SXRIPT ("we," "our," "us") makes an iOS app that helps you rehearse real conversations — job interviews, sales pitches, presentations, and more — with an AI partner named Echo. This policy explains what we collect when you use the app, why, and the choices you have.

1. Information we collect

Account information

When you sign up, we collect your email address and a display name. If you use "Sign in with Apple," we receive the identifier and email Apple shares with us (which may be a private relay address if you choose to hide your email).

Rehearsal session data

Each time you complete a rehearsal, we store: the scenario category you chose, the setup details you provide (who Echo should play, the context), the full conversation transcript (your messages and Echo's replies), and the score, strengths, improvement notes, and enhancement plan generated for that session. This is what powers your Results and History screens.

Voice & microphone data

If you use voice input, your speech is transcribed on your device using Apple's built-in Speech Recognition — we do not receive or store the audio recording itself, only the resulting text, which becomes part of your session transcript as described above.

Information we do not collect

We do not use advertising SDKs, do not run third-party analytics or tracking, and do not collect data for purposes unrelated to running the app's core features.

2. How we use it

  • To create and secure your account, and let you sign in on your devices.
  • To run your rehearsal sessions — generating Echo's in-character replies, mid-session feedback, and your end-of-session score.
  • To show your session history and track how your scores change over time.
  • To respond if you contact us for support.

We do not sell your personal information, and we do not share your conversations with other users — everything you rehearse is visible only to you.

3. Third-party services we use

SXRIPT is built on a small number of trusted infrastructure and AI providers, each used only for the specific job described below:

ServicePurpose
SupabaseAuthentication, and secure storage of your account and session data (hosted database).
Google Gemini (via Lovable AI Gateway)Generates Echo's replies, mid-session feedback, and your session score, from the scenario and transcript you provide.
ElevenLabsConverts Echo's text replies into spoken audio played back in the app. Text sent for narration is not retained by us after playback.
AppleOn-device Speech Recognition for voice input, and Sign in with Apple for authentication.

Each provider processes only the minimum data required for its function (for example, your conversation text is sent to generate a reply, but not your email address). These providers do not use your data to train models for other customers, beyond what's necessary to provide the service to us.

4. Storage & security

Your data is stored in Supabase's managed cloud infrastructure and protected by row-level security rules, so your account and sessions are only ever readable by you. All traffic between the app and our backend is encrypted in transit (HTTPS/TLS).

5. Data retention

We keep your account and session data for as long as your account remains active, so your history stays available to you. If you delete your account, your data is permanently removed as described in Section 7.

6. Your rights & choices

  • Access: your full session history is available anytime in the app's History tab.
  • Correction: you can update your display name in Settings.
  • Deletion: you can permanently delete individual sessions from History, or your entire account (Section 7).
  • Questions or requests: contact us any time — see Section 11.

Depending on where you live, you may have additional rights under laws like the GDPR or CCPA/CPRA, including the right to request a copy of your data or object to certain processing. Contact us and we'll assist.

7. Deleting your account

You can permanently delete your account and all associated data directly in the app: go to Settings → Delete Account. This action is immediate and cannot be undone — no confirmation email or waiting period is required.

8. Children's privacy

SXRIPT is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

9. International data transfers

Our service providers may process and store data on servers located outside your country of residence. Wherever your data is processed, we require our providers to protect it consistently with this policy.

10. Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date above and, where appropriate, notify you in the app. We encourage you to review this page periodically.

11. Contact us

Questions about this policy or your data? We're happy to help.

mohammed.adlani@sxript.ai