Clear by design
Privacy &
your data.
Preview notice · September 15, 2026
This notice describes the current website and private app preview. We will update it before public accounts and paid subscriptions launch.
On this website
The page serves text, images and an optional audio sample. It has no account form, checkout, email collection, advertising trackers or session recording. Playing the sample requests an audio file; it does not request microphone access. The website is hosted on Vercel, whose delivery infrastructure processes connection data such as IP addresses and HTTP request information. See Vercel’s privacy policy.
Optional website analytics
Analytics stay off until you choose Allow analytics in the footer. If enabled, we send page paths, sample playback starts, completions and failures, and clicks on available store links to PostHog US Cloud. No query strings, page fragments, referrers, typed content or advertising identifiers are sent. A random browser-tab identifier lasts until 30 minutes of inactivity or until the tab closes. Your choice is saved in this browser; we do not link website activity to your app account. No cookies, session recording or automatic click tracking are used. PostHog receives connection data to deliver these events; the project discards IP addresses and disables location enrichment.
Use Turn off in the footer at any time to stop collection and clear the tab identifier. This does not retract events already delivered. Browser Do Not Track and Global Privacy Control preferences keep analytics off. Vercel still processes the connection data needed to serve the website. Website metrics cover consenting visits and are not a count of every visitor.
Repository content and AI
The normal app experience uses a hosted service. When you submit a public GitHub URL, we retrieve selected public repository content and send material needed for research, writing, review and narration to OpenAI. Do not submit secrets or private repository material. Cloud processing is part of this service; it is not entirely on-device. See OpenAI’s privacy policy.
The shared catalog
Repository revisions, generated scripts, citations and audio are stored so matching editions can be reused by other listeners. Your library association is separate from the public recording. Removing your library copy or deleting your account does not remove the underlying public catalog edition.
App access and library data
The preview service stores invitation/account identifiers, access allowances, creation requests, job status and saved-library associations. Its database and media are hosted on Railway. Device credentials are stored in the device Keychain; the service stores hashes of session tokens. The Sign in with Apple implementation requests no name or email scopes and is not yet enabled for public use.
Downloads, listening position and bookmarks are stored on your device. If you configure the preview’s optional iCloud Drive folder sync, library data is also written to the folder you select. The current preview does not provide automatic account-based iCloud synchronization.
Deletion and backups
Use the book-management menu to remove downloaded audio or permanently delete a library entry. Account deletion removes hosted library associations and revokes account access. Local copies need to be removed separately. Private backups may retain an earlier snapshot until it leaves the seven-copy retention cycle; this is not immediate erasure or a guarantee of exactly seven days. A separate private recovery record preserves confirmed deletions so restoring a backup does not bring deleted account or library associations back. This record is kept beyond the rotating backups for recovery and contains hashed account identifiers and deletion references. Account-aware recovery preserves eligible library associations and requires fresh sign-in; old session credentials are invalidated. The membership implementation retains verified purchase linkage and signed-state snapshots to reconcile access and recover paid allowances. Operational purchase observations contain transaction references, product, currency, recorded price and renewal/refund status. They are part of private account recovery records. Purchases remain disabled; the retention policy and final subscription terms must be completed before billing opens.
Operational information
The service retains job status, errors, provider-operation receipts and usage records needed to operate the preview. We use PostHog US Cloud for service reliability metrics: creation outcomes and timing, catalog reuse, delivery failures, worker health, storage capacity, backup status, and AI token usage and estimated costs by model and writing stage. When billing becomes available, verified purchase and renewal observations, gross prices by currency, missing-price indicators and renewal/refund status are sent with pseudonymous transaction and subscription identifiers. Payment details, Apple account tokens and signed purchase payloads are not sent to PostHog. Operational gross amounts are not App Store financial settlement reports. Cost records use pseudonymous edition identifiers to measure successful and failed work; they do not contain prompts, model responses or audio. Events use a restricted set of fields and pseudonymous identifiers, without repository contents, transcripts, credentials, email addresses or raw error messages. IP storage and session recording are disabled for the Repophonic PostHog project. See PostHog’s privacy policy.
Sharing app diagnostics is optional and off by default. Enable or disable it under Profile → Help & about → Share app diagnostics. When enabled, the app sends screen names, download and playback outcomes, timing, app version, error categories and sanitized Apple crash reports through the Repophonic service to PostHog. Crash reports include application binary identifiers and stack addresses needed to locate a code failure, without raw crash messages, memory contents, device names or file paths. Apple delivers these on its own schedule. We discard reports whose time window overlaps a period before diagnostics consent or an account change. A random installation identifier is replaced on sign-out, account/service changes or opt-out; no device advertising identifier is used. Turning it off deletes unsent diagnostics, but does not retract events already delivered. Unsent app events are limited to 100 and expire after seven days. The service delivery queue is also bounded and expires unsent events after seven days. Delivered events remain subject to the project’s PostHog retention settings. The optional website analytics described above are separate from app diagnostics.
Ready alerts
When available, ready alerts are optional and controlled under Profile → Updates & notifications. If you enable them, Repophonic stores an encrypted Apple push token and associates it with your current account and device so it can tell you when a creation finishes or needs attention. Apple receives generic alert text and opaque account and book identifiers, without repository content or transcripts. Unused registrations expire after 30 days, and delivery records expire after seven days. Signing out, deleting your account or turning off alerts cancels queued delivery; an alert already sent to Apple may still arrive. The app checks your current account before opening a book. Ready alerts are separate from optional app diagnostics.
Questions or requests
Private-preview testers can ask for help through the conversation in which they received their invitation. A public support email will be listed here before public access opens. This website does not collect support requests.
Additional public-launch contact details and applicable privacy rights information will be added before public sign-up opens.