Privacy policy
Last updated: 15 September 2026
Controller
Leon Kraus
Zur Schockenkammer 1
31535 Neustadt
Germany
Email: [email protected]
The principle: most of it never leaves your phone
Bravy needs no account and no sign-up. Your journal — people, events, timeline, commitments, plans, debriefs and your practice history — lives in a database on your device. We neither read it nor store it. You can additionally lock the app behind Face ID or a passcode. Your contacts are never imported.
When data does leave the device, it carries no real names. Every person you add has a generated stand-in name, and only that stand-in appears in requests to us or to anyone else. This is enforced rather than promised: the function that assembles a request has no field for a display name.
What is transmitted when you practise
When you start a practice session, we receive which scenario you are practising and — only if you have explicitly confirmed a personalised session — the journal excerpts you selected, carrying stand-in names. During the conversation your voice is streamed to ElevenLabs, which transcribes it and runs the language model that speaks the other side. Afterwards the transcript and the conversation events sit briefly on our server, and the transcript is sent to OpenAI: that is where the feedback you read in the debrief is written.
We keep no permanent recording of your voice.
How long we keep things
Transcript and conversation events: 24 hours. They are then deleted automatically; a cleanup runs every hour. The debrief you read afterwards lives on your device, not with us.
Practice allowance and subscription status are stored against an anonymous identifier that your device generates and hands to RevenueCat, for as long as the subscription relationship lasts. No name is attached to it.
Abuse counters limit how many requests an identifier or an IP address can make within short time windows.
Legal bases
Running a practice session and handling the subscription rest on Art. 6 (1) (b) GDPR (performance of a contract). Abuse prevention, error diagnostics and anonymous usage measurement rest on Art. 6 (1) (f) GDPR (legitimate interest in a service that works and stays affordable).
Recipients
- ElevenLabs — transcribes your speech and generates the conversational voice (USA)
- OpenAI — analyses the transcript and writes the debrief (USA)
- RevenueCat — handles the subscription (USA)
- Neon — our server's database (USA, Oregon region)
- Apple — distributes the app and processes purchases
No third party is involved in error diagnostics or usage measurement: both run on instances we operate ourselves.
Transfers to the United States
ElevenLabs, OpenAI, RevenueCat and Neon process data in the United States. Transfers rely on the EU-US Data Privacy Framework where the provider in question is certified, and otherwise on the European Commission's standard contractual clauses. Data processing agreements are in place with all of them.
A residual risk remains: under certain conditions, US authorities can access data processed there. That is precisely why your journal does not leave the device, and why what does leave it carries no real names.
Usage measurement
We measure usage with Umami on an instance we run ourselves. No cookies are set and no cross-device profile is built. An event contains identifiers, status values, counters and durations — never conversation content, names or quotes.
Error diagnostics
We collect technical errors with GlitchTip on an instance we run ourselves, in order to find and fix crashes.
What we do not do
We use no advertising identifiers, run no ad tracking, sell no data and do not read your contacts.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Write to [email protected]. You may also lodge a complaint with a data protection supervisory authority.
Independently of all this, the app's settings let you delete every piece of practice data on the device at any time.
Changes
We update this policy when the app changes. The version published here is the one that applies.