Who is responsible

SayBits is operated by Alentra, based in Sweden. Alentra is responsible for deciding how the personal data described in this policy is used. Contact hello@alentra.app (mailto:hello@alentra.app) for privacy questions or to exercise your rights.

This policy covers the SayBits app, the saybits.com website and our support interactions. SayBits is for people aged 16 or older, subject to any higher age required where they live.

Information we process

Your account and profile. We process an account identifier, sign-in details supplied through Apple, Google or email authentication, verification status, username, display name and preferences. Your optional profile photo, biography, website, profile type and chosen city and country are also stored. Location is optional and appears on your public profile. When you search for a city, Apple Maps processes the search text to provide matching places. We store the place you select, including its region, country code and available place identifier; we do not store your search text or request your GPS location. You can change or remove the location in Edit profile. Sign-in providers process information under their own notices too. Your sign-in email is not automatically published on your profile.

Age confirmation. We store your confirmation that you are 16 or older, the accepted Terms version and the time of your first confirmation. On supported Apple devices, we check the age requirements exposed by Apple and request an age range when the system indicates it is required. Apple age ranges are processed on your device and are not sent to our backend or retained by SayBits. We do not collect your birthday through this flow. A confirmation is a declaration, not identity verification.

Optional assistive speech choice. You can turn on “I use assistive speech” during setup or in Settings → Privacy & alerts. It is off by default and is not shown on your public profile. We use it only to give authorized reviewers context when reviewing voice reports or appeals. We do not request a diagnosis or medical documents. Turning it off updates the current choice; a missing or off choice does not establish a violation. Where a moderation decision was made, a limited record of the context reviewed may remain with that case under the safety-record retention criteria below. The current account choice is removed through account deletion.

What you create and share. We store the voice recordings you submit, their duration and technical file details, chosen spoken language, topics, posting destination, timestamps, thread/reply relationships and information needed to deliver them. Drafts and recoverable failed recordings are held on your device. Audio being uploaded may already be on our servers even if publication has not completed. SayBits does not automatically transcribe recordings or generate voices.

Your activity and choices. We process follows, likes, saved bits, topic choices, blocks, message requests, Circle membership and invitations, read markers, notification settings and reports. We store the latest time you open the app while signed in and the latest recommendation reminder's time and topic. If enabled, recommendation notifications may suggest a topic or public bit in your listening languages after three days away, at most once every eight days. You can turn these off in notification settings. We also use playback acknowledgements and temporary feed state to resume listening and avoid repeats. Your device maintains a separate recent listening History for 24 hours.

Devices and service operation. Authentication and delivery services process technical information such as device or installation identifiers, connection information, IP addresses, request times and errors. If you enable notifications, Firebase and Apple process the information needed to route them to your device. These delivery identifiers are associated with your account while registered.

Support and safety. When you email us, report content or appeal a restriction, we process what you send, the relevant account/content references, our responses and review records. Please leave passwords and unrelated private information out of support requests.

Why we use it

We use account, content and interaction data to provide the features you request: sign-in, posting, playback, private conversations, saving, following, sharing and account management. Our proposed legal basis is performance of our agreement with you where the processing is necessary to deliver those features.

We use limited technical and safety records to protect accounts, prevent abuse, investigate reports, maintain reliable delivery and resolve disputes. The proposed basis is our legitimate interest in a secure, functioning service, balanced against your rights. Where a particular law requires processing or disclosure, we rely on that legal obligation.

For you combines followed topics with recommendations based on the topics of public original bits or thread segments you like. It can use patterns in shared topic interests to suggest related topics. It does not use the contents of private messages, listening alone, reply activity or person-following to learn these topic preferences. This is automated personalization; it is not an automated decision about employment, credit or similar eligibility. Our proposed basis for this limited personalization is legitimate interests, subject to the assessment described in the prelaunch handoff. Following offers a people-based feed. You can change followed topics and languages, use “Stop showing similar bits,” or contact us to object to processing based on legitimate interests.

We ask for notification permission after account setup, microphone access when you start recording, and camera access if you choose to take a profile photo. Choosing an existing profile photo uses the system photo picker and gives us only the photo you select. You can withdraw device permissions in device settings. Listening does not require microphone access, and notifications and profile photos are optional. Device permission is not blanket consent to unrelated data use. If we introduce processing that requires separate consent, we will ask for it specifically and explain how to withdraw it.

Who can see your information

Your public profile, public bits, replies, topics and public interaction totals are visible to other users. Public content can be shared outside SayBits, copied, quoted or included in previews. Choose what you publish with that in mind.

Circle and direct-message content is restricted to authorized participants within SayBits. It is not end-to-end encrypted: Alentra and its service providers can process stored content where needed to deliver, secure or investigate the service. Participants may record, download or share material outside the app. Access restrictions cannot prevent every recipient from making a copy.

Your Saved Bits list is private. A bit's public save total counts accounts that have saved it, without displaying their identities. Removing a save removes it from your list but does not reduce this lifetime total; saving it again does not add another contribution from the same account.

Service providers process data to operate SayBits. Current components include Google/Firebase for authentication, database storage, profile pictures and notification delivery; Cloudflare for voice-file storage and delivery; Railway for application hosting; ZeptoMail for account verification and password-reset emails through its EU API; and Apple for sign-in, city search, app distribution and push delivery. Account emails include your email address and a one-time action link. We disable email open and click tracking. Email providers also process support correspondence. We may disclose relevant information when legally required, to protect people or the service, or to handle a lawful claim. We do not sell personal data or use it for targeted advertising in this release.

Storage and international processing

Our main database and avatar storage are configured in Stockholm, voice storage uses Cloudflare's EU jurisdiction, and the backend runs in the Netherlands. These settings do not mean every authentication, support, security or network operation takes place only in the EEA. Providers may process information internationally. Applicable transfer safeguards and how to obtain information about them must be confirmed before this draft becomes effective; contact us with questions.

How long information stays

Account details, preferences and published content remain while needed to provide your account and the content you keep in the service. Public posts and private messages do not automatically disappear after a fixed number of days. You can delete your own content and initiate account deletion in the app.

Unpublished server upload reservations and temporary feed sessions generally become eligible for cleanup after 24 hours. Cleanup runs in the background and may finish later. This does not delete a recoverable draft still on your device or apply a 24-hour limit to published audio. The separate device History covers the latest 24 hours; playback caches are bounded and managed separately.

Deleting content removes authorized access while background jobs remove associated stored assets. Account deletion also removes account-linked content and relationships through the cleanup process. Anonymous aggregate save totals may remain. Recipients' external copies, exported files and third-party search caches are outside our direct control.

Some limited records may need longer retention for unresolved reports or appeals, security, preventing deleted or restricted accounts from resuming old operations, legal duties or claims. The proposed retention criteria are the purpose of the record, whether the issue remains open, applicable legal requirements and whether the identifying data is still necessary. We must review and implement the detailed operational schedule before this draft takes effect; we do not promise that all logs, receipts or backups disappear instantly.

Website and sharing

The reviewed launch website has no advertising trackers or analytics integration, and serves its fonts locally. Hosting providers still receive normal connection information. Curated sample audio plays only when you choose to play it; it is not a public feed of app recordings. Following a store, social or other external link brings you under that service's privacy practices.

The preview contact form currently does not send or store submitted messages on our servers. Email hello@alentra.app to reach us. We will update this explanation before activating form delivery. Shared app links and exported audio, images or videos may be handled by the receiving platform; that platform may keep a copy independently of SayBits.

Your rights and choices

Depending on the circumstances, you can request access, correction, deletion, restriction or a portable copy of your personal data, and object to processing based on legitimate interests. You can withdraw consent where it is the basis for processing, without changing the lawfulness of earlier processing. Contact hello@alentra.app; we may request proportionate information to verify that the request is yours. Some requests have lawful exceptions, which we will explain.

You can complain to Sweden's Integritetsskyddsmyndigheten (IMY) (https://www.imy.se/privatperson/utfora-arenden/lamna-ett-klagomal/) or your relevant supervisory authority. You do not have to contact us first to exercise that right. Information about data-protection rights is available from the EDPB (https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en).

Young people and changes

SayBits does not permit accounts for people under 16. If you believe an underage person has an account, tell us so we can investigate and take appropriate action. We do not claim to verify everyone's identity or age automatically.

We will update this policy when the service or its processing changes, show the effective date and communicate material changes appropriately. A new purpose requiring consent will not be authorized merely by changing this page.