Privacy policy
Last updated: 9 October 2026
Controller
Leon Kraus
Zur Schockenkammer 1
31535 Neustadt
Germany
Email: [email protected]
The principle: most of it never leaves your phone
Bravy needs no account and no sign-up. Your journal — people, events, timeline, commitments, plans, debriefs and your practice history — lives in a database on your device. We neither read it nor store it. You can additionally lock the app behind Face ID or a passcode. Your contacts are never imported.
When data does leave the device, the names you store for people stay behind. A request to us or to anyone else has no field for a person's name — not the real one, and no substitute either: the AI is told how you work together, the role and working style you chose to share, and the notes you picked — or, for a practice idea, allowed. This is enforced rather than promised: the function that assembles a request has no field a name could go in. What it cannot do is take names out of your own words — the notes you pick and what you say or type in a practice are sent as you wrote or said them, so a name in them is sent too.
You can give a person you added a photo, chosen with your phone's own photo picker. Bravy sees only the one picture you choose, keeps a small copy of it on your device without its metadata (such as where it was taken), and never sends it anywhere — not to us, not to the AI, in no request. The face of the other side in an avatar practice is a stock face from Anam, never the photo of a person you added. Like the rest of your journal, the photo is part of your phone's backup (iCloud or your computer), which Bravy cannot switch off for it. Removing the photo, deleting the person or deleting all journal data deletes it from the device.
What is transmitted when you practise
When you start a practice session, we receive which scenario you are practising and — only if you have explicitly confirmed a personalised session — the journal excerpts you selected and, when you practise a conversation you planned, its topic and what you wrote about the situation — all as you wrote them, without the name you stored for the person — and, if you left that row on, your experience and workplace (how long you have worked, your industry and your team's function, as you picked them in the app). Before a personalised session starts, all of this goes through our server to OpenAI to write the briefing you read first; after that it becomes part of the instructions for the other side, so it goes to the same providers as the conversation itself. If you have set your own name in the app, it is sent with a personalised or written practice so the other side can address you by it, and with the transcript for the debrief so the feedback can call you by it; the voice of a spoken library practice is never given it. When you let the other side begin a conversation you planned, what it plays from — including that topic and situation — goes to OpenAI at the start, to write its first words.
Spoken practice. Your voice is streamed to ElevenLabs over WebRTC. ElevenLabs transcribes it, has the reply written by a language model from OpenAI, which it uses as its own subprocessor, and speaks that reply. When the practice has goals, the conversation so far also goes through our server to OpenAI after each of your turns, to mark which goals you have reached; our server stores none of it.
Avatar practice. If the app offers it and you choose it, the other person appears with a face. Your voice then goes over WebRTC to Anam (Anam AI Ltd), which passes it on to ElevenLabs as in a spoken practice and turns the reply into the face and the voice you see and hear, in a page from our server shown inside the app. Anam receives your voice and the transcript of the conversation while you talk and processes them on servers in the EU or the USA; we ask it not to record the session, and it keeps a report of the session, including the transcript, until we delete it. Anam does not use the content of the session to train its own AI models or anyone else's. No camera is used: your own picture never leaves the phone.
Written practice. Each message you send goes through our server to OpenAI as you send it, together with the conversation so far, and OpenAI writes the reply. Dictating a message and having replies read aloud both happen on your phone.
Need a line. If you tap the lightbulb during a practice for a sentence you could say, our server passes OpenAI what it needs to suggest one: before the first turn the scenario, after it the last ten turns and the goals still open. Your experience and workplace go with it, if you entered them in the app. The debrief asks the same way for opening lines when a practice was too short to analyse. Our server stores none of it.
Afterwards. The transcript and the conversation events sit briefly on our server, and the transcript is sent to OpenAI: that is where the feedback you read in the debrief is written. With it go the goals the practice was run against and your position, if you entered one.
We keep no permanent recording of your voice.
Practice ideas (optional)
On a person's page you can ask Bravy for a practice idea — a conversation worth rehearsing with them ("Suggest") — or switch on automatic practice ideas for that person, which Bravy then asks for now and then by itself. Before the first one, the app asks for your consent on a screen that says what is read, where it goes and how to stop it.
To write an idea, the app sends a request to our server, and our server passes it to OpenAI (USA). It carries the relationship and, for each category you left on: the person's role and how they communicate, your own experience and workplace, your entries about them, your takeaways (as your own view), the agreements you recorded with them, and your past conversations with them as you recorded them. You switch the categories on every request, and for automatic ideas once, when you turn them on for the person. That grant includes entries you write later: an automatic idea reads the journal as it is at that time, without asking again. When there is more than one request can carry, your newest notes go and the oldest stay on the device; the screen before a request says so. The name you stored for the person does not go; your notes go as you wrote them, so a name in them goes too. When no entry and no past conversation goes along, the idea comes from examples we wrote, and nothing reaches OpenAI.
Our server keeps nothing of the request or the idea. It keeps only counters that limit how many ideas can be asked for — per user, and per person under an anonymous key your device derives — without any content. The idea itself is stored only on your device.
You withdraw your consent for one person by switching their automatic ideas off on their page (the ideas not yet out are discarded), and entirely with "Delete all data" in Settings.
Weekly messages (optional)
If you switch them on in Settings, Bravy sends at most two notifications a week, on fixed weekdays: a weekly check-in and a scenario of the week. They are delivered by OneSignal (OneSignal, Inc., USA). Before anything is sent to OneSignal, the app asks for your consent on a screen that names the provider and what it receives; without that consent the OneSignal software in the app transmits nothing.
With your consent, OneSignal receives: an anonymous subscription identifier generated by its software, the push token Apple issues for your device, your device model and operating system version, the app's language and version, your timezone, your IP address, and two on/off values — whether the check-in and the scenario of the week are switched on. On its own, its software also records when the app is opened (sessions) and whether a message arrived or was opened. It does not receive your name, your journal, your plans, your agreements or anything you wrote; the messages are the same for everybody who switched them on. OneSignal's software can additionally record an App Store purchase made in the app (the product, its price and currency); the software offers no way to switch that off.
You withdraw your consent by switching both messages off in Settings: the device then unsubscribes and the software stops transmitting. "Delete all data" in Settings also asks our server to delete, at OneSignal, the subscription and the user record OneSignal keeps with it (the on/off values, the language, the timezone and the sessions); if your device is offline at that moment, write to [email protected] and we delete them for you. Reminders for your own planned conversations and agreements are scheduled on your device and never go through OneSignal.
Buying Bravy Pro on the web (optional)
You can also buy Bravy Pro on the web, at https://buy.getbravy.com/PhrkerJwEJFrSoWH, instead of in the app. This section applies only to that purchase.
The purchase pages. The pages with the questions, the prices and the success page are run for us by RevenueCat (RevenueCat, Inc., USA). You answer the questions only by tapping; there is no field for a name or any text. RevenueCat processes your answers, your IP address and technical details of your browser.
The payment. The payment is processed by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). Stripe receives your email address, your payment details (card, Apple Pay or Google Pay), your country and, where needed, your billing address, your IP address and details of your device. Stripe also uses part of this under its own responsibility to prevent fraud and meet legal obligations; Stripe's own privacy policy applies to that. We never see your full card details.
Activation in the app. RevenueCat receives the purchase and your email address from Stripe and sends you the activation link. When you tap it on your iPhone, RevenueCat connects the purchase to the anonymous identifier your app generated — the same one an App Store purchase would be stored under. No account is created.
What we receive. Of RevenueCat's message to our server, the server uses only that the anonymous identifier has Bravy Pro, and through which channel it was bought (web instead of App Store). Our server does not use or keep your email address or payment details, and the app does not ask for them. The app does not read your answers on the purchase pages either.
How long the records of a web purchase are kept is under "How long we keep things", and the legal bases under "Legal bases".
How long we keep things
Transcript and conversation events: 24 hours. They are then deleted automatically; a cleanup runs every hour. The debrief you read afterwards lives on your device, not with us.
Practice allowance and subscription status are stored against an anonymous identifier that your device generates and hands to RevenueCat, for as long as the subscription relationship lasts. No name is attached to it.
A web purchase: we keep the invoice and accounting records for as long as tax and commercial law require — up to ten years. RevenueCat keeps the purchase and the email address you paid with while the subscription lasts, and afterwards for as long as accounting and legal obligations require.
Abuse counters limit how many requests an identifier or an IP address can make within short time windows — for practice ideas also per day and per month, and per person under an anonymous key. They hold no content. Counters that hold an IP address are deleted after seven days at the latest.
At OpenAI: OpenAI may keep the requests it receives from us for up to 30 days to monitor for abuse, and deletes them after that.
At Anam: after an avatar practice, Anam keeps a report of the session, including the transcript, until we delete it. Its technical logs are kept for 30 days.
Legal bases
Running a practice session and handling the subscription — including buying, paying for and activating Bravy Pro on the web — rest on Art. 6 (1) (b) GDPR (performance of a contract). Keeping the invoice and accounting records of a web purchase rests on Art. 6 (1) (c) GDPR (tax and commercial law obligations). Abuse prevention, error diagnostics, data-minimising usage analytics and delivering app updates rest on Art. 6 (1) (f) GDPR (legitimate interest in a service that works and stays affordable), and so does preventing fraud in a web payment (legitimate interest in secure payments).
The optional weekly messages and practice ideas rest on your consent, Art. 6 (1) (a) GDPR, which you can withdraw at any time with effect for the future — in Settings, and for one person's automatic ideas on their page.
Recipients
- ElevenLabs — transcribes your speech and generates the conversational voice in spoken and avatar practice (USA)
- OpenAI — writes the replies in written practice, writes the briefing for a personalised practice and marks the goals reached during a practice, suggests a line when you ask for one, analyses the transcript and writes the debrief, writes the other side's first words when it begins a conversation you planned, and writes practice ideas from what you allowed it to read (USA); also the language model ElevenLabs uses, as its subprocessor, for the replies in spoken and avatar practice
- Anam — shows the face and speaks the replies in avatar practice (EU/USA)
- RevenueCat — handles the subscription, runs the web purchase pages and sends the activation link (USA)
- Stripe — processes the payment when you buy on the web (Ireland; transfers to the USA possible)
- Neon — our server's database (USA, Oregon region)
- OneSignal — delivers the optional weekly messages, only with your consent (USA)
- Expo — delivers app updates between App Store releases (USA)
- Apple — distributes the app and processes purchases
No third party is involved in error diagnostics or usage measurement: both run on instances we operate ourselves.
Transfers to the United States
ElevenLabs, OpenAI, RevenueCat and Neon process data in the United States; Stripe, which processes the payment for a web purchase from Ireland, may transfer it there too. Transfers rely on the EU-US Data Privacy Framework where the provider in question is certified, and otherwise on the European Commission's standard contractual clauses. Data processing agreements are in place with all of them.
OneSignal processes the data of the optional weekly messages in the United States as well, on the same terms: the EU-US Data Privacy Framework where it is certified, otherwise the standard contractual clauses, under OneSignal's data processing agreement.
Anam processes the data of an avatar practice on servers in the EU and the United States. Transfers to the United States rely on the standard contractual clauses or another of the lawful transfer mechanisms Anam names in its privacy policy, under Anam's data processing agreement.
Expo delivers the app's updates from the United States. The transfer relies on the EU-US Data Privacy Framework where Expo is certified, and otherwise on the standard contractual clauses.
A residual risk remains: under certain conditions, US authorities can access data processed there. That is precisely why your journal leaves the device only in the parts you confirm or allow, and why what does leave it carries no name field for the people in it.
Usage measurement
We measure usage with Umami on an instance we run ourselves. The IP address and User-Agent of each request are also processed to distinguish visits. No cookies are set and no cross-device profile is built. An event contains identifiers, status values, counters and durations — never conversation content, names or quotes.
Error diagnostics
We collect technical errors with GlitchTip on an instance we run ourselves, in order to find and fix crashes. No third party is involved.
A report contains the error and its stack, plus what the SDK knows about the app version, the operating system and the device model. It deliberately contains no screenshot, no view hierarchy, no record of which buttons you tapped, no request contents — and no conversation content, journal entry or name. Those are removed before a report is sent rather than filtered afterwards. We keep reports for as long as fixing the error requires.
App updates
To deliver fixes between App Store releases, the app asks the update service of Expo (650 Industries, Inc., USA) each time it starts whether a newer version of its code is available, and downloads it if there is one. Expo receives your IP address, the app's version and update channel, your device's platform, and a random identifier that the update software generates for this installation, which Expo uses to count active installations. It receives nothing you wrote and no name. The update replaces only the app's own code; your data on the device stays as it is.
What we do not do
We use no advertising identifiers, run no ad tracking, sell no data and do not read your contacts.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Write to [email protected]. You may also lodge a complaint with a data protection supervisory authority.
Independently of all this, the app's settings let you delete every piece of practice and journal data on the device at any time.
Because there is no account, we cannot find your server-side data by your name. To have the counters for your identifier deleted — practice allowance, subscription status and practice-idea limits — write to [email protected] and include the order ID from Apple's receipt for your subscription; we use it to find the identifier and delete its rows. If you bought on the web, the email address you paid with is enough. If you never subscribed, they hold no practice and nothing we could connect to you. Deleting them does not cancel a subscription — that happens with Apple, or, if you bought on the web, through "Manage subscription" in the app's settings or the link in your purchase email.
Changes
We update this policy when the app changes. The version published here is the one that applies.