Privacy

Privacy policy

A plain-language account of what Before You Say It keeps, what it sends, and what it does not do. This page matches the current product — not a wish list.

Last updated: 12 September 2026

  1. 1. Who we are
  2. 2. What we collect
  3. 3. How we use it
  4. 4. Voice and AI processors
  5. 5. Sharing
  6. 6. Free-session recovery
  7. 7. What stays on your device
  8. 8. Your rights and deletion
  9. 9. Follow-Through
  10. 10. Children
  11. 11. Security, retention, and location
  12. 12. Changes
  13. 13. Contact
  14. Appendix. Named processors

1. Who we are

Before You Say It is a communication-practice product. Adults rehearse a hard conversation. It is practice, not therapy, and not a crisis service. If you or someone else is in danger, contact real-world support — in the US, call or text 988, or call 911 in an emergency.

The operator is Utoa LLC. The public site is https://beforeyousayit.app. Write to us at support@beforeyousayit.app. We do not publish a street address on this page.

2. What we collect

You give us some information directly:

  • Account email and password, through Supabase Auth on the same Auth project the live site uses.
  • Practice you type or approve as text (what you said, counterpart lines, coaching, and results) so a rehearsal can continue.
  • Custom scenario text only if you turn that setting on. It is off by default.
  • Purchase records needed to recognize access. Conversation content is not sent to billing.

Some information is created automatically when you use the product:

  • Hosting and request logs on Vercel, as needed to run the site.
  • Account and product records in Supabase (database and Auth).

This build has no analytics sink. We do not use Mixpanel, Meta Pixel, Google Analytics, or AppsFlyer.

Reminders, when you set them, are scheduled locally on your device. We do not collect a push token for them.

Safety answers are never stored and never sent. They exist only while the safety screen is open.

3. How we use it

We use this information to:

  • Create and sign you into an account.
  • Run practice: transcribe speech, generate a counterpart, write a debrief, and speak the other person’s lines.
  • Recognize a purchase and restore a recognized original Follow-Through to the signed-in owner.
  • Recover an interrupted free session for up to 24 hours, as described below.
  • Respond when you email support.

We do not sell personal information.

4. Voice and AI processors

Raw audio is sent once to OpenAI (gpt-4o-mini-transcribe, through the BYSI backend) to be converted to text. The local temporary recording file is then deleted. Before You Say It does not keep a recording library.

What you said, as text, is sent to Anthropic Claude through BYSI generation so the counterpart can answer and so we can write your debrief.

Counterpart speech is generated by ElevenLabs. Your own words are not sent for voice.

5. Sharing

We share personal information with the processors named on this page so they can provide the service we asked for — not to sell it. Web purchases go through Stripe. Native purchases go through RevenueCat with Apple or Google. No conversation content is included in billing.

Hosting is Vercel. Database and Auth are Supabase. We may also share information if the law requires it, or to protect people from harm.

6. Free-session recovery

During a 24-hour server session, BYSI keeps approved conversation text, generated results, and generated speech audio so an interrupted request can be recovered without generating it again. Uploaded recording bytes are processed there, not saved there. Access stops at expiry. A content-free spent-allocation record (account and session IDs and expiry) remains so the same free allocation is not issued twice.

7. What stays on your device

Local practice — session records, approved attempts, progress, and optional custom scenarios — stays in the app’s local storage. It does not automatically sync across devices.

The in-app Privacy screen can delete practice history on that device or reset local app data. That local reset is not account deletion. It does not erase your web account, server-held results, or provider records, and it does not cancel a subscription.

8. Your rights and deletion

You can ask us about the personal information we hold, or ask us to correct or delete it, by emailing support@beforeyousayit.app. An email is a request, not confirmation that the account was erased.

Account identity deletion is not enabled on the server in this build. The in-app Delete account control will say so. Local Privacy reset is not account deletion.

Processing a provider has already completed follows that provider’s own policy. We cannot retroactively delete work OpenAI, Anthropic, ElevenLabs, Stripe, RevenueCat, Apple, Google, Vercel, or Supabase have already finished.

9. Follow-Through

If you already have a recognized original Follow-Through, the signed-in owner can restore that saved output. Restore is not a second checkout. It is not converted into monthly Pro. Ownership is not inferred from an email address.

10. Children

Before You Say It is for adults. It is not directed at children under 13. If we learn we collected personal information from a child under 13 in error, we will delete it.

11. Security, retention, and location

We use ordinary industry measures to protect accounts and product data. No method of transmission or storage is perfect.

Local practice stays until you delete it or reset the app. Free-session recovery content is kept for the 24-hour session described above. Spent-allocation IDs remain after that. Account records stay while the account exists. Provider retention follows each processor’s policy.

Utoa LLC operates this product from the United States. Processors may handle data in other countries where they run their services.

12. Changes

If this policy changes, we will post the updated text on this page and change the date above. The live URL remains https://beforeyousayit.app/privacy.

13. Contact

Utoa LLC
Before You Say It
support@beforeyousayit.app
https://beforeyousayit.app

Appendix. Named processors

  • OpenAI — one-time transcription of raw audio (gpt-4o-mini-transcribe, through the BYSI backend).
  • Anthropic Claude — counterpart replies and debrief, through BYSI generation.
  • ElevenLabs — spoken counterpart lines. Your own words are not sent for voice.
  • Vercel — hosting.
  • Supabase — database and Auth.
  • Stripe — web purchases. No conversation content.
  • RevenueCat, Apple, and Google — native purchases. No conversation content.

Marker bysi-utoa-privacy-12-september-2026. Practice, not therapy. We do not sell personal information.