Yapr
← Back to Yapr

Legal

Privacy Policy

What Yapr collects, what never leaves your phone, and the controls you keep over your voice.

Effective[DATE]
Last updated16 July 2026 · draft v3.2
Controller[LEGAL ENTITY NAME]

Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("Yapr," "we," "us")

Version history: v3.2 — 16 Jul 2026 (new product surfaces, retention defaults filled, Cloudflare + Resend processors) · v3.1 — 12 Jul 2026 · v2 — 8 Jul 2026 · v1 — 21 May 2026.

1. The short version

Yapr translates conversations in real time and can speak the translation in a clone of your voice. Your voice is one of the most personal things you have, so our position is simple:

You own your voice. Yapr borrows it only as long as you say.

This summary is for convenience; the full policy below governs.

2. Who this applies to & age

Yapr is for adults and is not directed to children. Because creating a voice clone processes biometric data, you must be at least 18 years old to use Yapr, and we ask your age before collecting any personal data. We do not knowingly collect data from anyone under 18; if you believe a minor has provided us data, contact privacy@yap-r.com and we will delete it.

3. The two privacy modes (read this first)

Yapr has a single, always-visible privacy toggle that determines whether a conversation touches the cloud at all.

Standard mode (default)

Best translation and voice quality. Speech recognition, translation, and voice synthesis run through trusted third-party processors (see §6). We are explicit about what is and isn't retained (§5).

Strict mode

True zero-retention. Speech recognition, translation, and playback all run on your device. Our servers and third-party processors are not contacted for the conversation, so there is nothing for us — or anyone — to store. Quality is lower; we state that plainly in the app. Strict mode also powers offline Emergency phrases.

4. Information we collect

You provide:

Collected automatically (Standard mode):

Stays on your device (we never receive it):

We do NOT collect: precise location, your contacts, your photos, or advertising identifiers.

5. What we store, and what we never store

We never store (in either mode):

We store (Standard mode only — Strict mode stores nothing server-side):

Voice enrollment samples are used only to create your clone and are deleted immediately after the creation attempt completes — whether it succeeds or fails. The consent audio is verified and then deleted in the same step; what we keep is a consent record (the notice version you saw, a transcript, and a timestamp — not the audio), retained for the life of your account as proof of consent. Full detail: our public Biometric Data Retention & Destruction Schedule.

6. Third-party processors (Standard mode)

In Standard mode we share the minimum necessary with processors who act on our instructions under data-processing agreements. We require Data Processing Agreements (DPAs) with each before launch.

ProcessorPurposeData shared
ElevenLabs (US)Voice cloning; and in cloned-voice conversations: speech-to-text, translation orchestration, and text-to-speech in your voice (one connection)Enrollment samples (transient), conversation audio (transient), your voice ID
OpenAI (US)Speech-to-text + translation (Speed/system-voice and Rooms paths; also the translation step inside cloned-voice conversations); Learn course generation and the Roleplay practice character (speech-to-text + AI replies)Conversation audio / text (transient, processed not stored by us); Learn goal/progress text and Roleplay speech (transient); no-train by default on the API
Anthropic (Claude) (US)Translation (fallback provider when OpenAI is unavailable)Text to translate (transient)
SupabaseAuthentication, database, file storage, backend functions (hosting/infra); ephemeral Rooms session signalingAccount + metadata above
Cloudflare, Inc. (US)Network relay (TURN) for cross-network Rooms calls — relays end-to-end DTLS-SRTP-encrypted call media it cannot read, and processes IP/connection metadataIP / connection metadata; encrypted call media (unreadable to Cloudflare)
Google Sign-InAuthentication (if you choose it)Per Google's authentication flow
Resend (if email-code sign-in is enabled)Sign-in email delivery (one-time codes) — active only if email-code sign-in is enabledEmail address + sign-in codes
RevenueCat (if adopted)Purchase/subscription managementPurchase tokens + entitlements (no conversation data)
Sentry (if adopted, with your consent)Crash diagnosticsPII-scrubbed crash reports

In Rooms (two-phone translation), call media travels directly peer-to-peer between the two paired devices. When a direct connection isn't possible across networks, the media is relayed through Cloudflare's TURN service, which passes the end-to-end-encrypted media through without being able to read it and sees only IP/connection metadata; Supabase carries only the brief session-setup (signaling) messages.

Each processor retains data per its own terms; we use no-training / no-retention settings where the provider offers them. In Strict mode none of these are contacted. We do not claim Zero-Retention Mode for Standard-mode providers unless and until we hold the contracts that permit it. The current processor list, locations, and transfer mechanism for each are kept in our public sub-processor register.

7. How we use your information

We do not use your voice, recordings, or conversations to train our own or third parties' AI models, and we do not sell or share your personal information for advertising.

8. Legal bases (EU/UK GDPR)

9. Your rights & choices

Depending on where you live (EU/UK GDPR, California CCPA/CPRA, Illinois BIPA, and others) you may have the right to: access, correct, delete, port/export, restrict or object to processing, and withdraw consent. Yapr provides:

To exercise rights, use the in-app controls or email privacy@yap-r.com. We do not sell personal information; this also serves as our "Do Not Sell or Share" statement for CCPA/CPRA. We do not use sensitive personal information beyond the purposes permitted by CPRA §1798.121, so no separate "Limit the Use of My Sensitive Personal Information" link is required. [Counsel confirm.]

EU/UK: you also have the right to lodge a complaint with your supervisory authority (your local DPA, or the UK ICO). Our lead authority is [TBD once EU representative / establishment is set].

Illinois (BIPA) note: your voiceprint is a biometric identifier. We collect it only with your informed written/explicit consent (a dedicated in-app release, captured before any recording), use it solely to provide the voice feature, never sell, lease, trade, or profit from it, and destroy it per our public Biometric Data Retention & Destruction Schedule. [A lawyer must confirm BIPA-specific consent wording, retention schedule, and disclosures.]

Texas (CUBI) & Washington (My Health My Data): in Texas we collect a voiceprint only with notice and consent, don't sell it, and destroy it on our schedule. Washington's My Health My Data Act defines "consumer health data" broadly; to the extent it treats a voiceprint as in scope, we rely on your consent and provide access/deletion via the same channels. [Counsel to confirm whether a voiceprint is "consumer health data" under Washington MHMD and whether a separate MHMD notice/consent is required.]

Canada (PIPEDA / Quebec Law 25): we rely on express consent for biometric data; Quebec residents' rights (access, rectification, de-indexing, portability) can be exercised via the same channels. [Quebec availability follows the CAI biometric-database filing.]

Brazil (LGPD): where available in Brazil, you have the LGPD rights (confirmation, access, correction, anonymization, portability, deletion, revocation of consent) via the same channels; our legal basis for the voiceprint is consent (Art. 11(I)).

Other jurisdictions (Australia, New Zealand, Japan, Korea, Mexico, and others where Yapr is offered): we honor access, correction, and deletion requests through the same in-app controls and email, regardless of where you live.

10. Security

No system is perfectly secure; we cannot guarantee absolute security.

11. AI-generated content disclosure (EU AI Act Art. 50)

Yapr's translated speech is AI-generated audio — including, if you opt in, audio generated in a clone of your own voice. To keep synthetic speech honest:

12. International transfers

Yapr's processors operate primarily in the United States; using Yapr from outside the US means your data (including, if you opt in, your biometric voiceprint) is transferred there. For transfers from the EU/EEA, UK, and Switzerland we rely on, in order of preference:

  1. the EU–US Data Privacy Framework (and its UK Extension / Swiss counterpart) for processors holding an active DPF certification — our voice provider ElevenLabs is DPF-certified [reverify "Active" at signing];
  2. Standard Contractual Clauses (SCCs) plus a documented Transfer Impact Assessment for processors without DPF certification;
  3. [If Supabase is moved to an EEA region, account/metadata storage ceases to be a transfer at all — decision pending.]

The current processor list, locations, and transfer mechanism for each are kept in our sub-processor register. [Counsel: confirm mechanisms per processor at DPA signing; keep the register and this section in sync.]

13. Data retention

14. Health-data & HIPAA

Yapr is not a HIPAA-covered entity and does not claim HIPAA compliance. For privacy-sensitive conversations we offer Strict mode, where nothing leaves your device. Do not rely on Standard mode for protected health information.

15. Changes

We'll update this policy as the product evolves and post the new effective date. Material changes will be notified in-app or by email.

16. Contact & representatives

Privacy questions: privacy@yap-r.com
Security reports: security@yap-r.com

Controller: [LEGAL ENTITY + REGISTERED ADDRESS]

EU representative (GDPR Art. 27): [NAME + ADDRESS — appoint before EU availability]

UK representative (UK GDPR Art. 27): [NAME + ADDRESS — appoint before UK availability]

Data Protection Officer: [NAME/CONTACT if appointed — likely required; counsel to assess]

See also our Terms of Service, Biometric Data Schedule, Sub-processors, Accessibility statement, and how to delete your account.