purposes.
| Data path | How it is used | Your controls |
|---|---|---|
| Raw chunks and frames | Used as capture inputs for processing and handled separately from saved learning outputs. | Capture and account controls apply. |
| Retained transcripts, Moments, and learning library | Kept as account learning output when you save/use the feature. | Delete saved content or account using the controls available in the app. |
| Optional short source-audio excerpts | Plus may retain a short excerpt tied to a learning Moment when that feature is enabled. | Feature settings and content/account deletion controls apply. |
| Account-owned records and storage | The app provides in-app account deletion that removes account-owned server records and storage. | Limited legal, security, and backup handling may apply. |
| Operational logs and backups | May be created for service reliability, security, legal, or recovery purposes. | Access is limited to those operational purposes. |
| Support requests | Prepared in the user’s email app and sent to support@vibemkr.com only when the user chooses Send. | This website does not store or forward the form body. |
Deleting the app or account does not automatically cancel an Apple subscription. Manage or cancel billing in Apple subscription settings.
08 · safeguards
Security safeguards
The Trust Center is served without remote fonts, analytics, pixels, session replay, or embedded feeds and uses restrictive browser security headers. PhraseReplay’s app/backend uses authenticated service flows and server-side validation. We do not claim a certification or guarantee that any system is risk-free.
09 · choices
Your controls
- Start and stop capture yourself, choose capture intent, and keep microphone access off unless needed.
- Use the cloud-processing choice shown by the app before a cloud-assisted feature begins.
- Delete individual Sessions/Moments where the app provides that control, or request account deletion.
- Manage notification permissions in iOS Settings and manage, restore, or cancel Apple subscriptions in Apple’s subscription settings.
- Contact Support for access, correction, deletion, objection, or other privacy requests. Send only the minimum information needed to locate your request.
10 · regional information
Regional rights, children, and transfers
Local law may provide rights to access, correct, delete, restrict, object, port, appeal, or complain to a regulator. Contact Support to ask about a privacy request.
11 · contact
Security, changes, and contact
Report a security concern or privacy request through PhraseReplay Support or email support@vibemkr.com. Do not include passwords, one-time codes, payment-card data, government IDs, or private captured media unless we specifically request a safe redacted artifact.
We may update this policy when the Service, providers, or legal requirements change. We will update the version and dates and provide additional notice for material changes where required.
Version history
2.2 · 13 August 2026: added the data lifecycle sequence, required/optional feature matrix, transient-versus-retained wording, optional Plus audio-excerpt disclosure, account deletion scope, security safeguards, and one-way support email intake.
2.1 · 12 August 2026: clarified AI and service-provider data flows; separated Apple authentication, StoreKit, and APNs flows from local ReplayKit/system permission controls; added the five-column data-flow table and support/advertising limits.
2.0 · 12 August 2026: added capture data, AI processing, provider roles, retention, deletion, support, subscriptions, and regional information.
1.0 · 30 July 2026: prior repository policy; superseded.
Questions or corrections?
Send a privacy question or fact correction through Privacy & data request.