Debrief ("Debrief", "the app", "we", "us") is a voice-first personal relationship manager for Android, published by The App Joinery. This policy explains exactly what data the app handles, where it lives, what leaves your device and why, and the choices and rights you have.
We wrote this in plain language on purpose. If anything here is unclear, email us at hello@theappjoinery.com.
The data controller is The App Joinery.
Contact: hello@theappjoinery.com.
The core of Debrief is local. The following is stored only on your device, in a database encrypted with AES-256 (SQLCipher) whose key is protected by your device's hardware-backed keystore:
We never receive this database. It is not uploaded anywhere unless you turn on cloud backup (Section 5).
Phone contacts (optional). If you grant the Contacts permission, Debrief can let you link a friend to an existing phone contact for convenience. Contact data read for this purpose stays on your device and is not transmitted to us or anyone else. You can use the app without granting this permission.
To turn what you say into a structured profile and to generate suggestions, Debrief sends certain text to a processing service we operate (a Cloudflare Worker), which forwards it to our AI provider, Anthropic (Claude). This happens only when you take an action that needs it:
| When | What is sent | Why |
|---|---|---|
| You record or type a debrief | The transcript text, plus the names of friends already in your app (to correct mis-heard names) | Extract structured facts (birthday, family, interests, etc.) |
| You log a "moment" (trip, dinner, adventure) | The transcript text and the moment type | Extract a structured moment summary |
| You open conversation starters or gift ideas | A snapshot of the relevant friend (e.g. name, work, location, family, interests, recent notes) | Generate suggestions tailored to that person |
What you should know about this processing:
Speech recognition. Debrief uses Android's built-in speech recognition to turn your voice into text. On many devices this service is provided by the device maker or Google and, depending on your device and its settings, audio may be processed by that system service rather than entirely on-device. This is governed by your device/OS provider's privacy policy, not ours. Debrief itself does not store your raw audio; it works with the resulting transcript.
Debrief works fully without an account. You only sign in if you choose to enable cloud backup. Sign-in uses Google Sign-In / Firebase Authentication, and we receive your Google account email address to identify your backup. We request the Google Drive "app data folder" scope, which limits Debrief to a private folder that only the app can see. It does not give us access to the rest of your Drive.
If you turn on backup, an encrypted copy of your database is stored in a private "app data" folder in your own Google Drive. Backups are encrypted on your device with AES-256-GCM using a key derived (PBKDF2, 600,000 iterations) from a passphrase that only you know.
This is zero-knowledge: we do not know your passphrase, we cannot decrypt your backup, and Google stores only the encrypted blob in your Drive. If you lose your passphrase, the backup cannot be recovered, by us or anyone.
You can turn off backup and delete backup files at any time.
We rely on a small number of providers strictly to operate the app:
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare | Hosts the processing service that handles extraction/suggestion requests | Transcript and snapshot text sent during a request (transient) |
| Anthropic | AI provider (Claude) that performs the extraction/suggestions | The same request text; not used for training |
| Google (Firebase Auth, Google Sign-In, Google Drive) | Authentication and your optional encrypted backup storage | Your account email; the encrypted backup blob (Google cannot read it) |
| Google / device maker (Android speech recognition) | Converts your speech to text | Audio handled by the device's speech service, per your OS provider's policy |
No system is perfectly secure, but Debrief is designed so that the sensitive heart of your data, your friends' lives, is unreadable to us and to anyone without your device or your passphrase.
You can, at any time:
Depending on where you live (e.g. the EEA/UK under GDPR, or California under CCPA), you may have additional rights to access, correct, port, or erase personal data, and to object to or restrict processing. Because we hold essentially no readable personal data about you on our servers, most of these rights are exercised directly on your device. For anything else, contact us and we will help.
Legal bases (GDPR). Where GDPR applies, we process the limited data above to provide the service you request (performance of a contract) and on the basis of your consent for optional features such as backup and microphone access, which you can withdraw at any time.
Debrief is not directed to children under 13 (or the equivalent minimum age in your country) and we do not knowingly collect their personal data. If you believe a child has provided personal data to us, contact us and we will address it.
Our service providers may process data in countries other than yours, including the United States. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses. The data involved is limited to the transient processing text and your account email; your encrypted backup is readable only by you.
If we change this policy, we will update the "Last updated" date above and, for material changes, surface a notice in the app or on our website. Continued use after an update means you accept the revised policy.
Questions, requests, or concerns:
The App Joinery ·
hello@theappjoinery.com