1. Overview

This Privacy Policy explains what information True Lies ("we," "us," "our") collects through the True Lies mobile application (the "App"), how we use and share it, and the choices you have. By using the App you agree to the collection and use of information as described here.

2. Information We Collect

Account information

When you register, we collect your email address and password (stored in hashed form), or basic profile information if you sign in with Google.

Session content

When you run a session, we collect the audio you record, the transcript generated from it, the questions and topics you enter, and the resulting analysis (stress scores, consistency flags, and reports).

Usage & device data

We automatically collect information such as app version, device type and operating system, crash logs, and general usage events (e.g., sessions started, features used) to maintain and improve the App.

Payment information

Subscription payments are processed entirely by the Apple App Store or Google Play. We do not receive or store your full payment card details; we receive limited confirmation of purchase and subscription status from these platforms.

Camera & biometric data (roadmap feature)

True Lies is developing an optional camera-based feature that estimates heart rate from facial video using remote photoplethysmography (rPPG), and tracks blink rate, facial tension, and gaze movement. If and when this feature ships, it will be off by default and will require your separate, explicit consent before any camera session begins. Facial video and the biometric measurements derived from it (such as estimated heart rate) are treated as sensitive biometric information: they will be processed to generate your session report, will not be used to identify you outside the App, and will be subject to the additional consent, notice, and retention limits required by applicable biometric privacy laws (such as Illinois's BIPA) in the jurisdictions where they apply.

3. How We Use Information

We do not sell your personal information, and we do not use your session audio or transcripts to serve you advertising.

4. How Information Is Shared

Third-party AI & transcription providers

To generate transcripts and analysis, session audio and text are sent to third-party processing providers, which may include OpenAI (Whisper transcription, GPT models), Google (Gemini models), and Anthropic (Claude models). These providers process the content on our behalf under their own data-processing terms and do not use it to train their models for other customers, to the extent their commercial (API) terms so provide. We may add, remove, or change providers over time to maintain service quality.

Service providers

We share information with vendors who help us operate the App — such as cloud hosting and authentication providers — under contracts that limit their use of your information to providing services to us.

Legal & safety

We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of any person.

Business transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy or a successor policy.

5. Data Retention

We retain session recordings, transcripts, and reports for as long as your account is active, so that they remain available in your session history. You may delete individual sessions or your entire account at any time from Settings; deletion removes the associated content from our active systems within [Insert Timeframe, e.g., 30 days], except where retention is required for legal, security, or fraud-prevention purposes.

6. Data Security

We use industry-standard safeguards — including encryption in transit and access controls — to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Rights & Choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing (for example, under the EU/UK GDPR or the California Consumer Privacy Act).

8. Biometric Information

Where the App collects biometric identifiers or biometric information (for example, facial geometry or rPPG-derived heart-rate data from the optional camera feature described above), we will: obtain your prior written or in-app consent before collection; use that information only to provide and improve session analysis; not sell, lease, or otherwise profit from it; and retain it only as long as necessary to provide the App or as required by law, after which it will be permanently deleted, consistent with applicable biometric privacy statutes.

9. Recordings of Other People

Because sessions can include the voice of people other than the account holder, this information may relate to third parties who are not our direct users. If you are the subject of a recording made by someone else's account and want to make a privacy request, contact us at the email above and we will work with the account holder as required by applicable law.

10. Children's Privacy

The App is not directed to, and is not intended for use by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us so we can delete it.

11. International Data Transfers

Your information may be processed in countries other than your own, including the United States, where our service providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version in the App with a new "Last updated" date, and will provide additional notice for material changes.

13. Contact Us

Questions about this Privacy Policy can be sent to privacy@truelies.app.