Privacy Policy
The short version: Alibi ("the App") is a fake-call utility with optional AI voice features. We keep your data minimal and we never sell it. Core features work on-device; AI voice calls require cloud processing and are explained in detail below.
Information We Collect
1.1 Information You Provide
We collect information you voluntarily give us when you use the App:
- Account email and name โ required to sign in. You sign in with Apple or with Google, and that provider passes us the email address (and, for Apple, the name you choose to share) attached to your account. Handled by Supabase Auth. There is no password and no email-code sign-in.
- Profile nickname & avatar โ optional. A nickname you type is stored in our Supabase database. An avatar photo you pick is uploaded to Supabase Storage and served from a public URL, so treat it as publicly reachable. You can remove either at any time.
- Custom scenes & callers โ names, phone numbers, profile emoji, and scripts you create. Stored in our Supabase database so they sync across your devices. You can delete any scene at any time.
- Custom ringtones โ audio files you import from your device. These are uploaded to Supabase Storage so the same ringtone is available on your other devices. Deleting a ringtone in the App removes it from our storage.
- Voice samples โ custom voice cloning has been discontinued and the voice-recording screen is disabled in the shipped App, so the App records and uploads no voice sample. See Section 1.4.
- Live call audio โ during an AI voice call, your microphone audio is streamed from your device to OpenAI's Realtime service. See Section 1.4.
- Problem reports โ the App has a feedback form (Settings → Send Feedback). Submitting one sends the category you pick, what you wrote, the reply address you confirm, your app version, and your device’s operating system and version to our own product-tracking system, which is where we triage reports. Nothing else about your account travels with it โ not your scenes, your callers, or any audio.
- Support messages โ if you email us instead, we collect your email address and message content.
1.2 Information Collected Automatically
The App bundles no crash reporter. It does include one attribution SDK — AppsFlyer — which measures which marketing channel an install came from. Apart from that, the only data collected without a deliberate action from you is what our subscription provider needs:
| Data Type | What It Includes | Purpose |
|---|---|---|
| Account identifier | Your Supabase account ID, sent to RevenueCat when you sign in | Keep your subscription attached to your account across devices |
| Device identifiers & app info | Device and install identifiers, OS and app version, collected by the RevenueCat SDK | Validate purchases and restore entitlements |
| Advertising identifier & install source | Your device's advertising identifier (IDFA on iOS, Advertising ID on Android), the install source and basic in-app interaction events, collected by the AppsFlyer SDK | Measure which marketing channel an install came from. On iOS the identifier is read only if you allow it in the system tracking prompt |
| Purchase history | Which subscription you bought and whether it is active | Unlock paid features |
We do not collect your real phone contacts, GPS location, or any biometric data, and we run no crash reporter. We show no ads inside the App and build no advertising profile about you — the attribution data above is used only to measure where installs come from. Microphone audio is only captured when you actively record a voice sample or answer an AI voice call โ never in the background.
1.3 Purchase Information
If you purchase a premium subscription, payments are processed entirely by Apple's App Store or Google Play. We do not receive or store your payment card details. Subscription state is synchronized through RevenueCat, which we use to unlock premium features on your other devices; RevenueCat receives your Supabase account ID, your purchase receipt, and the device identifiers its SDK collects.
1.4 Voice & AI Call Data
Voice features send audio off-device. Each one is explained here in plain terms:
- AI voice calls (OpenAI Realtime) โ when you answer an AI call, your microphone audio is streamed in real time from your device to OpenAI's Realtime API, which drives the conversation. Our backend only issues the short-lived access token for that session; the audio itself does not pass through our servers, and we neither store nor transcribe it. OpenAI's retention of streamed audio is governed by its own policies. On networks where that service is unreachable, the App may fall back to Google's Gemini Live API, which then receives the same audio stream.
- The caller's voice (Fish Audio) โ the voice you hear is generated by Fish Audio. Our backend sends it the text to be spoken; your microphone audio is never sent to Fish Audio.
- Voice samples โ custom voice cloning has been discontinued. The voice-recording screen is disabled in the shipped App, so no sample is recorded, uploaded, or sent to any cloning provider. MiniMax, previously used for cloning, is no longer part of the App. Samples recorded by earlier versions may still exist in our Storage; deleting your account removes them.
If you never answer an AI voice call, no audio ever leaves your device.
How We Use Your Information
We use the information we collect to:
- Operate, maintain, and improve the App's features
- Respond to support requests and feedback
- Validate purchases and keep your subscription in sync across devices
- Comply with legal obligations
We show no ads inside the App, build no advertising profile about you, and never sell your data. We do measure which marketing channel an install came from — see Third-Party Services.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
Service Providers
We use trusted third-party services to help operate the App. These providers are contractually bound to use your data only to perform services on our behalf:
- Supabase โ authentication (Apple / Google sign-in), Postgres database for your profile, scenes and voice metadata, Edge Functions for secure API calls, and Storage for avatars, ringtones and voice samples.
- OpenAI โ real-time AI conversation during AI voice calls. Your microphone audio is streamed from your device to OpenAI; it is not stored by us.
- Fish Audio โ text-to-speech for the caller's voice. Receives the text to be spoken, never your microphone audio.
- Google (Gemini Live) โ fallback engine for AI voice calls when OpenAI's service is unreachable; it then receives the same audio stream.
- RevenueCat โ subscription state synchronization across devices. Receives your Supabase account ID, your App Store / Play Store purchase receipt, and the device identifiers its SDK collects.
- AppsFlyer — install attribution. Receives your device's advertising identifier, the install source and basic in-app interaction events, so we can tell which marketing channel an install came from. On iOS the identifier is sent only if you allow tracking in the system prompt.
- Apple App Store & Google Play โ payment processing and distribution.
Problem reports you submit through the feedback form are not on this list: they go to our own product-tracking system rather than to another company. What travels with a report is listed in Section 1.1.
Legal Requirements
We may disclose data if required by law, court order, or government authority, or to protect the rights, property, or safety of our users or the public.
Business Transfers
In the event of a merger, acquisition, or sale of assets, user data may be transferred. We will notify users before any such transfer and provide the option to delete their data.
Data Retention
We retain data only as long as necessary:
- On-device data (local preferences, cached audio): Retained until you delete the App or clear its data.
- Account, profile & scene data (your email, nickname, avatar, custom scenes, ringtones, voice metadata): Retained while your account is active. Deleting your account via Settings โ Account โ Delete Account triggers removal from our database and storage.
- Voice samples: Retained until you delete the voice or your account.
- Live AI call audio: Not retained by us. Streamed from your device to OpenAI, or to Google Gemini Live when the fallback is used, for real-time processing.
- Problem reports: Kept while the issue is open and for our own records afterwards, so we can tell whether a fix worked. A report is not deleted with your account — once filed it is a record of a problem rather than profile data, and we would lose the reason a change was made. Ask us and we will remove yours.
- Support correspondence: Retained for 12 months after your inquiry is resolved, then deleted.
You can request deletion of your data at any time by contacting us at the email address in Section 11. Deleting your account inside the App removes your cloud data immediately — there is no grace period. See Delete Your Account for the exact steps and the full list of what is removed.
Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request that we delete your personal data ("right to be forgotten").
- Portability: Request your data in a machine-readable format.
- Objection / Restriction: Object to or restrict certain processing of your data.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time.
Microphone
The App requests microphone access only for AI voice calls and for voice recording. You can revoke it at any time in your device's system settings; the rest of the App keeps working without those two features.
Push Notifications
You can disable push notifications at any time through your device's system settings.
To exercise any of your rights, email us at privacy@gcdm.studio. We will respond within 30 days.
Security
We take reasonable technical and organizational measures to protect your data, including:
- All data in transit is encrypted via TLS 1.2+
- On-device data is stored in the app's sandboxed container
- Access to backend systems is restricted and audited
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify affected users as required by applicable law.
Children's Privacy
The App is not directed to children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
Third-Party Services
The App integrates third-party services whose privacy practices are governed by their own policies. We recommend reviewing them:
- Supabase โ supabase.com/privacy
- OpenAI (AI voice conversation) โ openai.com/policies/privacy-policy
- Fish Audio (caller voice synthesis) โ fish.audio/privacy
- Google Gemini Live (fallback AI voice conversation) โ policies.google.com/privacy
- RevenueCat (subscription management) โ revenuecat.com/privacy
- Apple App Store / iOS โ apple.com/legal/privacy
- Google Play / Android โ policies.google.com/privacy
International Data Transfers
Our Supabase backend is hosted in the United States. When you use AI voice features, audio is processed by OpenAI โ or by Google Gemini Live when the fallback is used โ and the caller's voice is synthesized by Fish Audio; each operates its own global infrastructure. If you are located outside these regions, your data may be transferred to and processed in countries with different data protection laws than your own. Where required, we rely on standard contractual clauses (SCCs) approved by the European Commission and equivalent safeguards for other jurisdictions.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last Updated" date at the top of this page
- Display an in-app notification for material changes
- For significant changes, obtain renewed consent where required by law
Continued use of the App after changes become effective constitutes your acceptance of the revised policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
- Email: privacy@gcdm.studio
- Response time: We aim to respond within 30 days.
If you are located in the European Economic Area and believe your data has been processed unlawfully, you have the right to lodge a complaint with your local data protection authority (DPA).