Privacy Policy
This app is a practice space for difficult conversations. Almost everything you write stays on your own device. This page explains the few things that do leave it, and why.
What stays on your device
Your drafts, role-play transcripts, saved scenarios, settings, and progress are held in your browser's local storage on the device you used them on. They are never uploaded to us and we cannot read them. Clearing the app's data, or using the reset control in Settings, removes them permanently.
What we collect
| Data | When | Why |
|---|---|---|
| Email address | Only if you create an optional account | To attach an AI credit balance to a person, and to sign you in |
| Google or Apple user identifier | Only if you sign in with those providers | To recognise you on return |
| AI usage ledger — token counts, model name, cost, timestamp | Each AI call paid for with credits | To keep your balance accurate. No prompt or reply text is stored in the ledger. |
| Guest try counters — device id, hashed IP, UTC-day totals | Included try, without an account | To cap complimentary AI spend. Hashed IP is not stored raw. Prompt text is not stored in these rows. |
| Langfuse summary traces — feature, payer, tokens, cost | Credits and guest try, when observability is on | To measure cost. No prompt or reply text is sent to Langfuse. |
| Purchase records | If you buy credits | To credit your balance and support refunds |
| Anonymous product events (visit, sign-up, feature used, out of credits) | While using the app | To see which parts of the app help. Tied to a random identifier, not to your message content |
| Crash reports | Only after you switch on "Share anonymous crash reports" in Settings | To fix bugs |
What we never collect
We do not collect or store the content of your practice conversations, contacts, location, photos, or advertising identifiers. The app shows no advertising and we do not sell or share personal data with third parties for advertising or any other purpose.
How AI processing works
There are two modes, and you choose which one you use.
-
Credits. Your message is relayed through our
htttg-chatservice to Anthropic, which generates the reply. It is processed in transit and is not written to any database by us. Anthropic processes it as our sub-processor under their API terms and does not use API content to train their models. - Bring your own key. Your browser calls Anthropic directly with a key you supply. That key is stored only on your device, is never sent to us, and our relay is not involved at all.
Payments
Credits are sold on the website only. Payment is handled by Stripe. Card numbers go to Stripe and are never seen or stored by this app. Stripe's handling of your payment data is covered by Stripe's privacy policy.
Who we share data with
Only the service providers needed to run the app: Supabase (accounts, credit balances, and guest try counters), Anthropic (AI generation, credits and guest try), Langfuse (summary traces, no prompts), Stripe (payments), Amazon Web Services (website hosting), and Sentry (crash reports, opt-in only). Each processes data on our instructions. We disclose data otherwise only when the law requires it.
Where data is held and for how long
Account and ledger records are held on Supabase infrastructure and kept while your account exists. Anonymous product events are retained for up to 24 months. Crash reports are retained for up to 90 days. Deleting your account removes your account record and credit balance.
Your choices
- You can use the app without an account, in bring-your-own-key mode.
- Crash reporting is off until you turn it on.
- You can delete this device's guest try record and practice drafts from Settings at any time. Your Anthropic key and language stay unless you clear them yourself.
- You can ask for a copy of your data, a correction, or deletion by emailing us.
Deleting your account
You do not need to email us. Open Settings:
- Delete my data on this device is always visible. It removes this device's guest try record and practice drafts stored here. Your API key and language stay. No sign-in required.
- If you created an optional account, sign in, then tap Delete account. That permanently removes this app's account data and credit ledger and signs you out. Unused credits for this app are forfeited.
If the in-app path fails, email kensaurus@gmail.com from the address you signed up with. More detail is on support.
Children
This app is for adults. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has created an account, email us and we will remove it.
Security
All traffic uses HTTPS. Account data sits behind row-level security so one account cannot read another's records. No system is perfect, and we will notify affected users if a breach ever puts their data at risk.
Changes
If this policy changes materially we will update the date at the top and note the change in the app. Continued use after a change means you accept the updated policy.
Contact
kensaurus合同会社 (kensaurus LLC), Japan — kensaurus@gmail.com