Firmly

Privacy Policy

Effective date: September 6, 2026

Firmly lets you practice a hard conversation out loud with an AI character, and then tells you how it went. That only works if your voice leaves your phone. This page says exactly where it goes, who processes it, what we keep, and how you get rid of all of it.

Firmly is made by Martin Haindl (Haindl Apps). This policy covers the Firmly iOS app. Questions go to hello@haindlapps.com.

The short version

No account, one anonymous ID

The first time you open Firmly, the app quietly creates an anonymous account with Supabase, our backend provider. It is a random ID and nothing else. It is not linked to your name, your email address, your phone number or your Apple ID, and we cannot work out who you are from it.

That ID is what holds your practice history together: your session records, your feedback reports and whether your subscription is active. We also hand it to RevenueCat, the service that tells the app whether your subscription is active, so it recognizes the same anonymous person across launches.

The ID is stored in your device keychain, which means it survives deleting and reinstalling the app. If you want a genuinely fresh start, use "Delete all my data" in Settings before you delete the app.

A random device key

Alongside the anonymous ID, the app creates one more random string the first time it runs and keeps it in your device keychain, on this device only, never synced to iCloud. It is sent with every session start. Its single job is to keep the free voice session fair: our server remembers, per device key, whether the free session has been used, so that deleting your data and starting over does not hand out a new one.

The key is random, so it says nothing about you or your phone. It is not Apple's vendor identifier, not an advertising identifier, and it is not used for tracking or analytics. It survives deleting the app and it survives "Delete all my data": after a deletion nothing is attached to it anymore except that one yes-or-no note.

What Firmly collects, and why

Your voice, while a live session is running

When you practice out loud, your microphone audio is streamed to ElevenLabs, the voice platform that runs the conversation. They turn your speech into text so the character can react, and they speak the character's reply back to you.

We never receive your audio ourselves and it is never stored in our database. ElevenLabs does not record it either: the platform is set to keep no audio at all. The microphone is only live while a practice session is actually running. Firmly never listens in the background.

Text sessions run through the same platform, just without the microphone. What you type and what the character replies is handled exactly like the transcript of a spoken session.

The conversation itself

What was said in a session, by you and by the character, is the raw material for your feedback report. When you end a session, your device sends that transcript once to our server, which passes it to Anthropic to write the report.

Our database does not keep the transcript. No conversation turns are saved on our side, and the copy we handle exists only for the length of that one request. What survives is the report.

Your feedback report

Reports are kept, because the whole point is being able to look back. Your report is stored on your device (the most recent 20) and a copy is stored on our server against your anonymous ID. Reports quote lines you actually said, so treat them as personal.

Deleting a single report in Settings removes it from your device. The server copy stays until you use "Delete all my data", which removes every report at once.

What you type

How you use the app

Our server stores one row per practice session: which scenario, voice or text, which difficulty level, when it started and ended, how long it ran, and whether a report was generated. We need that to run your session allowance honestly and to understand what a session costs us to provide.

Firmly does not include a third-party analytics SDK. There is no advertising identifier, no device fingerprinting, and no tracking across other apps or websites. That is also why iOS never shows you the App Tracking Transparency prompt in Firmly: we have nothing to ask permission for.

Your subscription

Purchases go through Apple. Apple tells RevenueCat whether your subscription is active, and RevenueCat tells the app. We never see your card details, your billing address or your Apple ID. All we learn is whether a given anonymous ID has an active subscription.

The AI providers, and what each one gets

Firmly could not exist without third-party AI. Here is exactly who does what.

ElevenLabs (the voice platform)

Receives: your session audio, the words spoken on both sides, your first name if you set one, and the instructions describing the character and the scene.

Does: turns your speech into text, runs the live conversation, and speaks the character's replies in the character's voice.

Google (Gemini)

Receives: the character instructions and the conversation text, passed on by ElevenLabs.

Does: plays your practice partner. It decides what the character says next and how hard it pushes back.

Anthropic (Claude)

Receives: the conversation transcript after a session, the last few turns of a running session when you tap “Need a line?”, and the situation text you type yourself.

Does four separate jobs:

  1. Writes your feedback report once a session ends, including the quotes it points at.
  2. Steps in as the backup model inside the live conversation when the main model is slow or unavailable, so your practice partner can still answer.
  3. Checks a situation you typed yourself against a short list of things we will not role-play, before the session starts.
  4. Writes you one line to say when you tap “Need a line?” during a session, from the last few turns of that conversation. Those turns are sent for that one answer and not stored.

None of these providers receive an email address, because we do not have one. None of them receive your name unless you chose to enter one. Each handles data under its own privacy policy:

Other services are involved but do no AI work: Supabase (our database and server functions, hosted in the United States), Apple (payments and the App Store) and RevenueCat (subscription status).

How long things are kept

Session audio on the voice platform
Not recorded
Session transcript on the voice platform
Deleted by ElevenLabs after one day, see the note below
Conversation transcript on our server
Not stored at all. It lives only for the length of the request that writes your report
Feedback reports
On your device and on our server, until you delete them
Session records and your allowance
On our server, until you delete your data
Random device key and whether the free session was used
On our server, kept after you delete your data. It identifies no one
First name, onboarding answers, practice history, conversations you scheduled
On your device only, until you delete them
A situation you typed yourself
On your device, as part of the talk in your Real Talks list, until you remove it. Never on our server

A note about the voice platform

To run a spoken conversation, ElevenLabs has to receive it. Their platform is set to record no audio, and to delete the transcript of each session after one day. During that day we can look at a transcript to diagnose a problem or to check that a character behaved the way it should. Nothing there is labeled with an ID of yours: we send ElevenLabs no user identifier, only the session itself and your first name if you entered one.

Deleting your data

Open Settings in the app and tap Delete all my data. That is the whole procedure.

On our server it deletes your anonymous account and everything attached to it: your profile row, your session allowance, your session records and your feedback reports. On your device it wipes your reports, your practice history, the conversations you scheduled, your first name, your onboarding answers and your recorded AI consent. The app then starts over as if it had just been installed.

Three things to know:

If you would rather ask us in writing, email hello@haindlapps.com. Please be aware that because we hold no name or email address for you, we usually have no way to find your data from an email alone. The in-app button is the reliable route.

Your choices

Depending on where you live, you may have rights to access, correct, delete or export your personal data, or to object to how it is processed. We honor those requests. Given that your data is only reachable through the app's anonymous ID, the delete button is both the fastest and the most complete route. For anything else, write to hello@haindlapps.com.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

If you live in the European Union and believe we are handling your data wrongly, you can complain to a data protection authority. For us that is the Austrian Data Protection Authority (Datenschutzbehörde), dsb.gv.at. We would rather hear from you first, though.

Security

Traffic between the app and our servers is encrypted with HTTPS. Our database uses row level security, so an account can only ever read its own rows. The API keys for the AI providers live on our server and are never shipped inside the app. No system is perfectly secure and we will not pretend otherwise, but we do not keep more than we need, which is the best protection there is.

Where your data is processed

Our backend runs in the United States. Our AI providers process data in the United States and, depending on the provider, in other countries. If you use Firmly from outside the United States, your data is transferred to and processed in those places.

Children

Firmly is rated 13+ and is built for working adults. It is not directed at children under 13, and we do not knowingly collect anything from them. If you believe a child under 13 has used Firmly, email hello@haindlapps.com and we will delete the data.

Changes to this policy

If we change what Firmly collects, or who processes it, this page changes in the same step and the effective date at the top moves. If a change is significant, we will also point it out inside the app.

Contact

Martin Haindl (Haindl Apps)
Obere Ödlitzerstraße 12
2560 Berndorf, Austria
hello@haindlapps.com