Privacy Policy
Last updated: September 24, 2026
This policy explains what Pappi (the HeyPappi app and heypappi.com) collects, why, where it goes, and how you control it. Short version: we collect what we need to answer you and keep your account working, we don't sell anything, and you can see and delete your data yourself.
Who we are
Anomonus FZCO, Dubai Silicon Oasis, Dubai, United Arab Emirates ("we", "us"), is the controller of your personal data. Contact: privacy@heypappi.com.
What we collect
| Data | Why | Where it's kept |
|---|---|---|
| Account: a random device id, your nickname, and — if you sign in — your email address and sign-in method (Apple, Google or email) | To keep your conversations, questions and memory with you across devices | Our database and sign-in provider (Supabase) |
| Conversation transcripts (the text of what you and Pappi said), a short title, and the actions Pappi ran (e.g. "Opened Maps") | Your History, and your memory (below) | Our database |
| Memory: a short summary about you (name, language, preferences, ongoing topics) | So Pappi remembers you between conversations | Our database |
| Usage: when conversations start and end, how many seconds they last, which plan you're on | Your balance of questions, limits, preventing abuse | Our database |
| Purchase status: your plan, renewal date, top-ups | To give you what you paid for | Our database; Apple and RevenueCat process the purchase. We never see your card details |
| Invites: your invite code, who joined with it, and whether a reward was given (10 questions each) | Referral rewards and fraud checks (same phone, same mailbox) | Our database |
| Shared answers: if you create a share link, the question and Pappi's answer you chose to share | To show the page at heypappi.com/s/… | Our database, until you remove the link, delete that chat, or delete your account |
What goes to OpenAI
Pappi's voice runs on OpenAI's Realtime API. While a conversation is on, your voice, the screenshots of your screen (only while you share your screen — iOS shows a red indicator the whole time — or when you share an image), camera photos (only in camera mode), anything you type to Pappi, and your nickname and memory are sent to OpenAI so it can answer you in real time. Your phone talks to OpenAI directly; the audio does not pass through our servers.
OpenAI processes this data to produce answers under its API terms. Data sent through the OpenAI API is not used to train OpenAI's models by default, and we don't use your conversations to train anything. We also use OpenAI to write your memory summary and chat titles from the transcript.
What we don't store
- Audio of your voice or Pappi's voice — neither on our servers nor on your phone.
- Screenshots and camera photos — never on our servers. If you turn on "Keep screenshots in History" in the app, they stay on your iPhone only.
- Your contacts, messages or notifications. Pappi can't read them.
- Card numbers, passwords, PINs or ID numbers in memory — Pappi is told never to remember them.
The website
- A language cookie remembers the language you picked. That's the only cookie.
- If we turn on analytics, we use Plausible, which doesn't use cookies or collect personal data.
- Our web server keeps short-lived technical logs (IP address, pages requested) for security, for up to 14 days.
How long we keep it
- Transcripts and History: until you delete them — one chat or all of them, in History — or delete your account. On the Free plan the app shows the last 7 days of History.
- Memory: until you edit or clear it (Settings → Memory in the app), or delete your account.
- Usage and purchase records: while your account exists. Deleting a chat doesn't delete the usage record (questions aren't refunded).
- Backups of our database are overwritten on a rolling basis (TODO: confirm the Supabase backup window, e.g. 7 days).
Deleting your data
In the app: Settings → Account → Delete account. It deletes your conversations, memory, usage, invites, share links and your sign-in account right away. A subscription is cancelled separately in iPhone Settings → your name → Subscriptions. You can also email privacy@heypappi.com.
Children
Pappi is rated 17+ and isn't meant for children. We don't knowingly collect data from children. If you think a child used Pappi, email us and we'll delete the account.
If you're in the EU, EEA or UK
Under the GDPR (and the UK GDPR):
- Legal bases. Providing the service you asked for (contract): conversations, History, memory, your account, purchases, invites. Your consent: microphone, screen sharing, camera and notifications — you give it in iOS and can withdraw it there any time. Our legitimate interests: security, preventing abuse of free questions and invites, basic service statistics.
- Your rights. Access, correction, deletion, restriction, objection and data portability. In the app you can view and edit your memory, view and delete History, and delete your account yourself; for anything else email privacy@heypappi.com — we answer within 30 days. You can also complain to your local data protection authority.
- International transfers. Our database is hosted by Supabase (TODO: confirm region); OpenAI processes data in the United States; our web server is outside the EU. Transfers rely on the providers' Standard Contractual Clauses.
Who processes data for us
- OpenAI — voice answers, memory summaries, chat titles
- Supabase — database and sign-in
- Apple and RevenueCat — App Store purchases and subscriptions
- Apple and Google — only if you sign in with them
- Our server host — runs our API and this website
We don't sell your data and don't show ads.
Changes
If we change this policy, we'll update this page and the date at the top, and tell you in the app for anything important.
Contact
Anomonus FZCO, Dubai Silicon Oasis, Dubai, United Arab Emirates. Privacy: privacy@heypappi.com. Everything else: support@heypappi.com.