Debrief

Privacy Policy

Effective date: 28 June 2026  ·  Last updated: 28 June 2026

Debrief ("Debrief", "the app", "we", "us") is a voice-first personal relationship manager for Android, published by The App Joinery. This policy explains exactly what data the app handles, where it lives, what leaves your device and why, and the choices and rights you have.

We wrote this in plain language on purpose. If anything here is unclear, email us at hello@theappjoinery.com.

The short version

1. Who is responsible for your data

The data controller is The App Joinery.
Contact: hello@theappjoinery.com.

2. Data that stays on your device

The core of Debrief is local. The following is stored only on your device, in a database encrypted with AES-256 (SQLCipher) whose key is protected by your device's hardware-backed keystore:

We never receive this database. It is not uploaded anywhere unless you turn on cloud backup (Section 5).

Phone contacts (optional). If you grant the Contacts permission, Debrief can let you link a friend to an existing phone contact for convenience. Contact data read for this purpose stays on your device and is not transmitted to us or anyone else. You can use the app without granting this permission.

3. Data that leaves your device

To turn what you say into a structured profile and to generate suggestions, Debrief sends certain text to a processing service we operate (a Cloudflare Worker), which forwards it to our AI provider, Anthropic (Claude). This happens only when you take an action that needs it:

When What is sent Why
You record or type a debrief The transcript text, plus the names of friends already in your app (to correct mis-heard names) Extract structured facts (birthday, family, interests, etc.)
You log a "moment" (trip, dinner, adventure) The transcript text and the moment type Extract a structured moment summary
You open conversation starters or gift ideas A snapshot of the relevant friend (e.g. name, work, location, family, interests, recent notes) Generate suggestions tailored to that person

What you should know about this processing:

Speech recognition. Debrief uses Android's built-in speech recognition to turn your voice into text. On many devices this service is provided by the device maker or Google and, depending on your device and its settings, audio may be processed by that system service rather than entirely on-device. This is governed by your device/OS provider's privacy policy, not ours. Debrief itself does not store your raw audio; it works with the resulting transcript.

4. Account and sign-in (optional)

Debrief works fully without an account. You only sign in if you choose to enable cloud backup. Sign-in uses Google Sign-In / Firebase Authentication, and we receive your Google account email address to identify your backup. We request the Google Drive "app data folder" scope, which limits Debrief to a private folder that only the app can see. It does not give us access to the rest of your Drive.

5. Cloud backup (optional, end-to-end encrypted)

If you turn on backup, an encrypted copy of your database is stored in a private "app data" folder in your own Google Drive. Backups are encrypted on your device with AES-256-GCM using a key derived (PBKDF2, 600,000 iterations) from a passphrase that only you know.

This is zero-knowledge: we do not know your passphrase, we cannot decrypt your backup, and Google stores only the encrypted blob in your Drive. If you lose your passphrase, the backup cannot be recovered, by us or anyone.

You can turn off backup and delete backup files at any time.

6. What we do not do

7. Service providers (sub-processors)

We rely on a small number of providers strictly to operate the app:

Provider Role Data involved
Cloudflare Hosts the processing service that handles extraction/suggestion requests Transcript and snapshot text sent during a request (transient)
Anthropic AI provider (Claude) that performs the extraction/suggestions The same request text; not used for training
Google (Firebase Auth, Google Sign-In, Google Drive) Authentication and your optional encrypted backup storage Your account email; the encrypted backup blob (Google cannot read it)
Google / device maker (Android speech recognition) Converts your speech to text Audio handled by the device's speech service, per your OS provider's policy

8. Data retention

9. Security

No system is perfectly secure, but Debrief is designed so that the sensitive heart of your data, your friends' lives, is unreadable to us and to anyone without your device or your passphrase.

10. Your rights and choices

You can, at any time:

Depending on where you live (e.g. the EEA/UK under GDPR, or California under CCPA), you may have additional rights to access, correct, port, or erase personal data, and to object to or restrict processing. Because we hold essentially no readable personal data about you on our servers, most of these rights are exercised directly on your device. For anything else, contact us and we will help.

Legal bases (GDPR). Where GDPR applies, we process the limited data above to provide the service you request (performance of a contract) and on the basis of your consent for optional features such as backup and microphone access, which you can withdraw at any time.

11. Children

Debrief is not directed to children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their personal data. If you believe a child has provided personal data to us, contact us and we will address it.

12. International transfers

Our service providers may process data in countries other than yours, including the United States. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses. The data involved is limited to the transient processing text and your account email; your encrypted backup is readable only by you.

13. Changes to this policy

If we change this policy, we will update the "Last updated" date above and, for material changes, surface a notice in the app or on our website. Continued use after an update means you accept the revised policy.

14. Contact

Questions, requests, or concerns:
The App Joinery · hello@theappjoinery.com